ctipilot.ch

ShinyHunters

actor · actor:shinyhunters single-source

Financially motivated data-theft and extortion group (also tracked as UNC6240) behind the 2026 Salesforce/SaaS victim cluster (Instructure, Vimeo, 7-Eleven, Carnival, Inditex/Zara, Medtronic and others) and the Oracle PeopleSoft data-theft campaign.

Aliases: UNC6240

Coverage timeline
69
first 2026-05-04 → last 2026-08-02
Peak priority
critical
2 critical · 24 high · 43 notable
Sources cited
168
88 hosts
Sections touched
13
active-threats, deep-dive, research
Co-occurring entities
8
see Related entities below
ATT&CK techniques
27
pinned v19.2 · see below
2026-05-0469 appearances2026-08-02

ATT&CK techniques

27 techniques observed across 23 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1598.004Phishing for Information: Spearphishing Voice×2

Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×4

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-07-28/ey-itsm-breach-shinyhunters-attribution-claim · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×9

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i +3 more · ATT&CK page ↗

T1190Exploit Public-Facing Application×9
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1199Trusted Relationship×4

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-07-28/ey-itsm-breach-shinyhunters-attribution-claim · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×7

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i +1 more · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×4

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-07-28/ey-itsm-breach-shinyhunters-attribution-claim · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×9

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i +3 more · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×3

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×4

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-07-28/ey-itsm-breach-shinyhunters-attribution-claim · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×9

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i +3 more · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×4

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-07-28/ey-itsm-breach-shinyhunters-attribution-claim · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×9

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i +3 more · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · ATT&CK page ↗

Defense Impairment TA0112

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×3

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×4
T1552.004Unsecured Credentials: Private Keys×1

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×3

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1606.002Forge Web Credentials: SAML Tokens×1

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

T1621Multi-Factor Authentication Request Generation×1

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · ATT&CK page ↗

T1021.004Remote Services: SSH×2

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/shinyhunters-peoplesoft-campaign-oracle-confirms-cve-2026-35 · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×3

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1213.002Data from Information Repositories: Sharepoint×3

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Evidence: 2026-08-02/weekly-w31-shinyhunters-sso-as-tier-zero · 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-05-29/carnival-corporation-confirms-5-99-m-record-shinyhunters-bre · ATT&CK page ↗

T1530Data from Cloud Storage×3
T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×5

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

Story timeline

  1. 2026-08-02ShinyHunters status: a sector ISAC formalised the helpdesk-vishing-to-SSO chain as a written advisory and told defenders to protect the identity provider like a domain controller, while deliberately declining to name victims
    weekly-long-runningShinyHunters status — a sector advisory makes SSO the control plane, and declines to publish a victim tally
  2. 2026-08-02Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse
    weekly-incidents-recapW31's extortion claims ran ahead of the facts in both directions — over-claiming actors, one real breach inside
  3. 2026-07-31Health-ISAC tells the health sector to treat SSO as Tier 0 against ShinyHunters, and deliberately declines to name victims — the pattern, not the tally, is the advisory's point
    updatesA sector advisory formalises the helpdesk-vishing-to-SSO-takeover chain, as another confirmed victim shows the same Entra voice-phishing entry
  4. 2026-07-28ShinyHunters claims the Ernst & Young ITSM breach and asserts the stolen third-party credentials reached Jira, GitHub and Azure
    updatesShinyHunters claims the EY support-platform breach and alleges reach far beyond the disclosed ticket data
  5. 2026-07-19The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access
    weekly-multi-dayIdentity attacks converged on abusing trust, not breaking it — OAuth/SSO vishing, a client_id oracle, a Moodle JWT forgery, and helpdesk-vishing resets
  6. 2026-07-18Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
    active-threatsAbbott confirms unauthorized access to its Cancer Diagnostics (Exact Sciences) systems as ShinyHunters claims a helpdesk-vishing to Entra SSO breach
  7. 2026-07-16CVE-2026-46817 — Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)
    trending-vulnerabilitiesOracle E-Business Suite Payments pre-auth takeover (CVE-2026-46817) confirmed exploited and KEV-listed — patch or pull exposed instances off the internet
  8. 2026-07-14Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability
    researchMicrosoft maps a year of Salesforce OAuth abuse — vishing consent, supply-chain secret reuse, guest-access Aura abuse — invisible to sign-in detection
  9. 2026-07-12This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim
    weekly-incidents-recapW28 incidents cluster on third-party / cloud-account exposure — Accenture, Deutsche Bank vendor, KDDI, Nayax cloud account, Odido vishing, Nextcloud misconfig
  10. 2026-07-12Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it
    weekly-multi-dayM365 identity attacks converged this week — device-code, AiTM PhaaS, ROPC spray and vishing all bypass MFA/Conditional Access by sidestepping it
  11. 2026-07-10ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
    active-threatsDutch police tie ShinyHunters' Odido telecom breach to Dutch nationals via voice analysis — the vishing-to-spoofed-portal playbook now hits an EU telco
  12. 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
    active-threatsReliaQuest: new 'Helix' extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint
  13. 2026-07-05ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces
    weekly-long-runningShinyHunters / UNC6240 Oracle campaign status — Nissan named, notifications still landing
  14. 2026-07-05Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign
    weekly-top-storiesTwo internet-facing Oracle enterprise product lines under active exploitation this week — EBS RCE + PeopleSoft
  15. 2026-07-05Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered
    weekly-incidents-recapExtortion without encryption matures — a US county paid ~$1M to Kairos, no encryptor recovered
  16. 2026-07-05Looking ahead — 2026-W27
    weekly-looking-aheadLooking ahead — 2026-W27: items already in motion for the coming weeks
  17. 2026-07-03Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containment
    active-threats
  18. 2026-07-01Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation
    deep-dive
  19. 2026-07-01Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign
    updates
  20. 2026-06-29ShinyHunters / UNC6240 Oracle PeopleSoft campaign
    weekly-long-running
  21. 2026-06-29ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week
    weekly-multi-day
  22. 2026-06-29NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall
    weekly-top-stories
  23. 2026-06-29Looking ahead — 2026-W26
    weekly-looking-ahead
  24. 2026-06-29Education
    weekly-sector-patterns
  25. 2026-06-28NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
    active-threats
  26. 2026-06-27UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paid
    active-threats
  27. 2026-06-26ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
    active-threats
  28. 2026-06-22ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure
    weekly-multi-day
  29. 2026-06-22Public administration — named European institutions and government data in the firing line
    weekly-sector-patterns
  30. 2026-06-22Looking ahead — 2026-W25
    weekly-looking-ahead
  31. 2026-06-22Education — exposed CMS and forum software stack a structural risk
    weekly-sector-patterns
  32. 2026-06-22CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)
    weekly-vuln-rollup
  33. 2026-06-21Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
    active-threats
  34. 2026-06-20Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
    active-threats
  35. 2026-06-16Council of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaign
    updates
  36. 2026-06-14Education — ShinyHunters' PeopleSoft campaign lands disproportionately on universities
    weekly-sector-patterns
  37. 2026-06-14CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest
    weekly-top-stories
  38. 2026-06-14CrowdStrike 2026 Technology Threat Landscape Report — "technology = most-targeted" reads as prophecy against this week's incidents
    weekly-annual-reports
  39. 2026-06-13Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest
    updates
  40. 2026-06-13CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session
    trending-vulnerabilities
  41. 2026-06-12ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
    updates
  42. 2026-06-12CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
    trending-vulnerabilities
  43. 2026-06-11ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
    deep-dive
  44. 2026-06-05ShinyHunters extortion campaign adds DentaQuest — 234 GB published after refusal to pay, 2.6 M dental-benefit records exposed
    updates
  45. 2026-06-02ShinyHunters publishes the Charter Communications dataset after ransom refusal
    updates
  46. 2026-06-01ShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit records
    weekly-incidents-recap
  47. 2026-06-01Healthcare — HIPAA breach + healthcare supply-chain exposure
    weekly-sector-patterns
  48. 2026-05-29Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands
    active-threats
  49. 2026-05-27ShinyHunters Salesforce campaign — Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
    active-threats
  50. 2026-05-25ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized
    weekly-long-running
  51. 2026-05-25ShinyHunters lists Charter Communications (Spectrum) — telco victim in the Salesforce-credential campaign
    updates
  52. 2026-05-19Grafana Labs CoinbaseCartel breach — victim confirms source-code-only theft, no customer data, ransom rejected
    active-threats
  53. 2026-05-197-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
    active-threats7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel
  54. 2026-05-18Education — virtual-classroom platforms and EdTech SaaS exposure
    weekly-sector-patterns
  55. 2026-05-187-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records
    weekly-incidents-recap
  56. 2026-05-16GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
    active-threats
  57. 2026-05-13Instructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransom
    updates
  58. 2026-05-12Instructure (Canvas LMS) — ransom paid to ShinyHunters with "shred logs"; second intrusion confirmed; per-institution leak deadline reset to today
    updates
  59. 2026-05-11TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence
    weekly-long-running
  60. 2026-05-11TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak
    weekly-multi-day
  61. 2026-05-11Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation
    weekly-long-running
  62. 2026-05-11Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited
    weekly-multi-day
  63. 2026-05-10Canvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9
    updates
  64. 2026-05-09Inditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
    active-threats
  65. 2026-05-04ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas
    weekly-multi-day
  66. 2026-05-04ShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)
    weekly-long-running
  67. 2026-05-04Looking ahead — 2026-W19
    weekly-looking-ahead
  68. 2026-05-04Europol IOCTA 2026
    weekly-annual-reports
  69. 2026-05-04Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects
    weekly-multi-day

