CTI Academy
Log in Create account

ShinyHunters: Aliases, Attacks and the 2026 Arrests

By CTI Academy Team

Aliases, a 2020-2026 timeline, ATT&CK-mapped TTPs and a claim-versus-confirmed reading of the 2026 ShinyHunters arrests, from a CTI analyst's desk.

Status as of 8 October 2026: one suspect is held in the Netherlands, a second is reportedly detained in Jordan, the FBI says "multiple subjects" have been arrested, no 2026 charges have been made public, and a ShinyHunters leak site was still posting new claimed victims on 1 October.

On 7 September 2026, Dutch police released a voice recording, a fragment of which was played on the TV programme Opsporing Verzocht. In it, a Dutch-speaking man calls the customer service desk of telecom operator Odido and introduces himself as a colleague from IT. He uses so much internal jargon that the employee believes him. The employee lands on a copy of Odido's login page and types a username, a password and then a verification code. According to the police, that call gave a criminal hacking and extortion group the data of more than six million Odido customers. Odido refused to pay, and the group posted the data on the dark web.

The release about the call does not name the group. Three weeks later, announcing the arrest of a 24-year-old Amsterdam man, the same police force described ShinyHunters as a criminal hacking and extortion group involved in many large data breaches, "such as those of Odido, Pornhub and TicketMaster." The same release says the man was not arrested in the Odido investigation, where police are still looking for leads, so nothing official ties him to that call.

If you arrived from a games search: this is not the Pokémon hobby of hunting rare "shiny" creatures, although the name and the Umbreon logo are borrowed from it. Below I map the group's aliases and its 2020 to 2026 timeline, separate what officials have confirmed from what the group claims, and map its methods to MITRE ATT&CK and to the controls that break them.

What Is ShinyHunters?

ShinyHunters is a financially motivated data theft and extortion group, and increasingly a brand, that steals large datasets and then sells them or threatens to publish them unless the victim pays. MITRE ATT&CK, which added it as group G1057 in July 2026, describes a collective "active since at least 2019 operating under the ShinyCorp persona" and associated with The Com, a loose online community whose members have also included Scattered Spider and LAPSUS$. The FBI's May 2026 public service announcement describes a group specializing in large-scale data breaches and extortion against tech, finance and retail companies.

The word "brand" matters. People tied to the name have been arrested in three separate waves: a French member was arrested in 2022 and sentenced in the US in 2024, four suspects were arrested in France in 2025, and two more were detained, one of them reportedly, in September 2026. The name kept working through all of it. Sekoia and Beazley Security put it bluntly in their 2026 history of the group: "ShinyHunters is less a group than a brand and business model that has outlived its founders."

For anyone doing cyber threat intelligence work, that changes the question. "Did ShinyHunters do this?" is too vague to answer. "Who got in, who stole the data, and who is extorting under the ShinyHunters name?" can be answered, and the answers are often three different sets of people.

The ShinyHunters Alias Map

Every major vendor tracks some slice of this activity under its own name, and the slices do not line up neatly. If vendor naming is new to you, read our explainer on threat actor naming conventions first.

Name Used by What it covers
ShinyHunters, ShinyCorp the group, press brand, leak site, extortion
UNC6240 Google, Mandiant the extortion activity
Bling Libra Unit 42 ShinyHunters
G1057 MITRE ATT&CK ShinyHunters
UNC6040 Google 2025 Salesforce vishing
UNC6661 Google 2026 SSO vishing
Storm-3121 Microsoft access for extortion
UNC5537 Mandiant 2024 Snowflake thefts, link not Mandiant's
UNC6395 Google 2025 Drift theft, not attributed
Scattered LAPSUS$ Hunters self-styled Telegram alliance persona

Alias map linking ShinyHunters to UNC6240, Bling Libra, G1057, access clusters and The Com, with claimed links dashed

Figure 1: Three kinds of names point at ShinyHunters. On the left, vendor names for the same actor. On the right, intrusion clusters that vendors say fed ShinyHunters-branded extortion (solid) or that are only linked by claims, police statements or analyst inference (dashed amber). In the middle, the self-declared Scattered LAPSUS$ Hunters alliance. Diagram: CTI Academy.

