ctipilot.ch

ShinyHunters

actor · actor:shinyhunters single-source

Financially motivated data-theft and extortion group (also tracked as UNC6240) behind the 2026 Salesforce/SaaS victim cluster (Instructure, Vimeo, 7-Eleven, Carnival, Inditex/Zara, Medtronic and others) and the Oracle PeopleSoft data-theft campaign.

Aliases: UNC6240

Coverage timeline
64
first 2026-05-04 → last 2026-07-18
Peak priority
critical
2 critical · 23 high · 39 notable
Sources cited
156
82 hosts
Sections touched
13
active-threats, deep-dive, research
Co-occurring entities
8
see Related entities below
ATT&CK techniques
23
pinned v19.1 · see below
2026-05-0464 appearances2026-07-18

ATT&CK techniques

23 techniques observed across 18 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1190Exploit Public-Facing Application×9
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×6

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · ATT&CK page ↗

Defense Impairment TA0112

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×3

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1552.004Unsecured Credentials: Private Keys×1

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

T1021.004Remote Services: SSH×2

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×2

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1213.002Data from Information Repositories: Sharepoint×1

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-05-29/carnival-corporation-confirms-5-99-m-record-shinyhunters-bre · ATT&CK page ↗

T1530Data from Cloud Storage×3
T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×5

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

Story timeline

  1. 2026-07-18Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
    active-threatsAbbott confirms unauthorized access to its Cancer Diagnostics (Exact Sciences) systems as ShinyHunters claims a helpdesk-vishing to Entra SSO breach
  2. 2026-07-16CVE-2026-46817 — Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)
    trending-vulnerabilitiesOracle E-Business Suite Payments pre-auth takeover (CVE-2026-46817) confirmed exploited and KEV-listed — patch or pull exposed instances off the internet
  3. 2026-07-14Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability
    researchMicrosoft maps a year of Salesforce OAuth abuse — vishing consent, supply-chain secret reuse, guest-access Aura abuse — invisible to sign-in detection
  4. 2026-07-12This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim
    weekly-incidents-recapW28 incidents cluster on third-party / cloud-account exposure — Accenture, Deutsche Bank vendor, KDDI, Nayax cloud account, Odido vishing, Nextcloud misconfig
  5. 2026-07-12Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it
    weekly-multi-dayM365 identity attacks converged this week — device-code, AiTM PhaaS, ROPC spray and vishing all bypass MFA/Conditional Access by sidestepping it
  6. 2026-07-10ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
    active-threatsDutch police tie ShinyHunters' Odido telecom breach to Dutch nationals via voice analysis — the vishing-to-spoofed-portal playbook now hits an EU telco
  7. 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
    active-threatsReliaQuest: new 'Helix' extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint
  8. 2026-07-05ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces
    weekly-long-runningShinyHunters / UNC6240 Oracle campaign status — Nissan named, notifications still landing
  9. 2026-07-05Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign
    weekly-top-storiesTwo internet-facing Oracle enterprise product lines under active exploitation this week — EBS RCE + PeopleSoft
  10. 2026-07-05Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered
    weekly-incidents-recapExtortion without encryption matures — a US county paid ~$1M to Kairos, no encryptor recovered
  11. 2026-07-05Looking ahead — 2026-W27
    weekly-looking-aheadLooking ahead — 2026-W27: items already in motion for the coming weeks
  12. 2026-07-03Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containment
    active-threats
  13. 2026-07-01Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation
    deep-dive
  14. 2026-07-01Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign
    updates
  15. 2026-06-29ShinyHunters / UNC6240 Oracle PeopleSoft campaign
    weekly-long-running
  16. 2026-06-29ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week
    weekly-multi-day
  17. 2026-06-29NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall
    weekly-top-stories
  18. 2026-06-29Looking ahead — 2026-W26
    weekly-looking-ahead
  19. 2026-06-29Education
    weekly-sector-patterns
  20. 2026-06-28NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
    active-threats
  21. 2026-06-27UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paid
    active-threats
  22. 2026-06-26ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
    active-threats
  23. 2026-06-22ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure
    weekly-multi-day
  24. 2026-06-22Public administration — named European institutions and government data in the firing line
    weekly-sector-patterns
  25. 2026-06-22Looking ahead — 2026-W25
    weekly-looking-ahead
  26. 2026-06-22Education — exposed CMS and forum software stack a structural risk
    weekly-sector-patterns
  27. 2026-06-22CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)
    weekly-vuln-rollup
  28. 2026-06-21Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
    active-threats
  29. 2026-06-20Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
    active-threats
  30. 2026-06-16Council of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaign
    updates
  31. 2026-06-14Education — ShinyHunters' PeopleSoft campaign lands disproportionately on universities
    weekly-sector-patterns
  32. 2026-06-14CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest
    weekly-top-stories
  33. 2026-06-14CrowdStrike 2026 Technology Threat Landscape Report — "technology = most-targeted" reads as prophecy against this week's incidents
    weekly-annual-reports
  34. 2026-06-13Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest
    updates
  35. 2026-06-13CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session
    trending-vulnerabilities
  36. 2026-06-12ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
    updates
  37. 2026-06-12CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
    trending-vulnerabilities
  38. 2026-06-11ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
    deep-dive
  39. 2026-06-05ShinyHunters extortion campaign adds DentaQuest — 234 GB published after refusal to pay, 2.6 M dental-benefit records exposed
    updates
  40. 2026-06-02ShinyHunters publishes the Charter Communications dataset after ransom refusal
    updates
  41. 2026-06-01ShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit records
    weekly-incidents-recap
  42. 2026-06-01Healthcare — HIPAA breach + healthcare supply-chain exposure
    weekly-sector-patterns
  43. 2026-05-29Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands
    active-threats
  44. 2026-05-27ShinyHunters Salesforce campaign — Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
    active-threats
  45. 2026-05-25ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized
    weekly-long-running
  46. 2026-05-25ShinyHunters lists Charter Communications (Spectrum) — telco victim in the Salesforce-credential campaign
    updates
  47. 2026-05-19Grafana Labs CoinbaseCartel breach — victim confirms source-code-only theft, no customer data, ransom rejected
    active-threats
  48. 2026-05-197-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
    active-threats7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel
  49. 2026-05-18Education — virtual-classroom platforms and EdTech SaaS exposure
    weekly-sector-patterns
  50. 2026-05-187-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records
    weekly-incidents-recap
  51. 2026-05-16GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
    active-threats
  52. 2026-05-13Instructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransom
    updates
  53. 2026-05-12Instructure (Canvas LMS) — ransom paid to ShinyHunters with "shred logs"; second intrusion confirmed; per-institution leak deadline reset to today
    updates
  54. 2026-05-11TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence
    weekly-long-running
  55. 2026-05-11TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak
    weekly-multi-day
  56. 2026-05-11Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation
    weekly-long-running
  57. 2026-05-11Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited
    weekly-multi-day
  58. 2026-05-10Canvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9
    updates
  59. 2026-05-09Inditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
    active-threats
  60. 2026-05-04ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas
    weekly-multi-day
  61. 2026-05-04ShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)
    weekly-long-running
  62. 2026-05-04Looking ahead — 2026-W19
    weekly-looking-ahead
  63. 2026-05-04Europol IOCTA 2026
    weekly-annual-reports
  64. 2026-05-04Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects
    weekly-multi-day