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

overlaps with

attributed activity

Where this entity is cited

  • active-threats15
  • updates12
  • weekly-multi-day8
  • weekly-long-running7
  • weekly-sector-patterns6
  • weekly-incidents-recap5
  • weekly-looking-ahead4
  • trending-vulnerabilities3
  • weekly-top-stories3
  • weekly-annual-reports2
  • deep-dive2
  • weekly-vuln-rollup1
  • research1

Source distribution

  • bleepingcomputer.com23 (14%)
  • securityweek.com12 (7%)
  • theregister.com8 (5%)
  • attack.mitre.org6 (4%)
  • msrc.microsoft.com5 (3%)
  • securityaffairs.com4 (2%)
  • therecord.media4 (2%)
  • cloud.google.com3 (2%)
  • other103 (61%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (168)

Entries about ShinyHunters (69)

2026-08-02 · view entry permalink →

NOTABLENATOB2

ShinyHunters status: a sector ISAC formalised the helpdesk-vishing-to-SSO chain as a written advisory and told defenders to protect the identity provider like a domain controller, while deliberately declining to name victims

Prior weeklies carried ShinyHunters inside a wider pattern of identity intrusions that abuse a trusted relationship rather than breaking authentication. The status change this week is that a sector body wrote the chain down and issued guidance on it, which moves it from a pattern analysts recognise to an obligation a sector has been told about.

Health-ISAC's advisory sets out the sequence this pipeline has watched repeatedly: voice phishing directed at helpdesk staff, an MFA reset, password reset or device re-enrolment performed without out-of-band identity proofing, takeover of the Entra, Okta or Google SSO account, then lateral movement into connected SaaS platforms and bulk exfiltration used as pure extortion leverage with no encryption stage. Its central assertion is architectural: "SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale." (Health-ISAC, 2026-07-24). The advisory's guidance follows from that premise — the identity provider is to be protected with the controls an organisation reserves for its most privileged infrastructure rather than treated as an application.

The advisory's second notable property is what it withholds. It names no victims and publishes no tally, and the reporting on it is explicit that "the advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase" (BleepingComputer, 2026-07-29). For an actor whose entire leverage model is publicity, that is a deliberate editorial choice with an operational rationale: a victim count is a number a defender cannot act on, whereas the reset-without-proofing step is one they can go and close. It also sidesteps the calibration problem this week's incident reporting ran into elsewhere, where the actor's claims outpaced what victims would confirm.

Two in-window developments sit alongside the advisory and illustrate that gap rather than closing it. Brinks Home confirmed an intrusion detected on 2026-07-20 and was precise about the boundary of the impact, stating that "the intrusion did not impact in any way the company's alarm monitoring and system functionality" (BleepingComputer, 2026-07-30); ShinyHunters separately claims the intrusion began with an Entra voice-phishing call, which the company has not confirmed. And on the Ernst & Young breach the actor claims the stolen third-party credentials reached Jira, GitHub and Azure environments, far beyond the support-ticket attachments EY acknowledged — a claim carried with an explicit caveat: "BleepingComputer has no way to verify the threat actor's claims independently, and Ernst & Young has not confirmed that ShinyHunters was behind the attack." (BleepingComputer, 2026-07-27).