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

overlaps with

attributed activity

Where this entity is cited

  • active-threats15
  • updates10
  • weekly-multi-day7
  • weekly-long-running6
  • weekly-sector-patterns6
  • weekly-looking-ahead4
  • weekly-incidents-recap4
  • trending-vulnerabilities3
  • weekly-top-stories3
  • weekly-annual-reports2
  • deep-dive2
  • weekly-vuln-rollup1
  • research1

Source distribution

  • bleepingcomputer.com20 (13%)
  • securityweek.com12 (8%)
  • theregister.com7 (4%)
  • attack.mitre.org6 (4%)
  • msrc.microsoft.com5 (3%)
  • securityaffairs.com4 (3%)
  • cloud.google.com3 (2%)
  • helpnetsecurity.com3 (2%)
  • other96 (62%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (156)

Entries about ShinyHunters (64)

2026-07-18 · view entry permalink →

NOTABLENATOA3

Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records

Abbott Laboratories is investigating a cyber incident and states there was "unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only," adding that there is "no impact to any other Abbott businesses, sites or systems" and that the legacy Exact Sciences systems (Exact Sciences was folded into Abbott's diagnostics business in a 2026 acquisition) remain separate from Abbott's core infrastructure (Abbott, 2026-07-16). Abbott has not named an actor, confirmed a method, or disclosed what kind of information was accessed (MedTech Dive, 2026-07-17).

The ShinyHunters extortion group (registry-tracked, alias UNC6240) claims responsibility, saying the intrusion began with a vishing (voice-phishing) attack targeting several Abbott employees that compromised a Microsoft Entra ID single-sign-on account, which was then used to "exfiltrate data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa" — the actor's leak-site posting claims more than 30 million customer records, medical notes and orders, and set a leak deadline it later pushed to 21 July (BleepingComputer, 2026-07-17). A second, separate claim by an actor calling itself "ShadowByt3\$" alleges compromise of an externally facing LabCentral portal, which BleepingComputer reports houses publicly available technical product reference documents and does not contain proprietary or sensitive customer or business information (BleepingComputer, 2026-07-17). The record counts and the specific SaaS platforms are the actor's unverified claim, not Abbott's confirmation.

Abbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only.

Abbott Laboratories (own statement) 2026-07-16

ShinyHunters claimed it exfiltrated data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa, including internal documents, contracts, and customer information.

BleepingComputer 2026-07-17
incident18 Jul 04:35Zmulti-sourceOpen finding ↗

2026-07-16 · view entry permalink →

HIGHCVE-2026-46817exploitedNATOA1

CVE-2026-46817 — Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)

CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on 15 July 2026, the first formal confirmation of active exploitation for a flaw Oracle patched without fanfare in its May 2026 Critical Patch Update (CISA, 2026-07-15). The bug sits in the File Transmission component of Oracle Payments — the payment-processing engine built into Oracle E-Business Suite — and Oracle characterises it as improper privilege management, improper authentication and missing authentication for a critical function that an unauthenticated attacker with HTTP network access can use to compromise and take over Oracle Payments (CVSS 9.8; Oracle CPU, 2026-05-28). Affected releases are EBS 12.2.3 through 12.2.15.

Threat-intelligence firm Defused recorded the first in-the-wild exploitation against its EBS honeypot decoys on 27 June 2026 — roughly six weeks after the patch and before any public proof-of-concept existed — as a single source running an unauthenticated file read against the Payments component rather than broad scanning (Help Net Security, 2026-06-30). The observed technique calls the ibytransmit endpoint in the File Transmission component, invoking an internal Oracle Java function directly and redirecting it to read /etc/passwd; the same primitive can be pointed at configuration files holding database credentials, encryption keys or payment-processor API keys (Help Net Security, 2026-06-30). This is the same EBS product family already under sustained ShinyHunters/UNC6240 extortion pressure and the latest in a now-annual cadence of critical, remotely exploitable EBS flaws.

On 27 June 2026 our Oracle E-Business Suite decoys recorded the first in-the-wild exploitation of CVE-2026-46817 — roughly six weeks after Oracle's May 2026 patch and before any public proof-of-concept existed.

Help Net Security (citing Defused) 2026-06-30

The exploit targets the ibytransmit endpoint in Oracle Payments' File Transmission component, and calls an internal Oracle Java function directly, redirecting it to read a file (/etc/passwd) from the server.

Help Net Security

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CISA 2026-07-15
vulnerability16 Jul 04:35Zmulti-sourceOpen finding ↗

2026-07-14 · view entry permalink →

NOTABLENATOB2

Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability

Microsoft Threat Intelligence documented a year-long (mid-2025 to mid-2026) set of campaigns using tradecraft commonly associated with ShinyHunters (registry alias UNC6240) against Salesforce-integrated environments, through three distinct paths rather than any Salesforce product vulnerability (Microsoft Threat Intelligence, 2026-07-13). First, vishing-driven OAuth-consent abuse: attackers impersonating IT support socially engineer employees through the OAuth authorization workflow into granting a malicious connected app — disguised as the legitimate Salesforce Data Loader — full API access inherited from the victim's own privileges, letting them enumerate and exfiltrate CRM data through sanctioned application access that never trips a sign-in anomaly. Second, SaaS supply-chain compromise: compromised Salesloft Drift credentials (August 2025) exposed OAuth connection secrets reused across customer tenants; a November 2025 campaign abused Gainsight-published Salesforce apps the same way; and in June 2026 an actor Microsoft tracks as Storm-3138 compromised the Klue competitive-intelligence platform and reused harvested Salesforce credentials to query and exfiltrate customer CRM data. Third, guest-access abuse: requests chained against Salesforce's Aura framework via misconfigured guest-user accounts pulled far more data than a guest session should reach (The Hacker News, 2026-07-14). Microsoft observed the activity across retail, education and manufacturing tenants and states existing authentication-focused detections gave "limited visibility" because the traffic is indistinguishable from legitimate integration.

Threat actors socially engineered employees into authorizing attacker-controlled connected apps within their Salesforce tenant.

This activity was not the result of a vulnerability inherent to Salesforce.

malicious activity often appeared indistinguishable from legitimate Salesforce usage because threat actors operated through trusted identities, approved OAuth applications, and authorized integrations.