Triage: the chain produces no exploitation and no malware, so the detectable sequence is entirely in identity telemetry, and each step alone is legitimate. The discriminating pattern is proximity in time between three events on one account: a helpdesk-performed credential or MFA change, a first successful authentication from a device or address that account has never used, and bulk read or export activity across connected SaaS applications shortly afterwards. Individually these are a support ticket, a new laptop, and a busy analyst; in sequence within a short window they are this campaign. A helpdesk-initiated MFA reset on an account that had a working second factor registered minutes earlier is the highest-value single indicator, because a genuine reset request usually follows a genuine loss of access.

SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale.

Health-ISAC 2026-07-24

The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase.

The intrusion did not impact in any way the company's alarm monitoring and system functionality.

BleepingComputer has no way to verify the threat actor's claims independently, and Ernst & Young has not confirmed that ShinyHunters was behind the attack.

BleepingComputer 2026-07-29

Builds on: 2026-07-31/health-isac-shinyhunters-sso-tier0-advisory-brinks-home · 2026-07-28/ey-itsm-breach-shinyhunters-attribution-claim · 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data

synthesis02 Aug 23:59Zmulti-sourceOpen finding ↗

2026-08-02 · view entry permalink →

NOTABLENATOB2

Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse

A SOC that ingests leak-site and extortion-claim feeds spent this week being tested on a specific skill: holding a claim and a confirmation apart while acting on neither prematurely. Four disclosures pulled in different directions.

The hardest case is ExfilSquad, because the answer is not "fabricated" or "real" but both at once. The brand's Tor leak site first appeared on 2026-07-26 with 15 named victims, and SOCRadar's assessment of the list as a whole is that "the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely" (SOCRadar, 2026-07-28). Inside that list sits a fully confirmed government compromise: the UK Department for Education acknowledged that two public-facing portals were breached and that the Police National Legal Database was affected, exposing "135,000 pieces of data potentially identifying the names, forces and work email addresses of police officers" (The Record, 2026-07-30) — while pushing back on the criminals' own headline number, clarifying that the claimed 600,000 items are lines of data rather than individuals. A triage process that discounted the whole list on the vendor's fabrication assessment would have missed a real breach of a police database; one that accepted it wholesale would have chased fourteen phantoms.

Everest's Stadler Rail publication is the over-claiming case, and the claim is the part that would matter most if true. TechNadu reports that "Everest claims the compromised data touches projects linked to several high-profile operators, including Deutsche Bahn, Merseytravel, Westbahn, and MTR, alongside other unnamed clients", and immediately qualifies it: "if validated, exposure of engineering documentation and system configurations tied to these operators raises concerns around downstream risk to connected railway infrastructure" (TechNadu, 2026-07-29). No second outlet reports it independently, none of the four named operators has confirmed it, and Stadler's own release continues to state that it lost no data through the mid-July incident while attributing the access to compromised credentials for a data-exchange platform (Stadler Rail, 2026-07-21). A four-operator rail-infrastructure blast radius and a no-data-lost statement cannot both be complete accounts, and this week produced no evidence deciding between them.

The remaining two are attribution and reach claims with the same structure. ShinyHunters told BleepingComputer the EY credentials were obtained through a supply-chain attack and allowed access to EY's Jira, GitHub and Azure environments — a scope far beyond the support-ticket attachments EY acknowledged — and the outlet is explicit about the epistemic position: "BleepingComputer has no way to verify the threat actor's claims independently, and Ernst & Young has not confirmed that ShinyHunters was behind the attack." (BleepingComputer, 2026-07-27). And at Universitatea de Vest "Vasile Goldiş" din Arad, a Romanian public university confirmed an attack on its IT infrastructure while declining to say what was affected — "Universitatea nu a precizat, deocamdată, care sunt sistemele indisponibile și nici dacă au fost compromise sau extrase date personale", the university has not yet specified which systems are unavailable nor whether personal data was compromised or extracted (Radio România, 2026-07-28). A Qilin leak-site listing is the only thing linking any actor to it, and none of the Romanian reporting mentions that listing at all.

Triage: for an analyst holding a fresh listing, the discriminators that separated signal from noise this week were all external to the listing itself — whether any named victim has issued its own statement, whether a second outlet reports the claim independently or merely relays the same tracker post, whether the claimed data volume is expressed in a unit the actor chose (lines, files, gigabytes) rather than one the victim would recognise (individuals, records), and whether the actor's brand has a history predating the listing. ExfilSquad's site named fifteen victims on the very day it appeared, with no prior operating history behind the brand, which is itself the strongest single indicator on that list.

the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely

SOCRadar 2026-07-28

135,000 pieces of data potentially identifying the names, forces and work email addresses of police officers

The Record (Recorded Future News) 2026-07-30

Everest claims the compromised data touches projects linked to several high-profile operators, including Deutsche Bahn, Merseytravel, Westbahn, and MTR, alongside other unnamed clients. If validated, exposure of engineering documentation and system configurations tied to these operators raises concerns around downstream risk to connected railway infrastructure.

TechNadu 2026-07-29

BleepingComputer has no way to verify the threat actor's claims independently, and Ernst & Young has not confirmed that ShinyHunters was behind the attack.

BleepingComputer 2026-07-27

Builds on: 2026-07-31/exfilsquad-uk-department-for-education-pnld-breach · 2026-07-31/everest-publishes-stadler-rail-supplier-archive · 2026-07-28/ey-itsm-breach-shinyhunters-attribution-claim · 2026-07-29/uvvg-arad-romania-university-cyberattack-qilin-claim · 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach

incident02 Aug 23:57Zmulti-sourceOpen finding ↗

2026-07-31 · view entry permalink →

NOTABLEupdateNATOB1

Health-ISAC tells the health sector to treat SSO as Tier 0 against ShinyHunters, and deliberately declines to name victims — the pattern, not the tally, is the advisory's point

UPDATE · originally covered Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records (2026-07-18)

prior coverage tracked this actor's vishing-to-Entra-SSO tradecraft through the Abbott and Ernst & Young incidents as individual cases. The delta is that a sector body has now written the chain down as a pattern with a mitigation timeline attached, and that a fresh confirmed intrusion shows the same entry point (BleepingComputer, 2026-07-29).

Health-ISAC's advisory describes the chain end to end: voice phishing directed at helpdesk staff, leading to a password reset, MFA reset or device re-enrolment carried out without out-of-band identity proofing, giving the caller a legitimate Entra, Okta or Google SSO session; from there the operators pivot into the connected SaaS estate — Salesforce, Microsoft 365, SharePoint, ServiceNow, Teams — and exfiltrate in bulk. There is no encryption stage; the stolen data is the entire extortion instrument. Its own summary of why this works is the line worth quoting to a steering committee: SSO is the control plane, and the leverage comes from data theft at cloud scale. It recommends treating Entra, Okta and equivalent identity infrastructure as Tier 0, locked down the way a domain controller is, with a 30-to-60-day action list covering phishing-resistant MFA for high-risk users, hardened helpdesk reset procedures with verified callback, a conditional-access baseline blocking legacy authentication, SaaS-exfiltration detection on bulk downloads, API anomalies and OAuth-consent changes, and a tested token- and session-revocation playbook (Health-ISAC, 2026-07-24).

Two things about how the advisory is written are as informative as its content. It names no victims at all — BleepingComputer states directly that it does not identify affected organisations, disclose how many incidents have been observed, or give a timeframe for the increase, and the medtech and healthcare companies frequently listed alongside it come from BleepingComputer's own earlier reporting rather than from the advisory. And Health-ISAC cautions that not every data-theft claim has been verified, directing defenders at the attack pattern rather than at any specific tally. For a sector body facing an actor whose business model is publicising claims, declining to repeat the claims is a deliberate and defensible choice.

The fresh case landed the following day. Brinks Home confirmed, through its chief executive, that it detected an intrusion on 2026-07-20, engaged forensic experts, and that the intrusion did not affect its alarm monitoring or system functionality in any way; its own incident FAQ says it has not yet confirmed exactly what information was involved or whose (BleepingComputer, 2026-07-30). ShinyHunters claims the breach began on 13 July with a call convincing an employee to complete a Microsoft Entra authentication or registration process, and claims specific volumes of Salesforce, employee and support-chat data; BleepingComputer reports two different Salesforce record counts in the same article without reconciling them, and states it has not reviewed the data and could not verify the claims. The mechanism the actor describes matches the pattern the advisory documents, which is the reason to note it — the numbers are not established and are not treated here as though they were.

Detection. Everything useful sits in identity telemetry, and the shape is a sequence rather than an event. The trigger is a helpdesk-initiated credential or authenticator change — a password reset, an MFA method reset, or a new device registered against an existing account. What turns it into an incident is what follows within minutes to hours: a first successful sign-in for that account from a device, network or geography with no history, then enumeration and bulk retrieval against connected SaaS applications — large report exports, unusual API query volume against customer-record objects, new OAuth consent grants. Instrument the join between the reset event and the next sign-in, because either half alone is ordinary.

Triage: a locked-out user calling the helpdesk and having their MFA reset is one of the most common legitimate identity events in any organisation, and it looks identical to this attack up to the moment the reset completes. The discriminator is not in the endpoint or the network — it is whether identity was proven out of band, by a callback to a number already on record rather than a number the caller supplied, and whether the sign-in that follows the reset comes from anywhere the account has been before. Where the helpdesk's own process logs that verification step, the absence of it on a given ticket is the highest-fidelity signal available.

SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale.

Health-ISAC 2026-07-24

The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase.

The intrusion did not impact in any way the company's alarm monitoring and system functionality.

BleepingComputer 2026-07-29
threat31 Jul 04:09Zmulti-sourceOpen finding ↗

Earlier coverage (66)