Microsoft Threat Intelligence 2026-07-13
research14 Jul 20:22Zmulti-sourceOpen finding ↗

Earlier coverage (61)

2026-07-12NOTABLENATOB1This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victimThe week's confirmed incidents share a structural theme: the initial exposure sat in a cloud account, a third-party vendor, or a supplier platform rather than the victim's own perimeter. Accenture confirmed data theft after '888' advertised internal source code; Deutsche Bank disclosed a third-party vendor incident after 'Unsafe' ransomware claims; KDDI named a third-party-software zero-day as the root cause of its 12M-record ISP email breach; Nayax (an EEA payment institution) disclosed a cloud-account incident claimed by 'The Syndicate'; ShinyHunters' Odido (NL telecom) breach drew Dutch-national-involvement attribution from police voice analysis; and Nextcloud GmbH's own hosting exposed 367K records via a misconfigured Elasticsearch. Supplier and cloud-account risk, not perimeter RCE, drove the week's disclosures.2026-07-12HIGHNATOB1Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking itFour independent 2026-W28 disclosures describe the same M365 account-takeover pattern from different angles: Huntress' root-cause comparison of the Railway (device-code) and LSHIY (ROPC spray) campaigns, where 55 of 78 LSHIY-compromised accounts had CA policies requiring MFA that failed on scoping gaps; the Forg365 AiTM phishing-as-a-service kit; and the Helix data-extortion cluster pairing manager-impersonation vishing with device-code phishing. None defeats MFA cryptographically — each exploits an auth flow (device-code, ROPC/legacy, token replay) that a typical Conditional Access policy does not gate. Every M365 tenant should block device-code and ROPC where unused and confirm CA covers all cloud apps and client-app types.2026-07-10HIGHNATOB2'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltrationReliaQuest documented a previously unreported data-extortion cluster it calls Helix, assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting infrastructure. Operators phone a target impersonating their named manager (spoofed caller-ID), walk them through an Entra ID device-code sign-in that captures a session token without a password and sidesteps Conditional Access, register a new Authenticator within minutes for persistence, then run automated SharePoint enumeration and bulk exfiltration. SharePoint + Entra ID is the default identity/collaboration stack across Swiss and EU public-sector tenants, so the playbook is directly reachable; disabling the device-code flow is the single highest-impact control.2026-07-10NOTABLENATOA2ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telcoDutch National Police announced on 9 July 2026 that its investigation into the February 2026 ShinyHunters breach of telecom operator Odido (and its Ben brand) found strong indications of Dutch-national involvement, based on forensic voice analysis of a call recorded during the intrusion. The intrusion used the ShinyHunters playbook already tracked in this store: a vishing call impersonating IT staff persuaded a customer-service employee to authenticate into a spoofed corporate portal, harvesting credentials used to bulk-export 6.2M+ customer records before the account was blocked within an hour. The new signal is the EU-telco victim, the law-enforcement attribution, and two open Dutch DPA investigations; the underlying TTP is the ShinyHunters playbook already tracked in this store.2026-07-05NOTABLENATOB2Looking ahead — 2026-W27Items already in motion, not predictions: six Adobe ColdFusion CVSS 10.0 RCEs await weaponisation (patch before a PoC lands); CitrixBleed-lineage NetScaler CVE-2026-8451 has a public test artefact and its siblings exploited within days; WatchGuard Firebox 12.5.x still lacks a fix; the Dutch NIS2 Senate vote is set for 7 July with entry into force 15 August; ShinyHunters PeopleSoft notifications keep landing across an un-notified EU tail; and SOCRadar's claimed FortiBleed-actor Nextcloud zero-day awaits vendor disclosure.2026-07-05NOTABLEexploitedupdateNATOB1ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfacesThe ShinyHunters/UNC6240 Oracle PeopleSoft campaign (CVE-2026-35273) added Nissan as its largest named victim this week — employee HR/payroll PII across four countries — while GTIG notifications keep landing across the ~100-organisation tail. Separately, Medtronic is notifying ~9M people of a ShinyHunters-claimed April corporate-IT breach (not attributed to the PeopleSoft path). The campaign remains an active, victim-acquiring, zero-day-capable ERP-extortion operation.2026-07-05NOTABLENATOB2Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recoveredThis week's clearest extortion signal is the continued decoupling of extortion from encryption: a Ransom-ISAC retrospective details a US county government that paid ~$1M to the data-theft actor Kairos with no encryptor recovered in the case, MedusaLocker ran pure data-leak listings, and the ShinyHunters cluster continues to extort on exfiltration alone. For public-sector defenders the implication is that backup-and-restore