2026-07-28NOTABLEupdateNATOB3ShinyHunters claims the Ernst & Young ITSM breach and asserts the stolen third-party credentials reached Jira, GitHub and AzureShinyHunters added Ernst & Young to its leak site on 2026-07-27, claiming responsibility for the third-party ITSM support-platform breach EY disclosed on 2026-07-15 and telling BleepingComputer the credentials were obtained through a supply-chain attack and allowed it into EY's Jira, GitHub and Azure environments — a scope far beyond the support-ticket attachments EY acknowledged. EY has not confirmed the attribution or the claimed reach, and BleepingComputer states it cannot verify the actor's assertions. The transferable point for anyone who outsources IT helpdesk or ticketing is the claimed pivot itself: credentials held by a support platform are worth scoping as reaching everything they can authenticate to, not just the tickets they were issued for.2026-07-19HIGHNATOA1The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account accessFive independent 2026-W29 disclosures describe the same identity-intrusion pattern from different angles: none broke authentication cryptographically — each abused a trusted OAuth grant, token, or human process to obtain valid-account access that sign-in-anomaly detection barely sees. Microsoft mapped a year of ShinyHunters-associated Salesforce OAuth abuse (vishing-driven malicious consent, SaaS supply-chain secret reuse, guest-access Aura abuse), and the same actor's vishing-to-Entra-SSO tradecraft surfaced in the Abbott/Exact Sciences intrusion. Proofpoint documented OAuth client_id spoofing that turns an Entra ID "application not found" error into a credential-validity oracle while leaving a blank application name in the sign-in log. CVE-2026-54733 in Moodle's official Microsoft 365 plugin authenticated forged JWTs without ever verifying the signature — knowing any user's email yielded full site takeover. And the Scattered Spider TfL sentencing put the credential-purchase → helpdesk-vishing → MFA-reset chain into the court record. This extends the M365 auth-flow convergence the prior weekly documented (device-code, ROPC, AiTM) into the OAuth-trust, token-forgery and helpdesk-process layer — the controls that catch it are consent governance, token/grant hardening and helpdesk identity-proofing, not stronger MFA.2026-07-18NOTABLENATOA3Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ recordsAbbott Laboratories confirmed (2026-07-16) unauthorized access to a limited number of internal systems in its Cancer Diagnostics business (the acquired Exact Sciences unit) only. Separately, the ShinyHunters extortion group claims the intrusion began with a vishing call that compromised a Microsoft Entra ID single-sign-on account, then used it to pull 30M+ records from Entra, ServiceNow, SharePoint, Databricks and Coupa — a claim Abbott has neither confirmed nor attributed. The confirmed incident plus the same vishing-to-cloud-SSO tradecraft this actor uses against SaaS-integrated enterprises makes it relevant to healthcare and any SharePoint/Entra-dependent estate.2026-07-16HIGHexploitedNATOA1CVE-2026-46817 — Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on 2026-07-15, the first formal confirmation of active exploitation for an unauthenticated flaw in the File Transmission component of Oracle Payments (the payment engine inside Oracle E-Business Suite 12.2.3–12.2.15) that Oracle patched quietly in its May 2026 Critical Patch Update. It is reachable over plain HTTP with no authentication (CVSS 9.8); any internet-facing EBS instance not on the May fix should be patched or taken off the public internet now, and treated as potentially compromised if it was exposed after 2026-05-28.2026-07-14NOTABLENATOB2Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerabilityMicrosoft Threat Intelligence documented a year (mid-2025 to mid-2026) of campaigns using ShinyHunters-associated tradecraft (registry alias UNC6240) against Salesforce-integrated SaaS environments via three intrusion paths: vishing-driven malicious-OAuth-consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138's June 2026 Klue compromise), and guest-access Aura abuse. None exploited a Salesforce flaw — all abuse trusted OAuth relationships, so sign-in-anomaly detection gives limited visibility.2026-07-12NOTABLENATOB1This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victimThe week's confirmed incidents share a structural theme: the initial exposure sat in a cloud account, a third-party vendor, or a supplier platform rather than the victim's own perimeter. Accenture confirmed data theft after '888' advertised internal source code; Deutsche Bank disclosed a third-party vendor incident after 'Unsafe' ransomware claims; KDDI named a third-party-software zero-day as the root cause of its 12M-record ISP email breach; Nayax (an EEA payment institution) disclosed a cloud-account incident claimed by 'The Syndicate'; ShinyHunters' Odido (NL telecom) breach drew Dutch-national-involvement attribution from police voice analysis; and Nextcloud GmbH's own hosting exposed 367K records via a misconfigured Elasticsearch. Supplier and cloud-account risk, not perimeter RCE, drove the week's disclosures.2026-07-12HIGHNATOB1Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking itFour independent 2026-W28 disclosures describe the same M365 account-takeover pattern from different angles: Huntress' root-cause comparison of the Railway (device-code) and LSHIY (ROPC spray) campaigns, where 55 of 78 LSHIY-compromised accounts had CA policies requiring MFA that failed on scoping gaps; the Forg365 AiTM phishing-as-a-service kit; and the Helix data-extortion cluster pairing manager-impersonation vishing with device-code phishing. None defeats MFA cryptographically — each exploits an auth flow (device-code, ROPC/legacy, token replay) that a typical Conditional Access policy does not gate. Every M365 tenant should block device-code and ROPC where unused and confirm CA covers all cloud apps and client-app types.2026-07-10HIGHNATOB2'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltrationReliaQuest documented a previously unreported data-extortion cluster it calls Helix, assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting infrastructure. Operators phone a target impersonating their named manager (spoofed caller-ID), walk them through an Entra ID device-code sign-in that captures a session token without a password and sidesteps Conditional Access, register a new Authenticator within minutes for persistence, then run automated SharePoint enumeration and bulk exfiltration. SharePoint + Entra ID is the default identity/collaboration stack across Swiss and EU public-sector tenants, so the playbook is directly reachable; disabling the device-code flow is the single highest-impact control.2026-07-10NOTABLENATOA2ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telcoDutch National Police announced on 9 July 2026 that its investigation into the February 2026 ShinyHunters breach of telecom operator Odido (and its Ben brand) found strong indications of Dutch-national involvement, based on forensic voice analysis of a call recorded during the intrusion. The intrusion used the ShinyHunters playbook already tracked in this store: a vishing call impersonating IT staff persuaded a customer-service employee to authenticate into a spoofed corporate portal, harvesting credentials used to bulk-export 6.2M+ customer records before the account was blocked within an hour. The new signal is the EU-telco victim, the law-enforcement attribution, and two open Dutch DPA investigations; the underlying TTP is the ShinyHunters playbook already tracked in this store.2026-07-05NOTABLENATOB2Looking ahead — 2026-W27Items already in motion, not predictions: six Adobe ColdFusion CVSS 10.0 RCEs await weaponisation (patch before a PoC lands); CitrixBleed-lineage NetScaler CVE-2026-8451 has a public test artefact and its siblings exploited within days; WatchGuard Firebox 12.5.x still lacks a fix; the Dutch NIS2 Senate vote is set for 7 July with entry into force 15 August; ShinyHunters PeopleSoft notifications keep landing across an un-notified EU tail; and SOCRadar's claimed FortiBleed-actor Nextcloud zero-day awaits vendor disclosure.2026-07-05NOTABLEexploitedupdateNATOB1ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfacesThe ShinyHunters/UNC6240 Oracle PeopleSoft campaign (CVE-2026-35273) added Nissan as its largest named victim this week — employee HR/payroll PII across four countries — while GTIG notifications keep landing across the ~100-organisation tail. Separately, Medtronic is notifying ~9M people of a ShinyHunters-claimed April corporate-IT breach (not attributed to the PeopleSoft path). The campaign remains an active, victim-acquiring, zero-day-capable ERP-extortion operation.2026-07-05NOTABLENATOB2Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recoveredThis week's clearest extortion signal is the continued decoupling of extortion from encryption: a Ransom-ISAC retrospective details a US county government that paid ~$1M to the data-theft actor Kairos with no encryptor recovered in the case, MedusaLocker ran pure data-leak listings, and the ShinyHunters cluster continues to extort on exfiltration alone. For public-sector defenders the implication is that backup-and-restore resilience no longer bounds the impact — the leverage is disclosure, so data-exfiltration detection and minimisation matter as much as recovery.2026-07-05HIGHexploitedNATOB2Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaignOracle E-Business Suite CVE-2026-46817 (pre-auth RCE in the Payments File Transmission servlet, CVSS 9.8) saw its first confirmed in-the-wild exploitation this week, landing while the separate ShinyHunters Oracle PeopleSoft campaign (CVE-2026-35273) kept acquiring named victims. The operational reality for a public-sector or higher-education estate: treat every internet-reachable Oracle application tier — EBS, PeopleSoft, and their web front ends — as a priority patch-and-isolate target, not just the specific CVE.2026-07-03HIGHMedtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containmentMedtronic is notifying ~9 million people of a ShinyHunters-claimed April breach of corporate IT systems (names, DOB, SSNs, health data), 2.5 months after containment; it says medical devices were unaffected and segregated from the compromised networks (BleepingComputer, 2026-07-02).2026-07-01NOTABLEexploitedOracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitationWhat it is. CVE-2026-46817 (CVSS 9.8) is an unauthenticated remote-code-execution flaw in the File Transmission component of Oracle Payments, part of Oracle E-Business Suite, affecting EBS 12.2.3 through 12.2.15.2026-07-01HIGHexploitedupdateNissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaignThe ShinyHunters Oracle PeopleSoft campaign adds Nissan as its largest named victim yet — current and former employee HR/payroll PII across four countries, a different exposure profile than the NAIC breach covered 2026-06-28 (SecurityWeek, 2026-06-30).2026-06-29NOTABLELooking ahead — 2026-W26ShinyHunters PeopleSoft notifications are still landing — expect more named European education and public-finance victims. GTIG has notified ~100 organisations (68% higher education) and NAIC is the fresh high-profile case; patch internet-reachable PeopleSoft and hunt /PSEMHUB/ and /PSIGW/HttpListeningConnector.2026-06-29NOTABLEexploitedShinyHunters / UNC6240 Oracle PeopleSoft campaignThe campaign behind the § 1 NAIC breach.2026-06-29NOTABLEEducationEducation was a structural victim class. The ShinyHunters Canvas/Instructure breach hit 160 UK universities per the UK CMC sector review (ransom paid, limited downstream damage).2026-06-29NOTABLEShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one weekThe week is a compact case study in how a single extortion cluster's reported activity spans very different initial-access tradecraft.2026-06-29HIGHexploitedNAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stallNAIC breached through an Oracle PeopleSoft zero-day (CVE-2026-35273); ShinyHunters dumps 3.1 TB and US rating-agency feeds stall — the same UNC6240 campaign GTIG has tracked against ~100 orgs (68% higher education) is still acquiring victims; treat internet-reachable PeopleSoft as assume-compromise. (daily 06-28, NAIC)2026-06-28HIGHexploitedNAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pauseNAIC — the standard-setting body for all 50 US state insurance regulators — confirms a breach via an Oracle PeopleSoft zero-day; ShinyHunters published ~3.1 TB of insurance regulatory and credit-rating-agency data, and rating-agency feeds paused, forcing NAIC to suspend assigning investment-risk designations. Part of a 100+ org PeopleSoft zero-day campaign; any organisation running Oracle PeopleSoft should verify patch status against the campaign (NAIC, 2026-06-26).2026-06-27NOTABLEUK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paidThe UK Cyber Monitoring Centre (CMC) published a post-incident sector review on 2026-06-25 of the April 2026 ShinyHunters (UNC6240) breach of Instructure's Canvas learning-management platform, which affected roughly 160 UK higher-education institutions (Computer Weekly, 2026-06-25).2026-06-26HIGHShinyHunters used a single vishing call into the company's identity platform to breach Madison Square GardenShinyHunters breached Madison Square Garden through a single vishing call into the company's identity platform — 404 Media's review of the stolen data confirms a low-level employee was talked into letting the operators into MSG's systems, the same vishing → identity-platform (Entra/Okta) → MFA-enrollment kill chain that works equally well against EU public-sector tenants (404 Media, 2026-06-24).2026-06-22NOTABLELooking ahead — 2026-W25RoguePlanet (CVE-2026-50656) has no patch and a PoC that works on June builds — watch MSRC for an out-of-band fix. Microsoft says a fix is "in development" with no timeline; the researcher warns mitigations are not reliable.2026-06-22NOTABLEEducation — exposed CMS and forum software stack a structural riskEducation entities sat under two pressures this week: the continuing ShinyHunters PeopleSoft campaign that W24 documented landing disproportionately on universities, and a cluster of critical web-application CVEs in software ubiquitous across European universities and student communities — JCE for Joomla …2026-06-22NOTABLEPublic administration — named European institutions and government data in the firing lineThe public sector again carried high-severity activity on multiple vectors. The Council of Europe — a Strasbourg human-rights body of which Switzerland is a member — was named in the ShinyHunters PeopleSoft campaign (§ 2).2026-06-22NOTABLECVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)Oracle's June Critical Security Patch Update shipped 245 fixes on 2026-06-17, around 100 remotely exploitable