resilience no longer bounds the impact — the leverage is disclosure, so data-exfiltration detection and minimisation matter as much as recovery.2026-07-05HIGHexploitedNATOB2Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaignOracle E-Business Suite CVE-2026-46817 (pre-auth RCE in the Payments File Transmission servlet, CVSS 9.8) saw its first confirmed in-the-wild exploitation this week, landing while the separate ShinyHunters Oracle PeopleSoft campaign (CVE-2026-35273) kept acquiring named victims. The operational reality for a public-sector or higher-education estate: treat every internet-reachable Oracle application tier — EBS, PeopleSoft, and their web front ends — as a priority patch-and-isolate target, not just the specific CVE.2026-07-03HIGHMedtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containmentMedtronic is notifying ~9 million people of a ShinyHunters-claimed April breach of corporate IT systems (names, DOB, SSNs, health data), 2.5 months after containment; it says medical devices were unaffected and segregated from the compromised networks (BleepingComputer, 2026-07-02).2026-07-01NOTABLEexploitedOracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitationWhat it is. CVE-2026-46817 (CVSS 9.8) is an unauthenticated remote-code-execution flaw in the File Transmission component of Oracle Payments, part of Oracle E-Business Suite, affecting EBS 12.2.3 through 12.2.15.2026-07-01HIGHexploitedupdateNissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaignThe ShinyHunters Oracle PeopleSoft campaign adds Nissan as its largest named victim yet — current and former employee HR/payroll PII across four countries, a different exposure profile than the NAIC breach covered 2026-06-28 (SecurityWeek, 2026-06-30).2026-06-29NOTABLELooking ahead — 2026-W26ShinyHunters PeopleSoft notifications are still landing — expect more named European education and public-finance victims. GTIG has notified ~100 organisations (68% higher education) and NAIC is the fresh high-profile case; patch internet-reachable PeopleSoft and hunt /PSEMHUB/ and /PSIGW/HttpListeningConnector.2026-06-29NOTABLEexploitedShinyHunters / UNC6240 Oracle PeopleSoft campaignThe campaign behind the § 1 NAIC breach.2026-06-29NOTABLEEducationEducation was a structural victim class. The ShinyHunters Canvas/Instructure breach hit 160 UK universities per the UK CMC sector review (ransom paid, limited downstream damage).2026-06-29NOTABLEShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one weekThe week is a compact case study in how a single extortion cluster's reported activity spans very different initial-access tradecraft.2026-06-29HIGHexploitedNAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stallNAIC breached through an Oracle PeopleSoft zero-day (CVE-2026-35273); ShinyHunters dumps 3.1 TB and US rating-agency feeds stall — the same UNC6240 campaign GTIG has tracked against ~100 orgs (68% higher education) is still acquiring victims; treat internet-reachable PeopleSoft as assume-compromise. (daily 06-28, NAIC)2026-06-28HIGHexploitedNAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pauseNAIC — the standard-setting body for all 50 US state insurance regulators — confirms a breach via an Oracle PeopleSoft zero-day; ShinyHunters published ~3.1 TB of insurance regulatory and credit-rating-agency data, and rating-agency feeds paused, forcing NAIC to suspend assigning investment-risk designations. Part of a 100+ org PeopleSoft zero-day campaign; any organisation running Oracle PeopleSoft should verify patch status against the campaign (NAIC, 2026-06-26).2026-06-27NOTABLEUK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paidThe UK Cyber Monitoring Centre (CMC) published a post-incident sector review on 2026-06-25 of the April 2026 ShinyHunters (UNC6240) breach of Instructure's Canvas learning-management platform, which affected roughly 160 UK higher-education institutions (Computer Weekly, 2026-06-25).2026-06-26HIGHShinyHunters used a single vishing call into the company's identity platform to breach Madison Square GardenShinyHunters breached Madison Square Garden through a single vishing call into the company's identity platform — 404 Media's review of the stolen data confirms a low-level employee was talked into letting the operators into MSG's systems, the same vishing → identity-platform (Entra/Okta) → MFA-enrollment kill chain that works equally well against EU public-sector tenants (404 Media, 2026-06-24).2026-06-22NOTABLELooking ahead — 2026-W25RoguePlanet (CVE-2026-50656) has no patch and a PoC that works on June builds — watch MSRC for an out-of-band fix. Microsoft says a fix is "in development" with no timeline; the researcher warns mitigations are not reliable.2026-06-22NOTABLEEducation — exposed CMS and forum software stack a structural riskEducation entities sat under two pressures this week: the continuing ShinyHunters PeopleSoft campaign that W24 documented landing disproportionately on universities, and a cluster of critical web-application CVEs in software ubiquitous across European universities and student communities — JCE for Joomla …2026-06-22NOTABLEPublic administration — named European institutions and government data in the firing lineThe public sector again carried high-severity activity on multiple vectors. The Council of Europe — a Strasbourg human-rights body of which Switzerland is a member — was named in the ShinyHunters PeopleSoft campaign (§ 2).2026-06-22NOTABLECVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)Oracle's June Critical Security Patch Update shipped 245 fixes on 2026-06-17, around 100 remotely exploitable without authentication, headlined by an unauthenticated Solaris Remote Administration Daemon flaw (CVE-2026-46978, CVSS 10.0) and a PeopleSoft RCE (CVE-2026-35278, 9.8) (Oracle CSPU; daily 06-18).2026-06-22HIGHShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressureShinyHunters named the Council of Europe in the Oracle PeopleSoft campaign — a European institution of which Switzerland is a member — while adding Kodak and One Medical to its leak-site pressure. (daily 06-16, SecurityWeek)2026-06-21NOTABLEAmazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires todayOne Medical (Amazon) confirmed on 2026-06-13 that an unauthorised party accessed a legacy third-party file-storage system retaining archived records for One Medical Seniors (formerly Iora Health), during a 2026-06-08 to 2026-06-11 window, affecting demographic and clinical records for patients at nine clinics …2026-06-20NOTABLEKodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publicationEastman Kodak acknowledged on 17 June 2026 that "an unauthorized third party illegally gained access to a limited amount of company data," after ShinyHunters listed it on their dark-web leak site on 15 June claiming 2.2 million PII records and set an 18 June contact deadline (SecurityWeek, 2026-06-18 …2026-06-16HIGHupdateCouncil of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaignCouncil of Europe breached via the Oracle PeopleSoft zero-day (CVE-2026-35273) — ShinyHunters claims 297 GB / ~429,000 files and set a 16 June leak deadline; the first European intergovernmental victim named in the 100+-organisation PeopleSoft campaign (§ 4 update). (SecurityWeek, 2026-06-15)2026-06-14NOTABLECrowdStrike 2026 Technology Threat Landscape Report — "technology = most-targeted" reads as prophecy against this week's incidentsCrowdStrike's report (published 9 June, distilled in the 06-11 daily) found technology to be the most-targeted sector. Rather than re-recap it, the weekly's lens is corroboration: this very week supplied the evidence.2026-06-14NOTABLEEducation — ShinyHunters' PeopleSoft campaign lands disproportionately on universitiesThe week's clearest sectoral concentration. Mandiant/GTIG's attribution of the Oracle PeopleSoft zero-day campaign (§ 1) explicitly noted that the education sector was hit hardest, with the University of Nottingham confirming ~455,000 affected records (Google GTIG; daily 06-13).2026-06-14HIGHexploitedCVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardestShinyHunters' Oracle PeopleSoft campaign was vendor-confirmed as a zero-day and attributed to UNC6240, with education hit hardest. Oracle shipped an out-of-band fix for CVE-2026-35273; the University of Nottingham quantified 455,000 records; Mandiant/GTIG put 100+ organisations in scope. (daily 06-12, daily 06-13, Google GTIG)2026-06-13CRITICALexploitedupdateOracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardestOracle PeopleSoft CVE-2026-35273 confirmed exploited as a zero-day since 27 May; 100+ orgs hit, 68% higher education. Mandiant/GTIG attributes the unauthenticated SSRF→RCE campaign against the PeopleSoft Environment Management Hub to UNC6240 (ShinyHunters); the University of Nottingham confirmed 454,600 student records stolen. CISA added it to KEV on 12 June. Swiss/EU universities running PeopleTools 8.61/8.62 (Campus Solutions) are squarely in scope (Mandiant/GTIG, 2026-06-11).2026-06-13HIGHCVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician sessionSimpleHelp RMM ships an unauthenticated OIDC auth-bypass (CVE-2026-48558). A forged unsigned OIDC token yields a full technician session and bypasses IdP MFA — a clean initial-access vector into every downstream MSP-managed estate (Horizon3.ai, 2026-06-12).2026-06-12CRITICALexploitedupdateShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 recordsOracle confirms the PeopleSoft zero-day: CVE-2026-35273, pre-auth RCE (CVSS 9.8) in the Environment Management Hub, out-of-band patch released. Mandiant attributes the 100+-organisation data-theft campaign to UNC6240 (ShinyHunters) with an exploitation window of 27 May – 9 June (Mandiant GTIG, 2026-06-11). Patch and compromise-assess — exploitation predates the fix.2026-06-12NOTABLECVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)Fortinet patched CVE-2026-25089 (CWE-78, internal reference FG-IR-26-141) on 9 June: the FortiSandbox web interface's "start VNC" handler passes attacker-controlled JSON to the underlying OS without sanitisation, allowing a remote unauthenticated attacker to achieve second-order command injection via a crafted HTTP …2026-06-11HIGHShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltrationShinyHunters claims