without authentication, headlined by an unauthenticated Solaris Remote Administration Daemon flaw (CVE-2026-46978, CVSS 10.0) and a PeopleSoft RCE (CVE-2026-35278, 9.8) (Oracle CSPU; daily 06-18).2026-06-22HIGHShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressureShinyHunters named the Council of Europe in the Oracle PeopleSoft campaign — a European institution of which Switzerland is a member — while adding Kodak and One Medical to its leak-site pressure. (daily 06-16, SecurityWeek)2026-06-21NOTABLEAmazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires todayOne Medical (Amazon) confirmed on 2026-06-13 that an unauthorised party accessed a legacy third-party file-storage system retaining archived records for One Medical Seniors (formerly Iora Health), during a 2026-06-08 to 2026-06-11 window, affecting demographic and clinical records for patients at nine clinics …2026-06-20NOTABLEKodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publicationEastman Kodak acknowledged on 17 June 2026 that "an unauthorized third party illegally gained access to a limited amount of company data," after ShinyHunters listed it on their dark-web leak site on 15 June claiming 2.2 million PII records and set an 18 June contact deadline (SecurityWeek, 2026-06-18 …2026-06-16HIGHupdateCouncil of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaignCouncil of Europe breached via the Oracle PeopleSoft zero-day (CVE-2026-35273) — ShinyHunters claims 297 GB / ~429,000 files and set a 16 June leak deadline; the first European intergovernmental victim named in the 100+-organisation PeopleSoft campaign (§ 4 update). (SecurityWeek, 2026-06-15)2026-06-14NOTABLECrowdStrike 2026 Technology Threat Landscape Report — "technology = most-targeted" reads as prophecy against this week's incidentsCrowdStrike's report (published 9 June, distilled in the 06-11 daily) found technology to be the most-targeted sector. Rather than re-recap it, the weekly's lens is corroboration: this very week supplied the evidence.2026-06-14NOTABLEEducation — ShinyHunters' PeopleSoft campaign lands disproportionately on universitiesThe week's clearest sectoral concentration. Mandiant/GTIG's attribution of the Oracle PeopleSoft zero-day campaign (§ 1) explicitly noted that the education sector was hit hardest, with the University of Nottingham confirming ~455,000 affected records (Google GTIG; daily 06-13).2026-06-14HIGHexploitedCVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardestShinyHunters' Oracle PeopleSoft campaign was vendor-confirmed as a zero-day and attributed to UNC6240, with education hit hardest. Oracle shipped an out-of-band fix for CVE-2026-35273; the University of Nottingham quantified 455,000 records; Mandiant/GTIG put 100+ organisations in scope. (daily 06-12, daily 06-13, Google GTIG)2026-06-13CRITICALexploitedupdateOracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardestOracle PeopleSoft CVE-2026-35273 confirmed exploited as a zero-day since 27 May; 100+ orgs hit, 68% higher education. Mandiant/GTIG attributes the unauthenticated SSRF→RCE campaign against the PeopleSoft Environment Management Hub to UNC6240 (ShinyHunters); the University of Nottingham confirmed 454,600 student records stolen. CISA added it to KEV on 12 June. Swiss/EU universities running PeopleTools 8.61/8.62 (Campus Solutions) are squarely in scope (Mandiant/GTIG, 2026-06-11).2026-06-13HIGHCVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician sessionSimpleHelp RMM ships an unauthenticated OIDC auth-bypass (CVE-2026-48558). A forged unsigned OIDC token yields a full technician session and bypasses IdP MFA — a clean initial-access vector into every downstream MSP-managed estate (Horizon3.ai, 2026-06-12).2026-06-12CRITICALexploitedupdateShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 recordsOracle confirms the PeopleSoft zero-day: CVE-2026-35273, pre-auth RCE (CVSS 9.8) in the Environment Management Hub, out-of-band patch released. Mandiant attributes the 100+-organisation data-theft campaign to UNC6240 (ShinyHunters) with an exploitation window of 27 May – 9 June (Mandiant GTIG, 2026-06-11). Patch and compromise-assess — exploitation predates the fix.2026-06-12NOTABLECVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)Fortinet patched CVE-2026-25089 (CWE-78, internal reference FG-IR-26-141) on 9 June: the FortiSandbox web interface's "start VNC" handler passes attacker-controlled JSON to the underlying OS without sanitisation, allowing a remote unauthenticated attacker to achieve second-order command injection via a crafted HTTP …2026-06-11HIGHShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltrationShinyHunters claims Oracle PeopleSoft data theft at 100+ organisations across ~300 instances, mostly in higher education; the University of Nottingham confirmed student and alumni data was accessed (BleepingComputer, 2026-06-10). Post-access lateral movement abuses default PeopleSoft/Oracle SSH service accounts — see the deep dive.2026-06-05NOTABLEupdateShinyHunters extortion campaign adds DentaQuest — 234 GB published after refusal to pay, 2.6 M dental-benefit records exposedUPDATE (originally covered 2026-06-02): DentaQuest, a Sun Life subsidiary administering dental and vision benefits for ~35 M US Medicaid, Medicare and employer-plan members, is the latest confirmed named victim of the ShinyHunters data-extortion campaign last covered here on the Charter Communications listing.2026-06-02NOTABLEupdateShinyHunters publishes the Charter Communications dataset after ransom refusalUPDATE (originally covered 2026-05-27): After Charter Communications declined to pay, ShinyHunters published the stolen dataset on 30 May. Have I Been Pwned ingested it as 4.9 million unique email addresses, alongside names, phone numbers and physical addresses (Security Affairs, 2026-05-30 · Have I Been Pwned).2026-06-01NOTABLEShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit recordsDentaQuest (Sun Life subsidiary, administering dental/vision benefits for ~35 M US Medicaid and Medicare members) confirmed on 1 June that ShinyHunters published 234 GB of stolen data after ransom negotiations broke down (BleepingComputer, 2026-06-04; BankInfoSecurity; daily 2026-06-05).2026-06-01NOTABLEHealthcare — HIPAA breach + healthcare supply-chain exposureShinyHunters published the DentaQuest dataset this week: 234 GB, 2.6 million records in HIPAA-format ASC X12 claims interchange, including Medicaid IDs (BleepingComputer, 2026-06-04).2026-05-29HIGHCarnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brandsCarnival Corporation files substitute notices confirming a breach affecting 5,995,277 individuals (Maine AG filing; driver's-licence + passport numbers exposed across Princess / Holland America / Cunard / Costa per The Record). Maine AG records the breach occurring 2026-04-10 and discovered 2026-04-14 (single-employee-account social engineering); ShinyHunters claimed and ultimately published when ransom was refused.2026-05-27HIGHShinyHunters Salesforce campaign — Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affectedShinyHunters Salesforce extortion — two fresh victim confirmations. Charter Communications (Spectrum) confirmed a breach but disputes that sensitive PI or CPNI was taken (BleepingComputer, 2026-05-26), while 7-Eleven confirmed a breach affecting roughly 185,000 individuals — CyberInsider reports Social Security and driver's-licence numbers in the exposed set (CyberInsider, 2026-05-26); both trace to