Oracle PeopleSoft data theft at 100+ organisations across ~300 instances, mostly in higher education; the University of Nottingham confirmed student and alumni data was accessed (BleepingComputer, 2026-06-10). Post-access lateral movement abuses default PeopleSoft/Oracle SSH service accounts — see the deep dive.2026-06-05NOTABLEupdateShinyHunters extortion campaign adds DentaQuest — 234 GB published after refusal to pay, 2.6 M dental-benefit records exposedUPDATE (originally covered 2026-06-02): DentaQuest, a Sun Life subsidiary administering dental and vision benefits for ~35 M US Medicaid, Medicare and employer-plan members, is the latest confirmed named victim of the ShinyHunters data-extortion campaign last covered here on the Charter Communications listing.2026-06-02NOTABLEupdateShinyHunters publishes the Charter Communications dataset after ransom refusalUPDATE (originally covered 2026-05-27): After Charter Communications declined to pay, ShinyHunters published the stolen dataset on 30 May. Have I Been Pwned ingested it as 4.9 million unique email addresses, alongside names, phone numbers and physical addresses (Security Affairs, 2026-05-30 · Have I Been Pwned).2026-06-01NOTABLEShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit recordsDentaQuest (Sun Life subsidiary, administering dental/vision benefits for ~35 M US Medicaid and Medicare members) confirmed on 1 June that ShinyHunters published 234 GB of stolen data after ransom negotiations broke down (BleepingComputer, 2026-06-04; BankInfoSecurity; daily 2026-06-05).2026-06-01NOTABLEHealthcare — HIPAA breach + healthcare supply-chain exposureShinyHunters published the DentaQuest dataset this week: 234 GB, 2.6 million records in HIPAA-format ASC X12 claims interchange, including Medicaid IDs (BleepingComputer, 2026-06-04).2026-05-29HIGHCarnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brandsCarnival Corporation files substitute notices confirming a breach affecting 5,995,277 individuals (Maine AG filing; driver's-licence + passport numbers exposed across Princess / Holland America / Cunard / Costa per The Record). Maine AG records the breach occurring 2026-04-10 and discovered 2026-04-14 (single-employee-account social engineering); ShinyHunters claimed and ultimately published when ransom was refused.2026-05-27HIGHShinyHunters Salesforce campaign — Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affectedShinyHunters Salesforce extortion — two fresh victim confirmations. Charter Communications (Spectrum) confirmed a breach but disputes that sensitive PI or CPNI was taken (BleepingComputer, 2026-05-26), while 7-Eleven confirmed a breach affecting roughly 185,000 individuals — CyberInsider reports Social Security and driver's-licence numbers in the exposed set (CyberInsider, 2026-05-26); both trace to the vishing → Entra → Salesforce-Aura pattern.2026-05-25NOTABLEShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seizedComplementing the § 2 victim arc, horizon research confirms the campaign now lists 40+ confirmed or claimed victims (key: item:shinyhunters-salesforce-campaign-charter-and-7-eleven-both-c), with Canada Life (insurance carrier, UK/Ireland) and Pitney Bowes confirming breaches in the window, and …2026-05-25HIGHupdateShinyHunters lists Charter Communications (Spectrum) — telco victim in the Salesforce-credential campaignShinyHunters listed Charter Communications (Spectrum), claiming 42M records with a 27 May deadline — a fresh victim in the Salesforce-credential campaign tracked here via 7-Eleven (2026-05-19), and by our own tracking its first telco/ISP victim to respond publicly. Charter denies any "sensitive PI or CPNI" exfiltration, a denial calibrated to FCC categories; the 42M figure is the actor's unverified claim (CyberInsider, 2026-05-23).2026-05-19NOTABLEGrafana Labs CoinbaseCartel breach — victim confirms source-code-only theft, no customer data, ransom rejectedUPDATE (originally covered 2026-W21): Grafana Labs issued an official 2026-05-18 confirmation of the GitHub Pwn-Request breach previously reported in the 2026-W21 weekly summary (SecurityWeek, 2026-05-18; BleepingComputer, 2026-05-18; The Register, 2026-05-18).2026-05-19HIGH7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records (SecurityWeek, 2026-05-18). Part of the broader ShinyHunters Salesforce-targeting campaign with co-victims Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic — phishing / OAuth / misconfiguration, not Salesforce-product vulnerabilities.2026-05-18NOTABLE7-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records7-Eleven confirmed on 2026-05-18 that an unauthorised third party accessed franchise-application records (600,000+) in a breach ShinyHunters claimed in April 2026.2026-05-18NOTABLEEducation — virtual-classroom platforms and EdTech SaaS exposureBigBlueButton — the open-source virtual-classroom platform deployed across German DFN, Swiss SWITCH and pan-European GÉANT academic networks, including cantonal school deployments — disclosed three flaws (weak session-token randomness, API checksum bypass, SSRF) in bbb-web < 3.0.21 / < 3.0.23 (daily 2026-05-19).2026-05-16HIGHGTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrandGTIG analyses UNC6671 "BlackFile" vishing-driven AiTM extortion: real-time helpdesk impersonation → attacker-registered lookalike SSO portals → MFA token capture and rogue MFA device registration → programmatic SharePoint exfiltration of 1M+ files per victim via Python requests spoofing the Microsoft Office ClientAppId; DLS shutdown signals probable rebrand (Google Threat Intelligence Group, 2026-05-15).2026-05-13NOTABLEupdateInstructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransomUPDATE (originally covered 2026-05-12): Late on 2026-05-11, US House Homeland Security Committee Chairman Andrew Garbarino sent a formal letter to Instructure CEO Steve Daly ahead of the 2026-05-12 ShinyHunters extortion deadline, demanding a briefing by 2026-05-21 on the circumstances of both Canvas intrusions …2026-05-12HIGHupdateInstructure (Canvas LMS) — ransom paid to ShinyHunters with "shred logs"; second intrusion confirmed; per-institution leak deadline reset to todayInstructure paid ShinyHunters; double Canvas intrusion confirmed; per-institution leak deadline is today (2026-05-12). Ransom acknowledged and "shred logs" received for the platform-wide dataset; a second intrusion on 2026-05-07 defaced ~330 institution portals via the same Free-for-Teacher flaw, and ShinyHunters has now set a fresh per-institution payment deadline (The Register, 2026-05-12). European universities reliant on Canvas should treat the platform-wide settlement as legally unverifiable destruction.2026-05-11NOTABLECanvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigationFull coverage in § 2 (multi-day chain).2026-05-11NOTABLETeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistenceFull coverage in § 2 (multi-day chain).2026-05-11NOTABLECanvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploitedThe W19 weekly closed with the Canvas / Instructure extortion deadline of 2026-05-12 pending.2026-05-11HIGHexploitedTeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leakTeamPCP Mini Shai-Hulud wave 4 compromised 170+ npm packages / 400+ malicious versions per daily-brief tracking (TanStack, UiPath, Mistral AI, OpenSearch, OpenAI named); Datadog static analysis of the leaked Shai-Hulud framework source (2026-05-12 leak) surfaces previously-undocumented IDE-persistence hooks targeting .claude/settings.json and .vscode/tasks.json, plus OIDC token extraction from /proc/<pid>/mem to forge Sigstore provenance attestations. Provenance-only verification no longer separates malicious from legitimate publications. (Datadog Security Labs · Wiz Blog · daily 2026-05-13 UPDATE · daily 2026-05-15 UPDATE)2026-05-10HIGHupdateCanvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9Canvas/Instructure UPDATE — ShinyHunters claims a second intrusion despite the May 8 patch and "continued active access". Seven Dutch universities (VU Amsterdam, UvA, Erasmus, Tilburg, TU/e, Maastricht, Twente) executed emergency Canvas disconnects on/before 2026-05-09; Dutch DPA notified by VU Amsterdam. Original 2026-05-12 extortion deadline now two days away; Instructure rotated application keys and required customer API client re-authorisation.2026-05-09NOTABLEInditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromiseHave I Been Pwned confirmed on 2026-05-08 that 197,400 unique email addresses from Inditex (Zara's parent, headquartered in A Coruña, Spain) were exposed following a breach of a former third-party analytics provider.2026-05-04NOTABLELooking ahead — 2026-W19Canvas / Instructure extortion deadline — Tuesday 2026-05-12 (two days out). Second-intrusion claim against Instructure made 2026-05-08 despite the May 8 patches; seven Dutch universities disconnected; Dutch DPA and ICO engaged.2026-05-04NOTABLEShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)Current state: most-active operator family of 2026-W19. Confirmed parallel involvement across Vimeo/Anodot, Inditex/Zara/Anodot, ADT/Okta-SSO/Salesforce, and Canvas/Instructure (second-intrusion claim despite May 8 patches).2026-05-04NOTABLEEuropol IOCTA 2026The Internet Organised Crime Threat Assessment 2026 (published 2026-04-28) was Europol's first IOCTA to identify the interweaving of state-sponsored hybrid threats with criminal actors as the defining strategic risk for EU public-sector defenders.2026-05-04HIGHCanvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnectsCanvas / Instructure — second intrusion claim against Instructure on 2026-05-08 despite the May 8 patches; seven Dutch universities (VU Amsterdam, UvA, Erasmus, Tilburg, TU/e, Maastricht, Twente) executed emergency Canvas disconnects on or before 2026-05-09; the extortion deadline is 2026-05-12 (Tuesday). (Techzine EU · DutchNews.nl · daily 2026-05-10)2026-05-04NOTABLEShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / CanvasThe cross-day pattern most visible in 2026-W19 is the ShinyHunters / WorldLeaks operator family's role in four parallel third-party / SaaS-tier compromises with European footprint, all riding the third-party-analytics → cloud-data-warehouse → tenant-data-exfiltration pivot rather than direct attack on the victim's …