the vishing → Entra → Salesforce-Aura pattern.2026-05-25NOTABLEShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seizedComplementing the § 2 victim arc, horizon research confirms the campaign now lists 40+ confirmed or claimed victims (key: item:shinyhunters-salesforce-campaign-charter-and-7-eleven-both-c), with Canada Life (insurance carrier, UK/Ireland) and Pitney Bowes confirming breaches in the window, and …2026-05-25HIGHupdateShinyHunters lists Charter Communications (Spectrum) — telco victim in the Salesforce-credential campaignShinyHunters listed Charter Communications (Spectrum), claiming 42M records with a 27 May deadline — a fresh victim in the Salesforce-credential campaign tracked here via 7-Eleven (2026-05-19), and by our own tracking its first telco/ISP victim to respond publicly. Charter denies any "sensitive PI or CPNI" exfiltration, a denial calibrated to FCC categories; the 42M figure is the actor's unverified claim (CyberInsider, 2026-05-23).2026-05-19NOTABLEGrafana Labs CoinbaseCartel breach — victim confirms source-code-only theft, no customer data, ransom rejectedUPDATE (originally covered 2026-W21): Grafana Labs issued an official 2026-05-18 confirmation of the GitHub Pwn-Request breach previously reported in the 2026-W21 weekly summary (SecurityWeek, 2026-05-18; BleepingComputer, 2026-05-18; The Register, 2026-05-18).2026-05-19HIGH7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records (SecurityWeek, 2026-05-18). Part of the broader ShinyHunters Salesforce-targeting campaign with co-victims Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic — phishing / OAuth / misconfiguration, not Salesforce-product vulnerabilities.2026-05-18NOTABLE7-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records7-Eleven confirmed on 2026-05-18 that an unauthorised third party accessed franchise-application records (600,000+) in a breach ShinyHunters claimed in April 2026.2026-05-18NOTABLEEducation — virtual-classroom platforms and EdTech SaaS exposureBigBlueButton — the open-source virtual-classroom platform deployed across German DFN, Swiss SWITCH and pan-European GÉANT academic networks, including cantonal school deployments — disclosed three flaws (weak session-token randomness, API checksum bypass, SSRF) in bbb-web < 3.0.21 / < 3.0.23 (daily 2026-05-19).2026-05-16HIGHGTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrandGTIG analyses UNC6671 "BlackFile" vishing-driven AiTM extortion: real-time helpdesk impersonation → attacker-registered lookalike SSO portals → MFA token capture and rogue MFA device registration → programmatic SharePoint exfiltration of 1M+ files per victim via Python requests spoofing the Microsoft Office ClientAppId; DLS shutdown signals probable rebrand (Google Threat Intelligence Group, 2026-05-15).2026-05-13NOTABLEupdateInstructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransomUPDATE (originally covered 2026-05-12): Late on 2026-05-11, US House Homeland Security Committee Chairman Andrew Garbarino sent a formal letter to Instructure CEO Steve Daly ahead of the 2026-05-12 ShinyHunters extortion deadline, demanding a briefing by 2026-05-21 on the circumstances of both Canvas intrusions …2026-05-12HIGHupdateInstructure (Canvas LMS) — ransom paid to ShinyHunters with "shred logs"; second intrusion confirmed; per-institution leak deadline reset to todayInstructure paid ShinyHunters; double Canvas intrusion confirmed; per-institution leak deadline is today (2026-05-12). Ransom acknowledged and "shred logs" received for the platform-wide dataset; a second intrusion on 2026-05-07 defaced ~330 institution portals via the same Free-for-Teacher flaw, and ShinyHunters has now set a fresh per-institution payment deadline (The Register, 2026-05-12). European universities reliant on Canvas should treat the platform-wide settlement as legally unverifiable destruction.2026-05-11NOTABLECanvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigationFull coverage in § 2 (multi-day chain).2026-05-11NOTABLETeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistenceFull coverage in § 2 (multi-day chain).2026-05-11NOTABLECanvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploitedThe W19 weekly closed with the Canvas / Instructure extortion deadline of 2026-05-12 pending.2026-05-11HIGHexploitedTeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leakTeamPCP Mini Shai-Hulud wave 4 compromised 170+ npm packages / 400+ malicious versions per daily-brief tracking (TanStack, UiPath, Mistral AI, OpenSearch, OpenAI named); Datadog static analysis of the leaked Shai-Hulud framework source (2026-05-12 leak) surfaces previously-undocumented IDE-persistence hooks targeting .claude/settings.json and .vscode/tasks.json, plus OIDC token extraction from /proc/<pid>/mem to forge Sigstore provenance attestations. Provenance-only verification no longer separates malicious from legitimate publications. (Datadog Security Labs · Wiz Blog · daily 2026-05-13 UPDATE · daily 2026-05-15 UPDATE)2026-05-10HIGHupdateCanvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9Canvas/Instructure UPDATE — ShinyHunters claims a second intrusion despite the May 8 patch and "continued active access". Seven Dutch universities (VU Amsterdam, UvA, Erasmus, Tilburg, TU/e, Maastricht, Twente) executed emergency Canvas disconnects on/before 2026-05-09; Dutch DPA notified by VU Amsterdam. Original 2026-05-12 extortion deadline now two days away; Instructure rotated application keys and required customer API client re-authorisation.2026-05-09NOTABLEInditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromiseHave I Been Pwned confirmed on 2026-05-08 that 197,400 unique email addresses from Inditex (Zara's parent, headquartered in A Coruña, Spain) were exposed following a breach of a former third-party analytics provider.2026-05-04NOTABLELooking ahead — 2026-W19Canvas / Instructure extortion deadline — Tuesday 2026-05-12 (two days out). Second-intrusion claim against Instructure made 2026-05-08 despite the May 8 patches; seven Dutch universities disconnected; Dutch DPA and ICO engaged.2026-05-04NOTABLEShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)Current state: most-active operator family of 2026-W19. Confirmed parallel involvement across Vimeo/Anodot, Inditex/Zara/Anodot, ADT/Okta-SSO/Salesforce, and Canvas/Instructure (second-intrusion claim despite May 8 patches).2026-05-04NOTABLEEuropol IOCTA 2026The Internet Organised Crime Threat Assessment 2026 (published 2026-04-28) was Europol's first IOCTA to identify the interweaving of state-sponsored hybrid threats with criminal actors as the defining strategic risk for EU public-sector defenders.2026-05-04HIGHCanvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnectsCanvas / Instructure — second intrusion claim against Instructure on 2026-05-08 despite the May 8 patches; seven Dutch universities (VU Amsterdam, UvA, Erasmus, Tilburg, TU/e, Maastricht, Twente) executed emergency Canvas disconnects on or before 2026-05-09; the extortion deadline is 2026-05-12 (Tuesday). (Techzine EU · DutchNews.nl · daily 2026-05-10)2026-05-04NOTABLEShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / CanvasThe cross-day pattern most visible in 2026-W19 is the ShinyHunters / WorldLeaks operator family's role in four parallel third-party / SaaS-tier compromises with European footprint, all riding the third-party-analytics → cloud-data-warehouse → tenant-data-exfiltration pivot rather than direct attack on the victim's …