Two details trip people up. First, Google deliberately splits access from extortion. In its January 2026 report it tracks the callers as UNC6661 and UNC6671 and the extortion as UNC6240, "to enable a more granular understanding of evolving partnerships and account for potential impersonation activity." Second, cross-vendor names are not one-to-one. Microsoft says Storm-3121 "conducts initial access activity leading to ShinyHunters and Falcon extortion," and names no Google cluster. Google ties the Falcon brand to UNC6671, a cluster whose operations it assesses as independent of ShinyHunters, and one lure domain on Microsoft's list, passkeyhelpdesk[.]com, is one Google saw used against victims later claimed by Falcon and Helix. My reading, which neither vendor states: Storm-3121 probably overlaps at least two Google clusters, UNC6671 and the access activity that feeds UNC6240's ShinyHunters extortion. Write "overlaps with," not "equals."

A Timeline From 2020 to 2026

The figure puts six years on a proportional axis. Read the empty stretches too: 2022 and early 2023 were quiet while the first prosecution moved through the courts, and the brand came back larger each time.

Swimlane timeline of ShinyHunters campaigns, vendor research and arrests from 2020 to October 2026 on a proportional axis

Figure 2: ShinyHunters from 2020 to 2026, split into campaigns and claims, research and advisories, and arrests and court actions. Bars show activity periods from DOJ, FBI, Google or Microsoft reports; amber dashed dots are claims or contested links. The September and October 2026 events are expanded in Figure 5. Diagram: CTI Academy.

2020 to 2023: Selling Databases on RaidForums

The early ShinyHunters was a data broker. The US Justice Department says that between April 2020 and July 2021 "ShinyHunters posted sales of hacked data from more than 60 companies" on RaidForums, EmpireMarket and Exploit, sometimes threatening to leak files if a victim did not pay. The method was unglamorous: phishing emails, fake login pages, then searching the stolen data for credentials to more systems, such as cloud storage.

In May 2020 the group offered 91 million Tokopedia records for US$5,000 as part of a batch of more than 160 million records, and claimed to have stolen more than 500GB from Microsoft's private GitHub repositories, which Microsoft said it was investigating. Wattpad's breach exposed almost 270 million records in June 2020, and Flashpoint noted that ShinyHunters claimed the hack but denied leaking the public copy.

The AT&T case is the one I use to teach humility. In August 2021 ShinyHunters advertised what it said was data on 70 million AT&T customers, and AT&T denied the data came from its systems. In March 2024, after a similar dataset leaked for free, AT&T said it covered about 73 million current and former account holders, without saying whether it came from AT&T or a vendor; at the time it was unclear whether the leak was linked to the 2021 listing. A denial is a data point, not a verdict.

Sebastien Raoult, a French citizen known as "Sezyo Kaizen" who DOJ says helped build the phishing sites, was arrested in Morocco in 2022, extradited in January 2023 and, on 9 January 2024, sentenced in Seattle to three years in prison and more than US$5 million in restitution for conspiracy to commit wire fraud and aggravated identity theft. Researchers have also traced the crew back to the earlier GnosticPlayers group, but Sekoia stresses that this lineage "rests substantially on researcher attribution rather than on confirmed admission."

2024: Snowflake and the Brand as Megaphone

In 2024 the brand got bigger than its crew. Mandiant tracked the theft of data from Snowflake customer accounts as UNC5537: the attackers logged in with credentials from old infostealer infections, "some of which dated as far back as 2020," on accounts without MFA, and Mandiant and Snowflake notified about 165 potentially exposed organizations. Our guide to infostealer malware and stealer logs explains how such credentials end up for sale.

On 5 August 2026, Connor Riley Moucka pleaded guilty to four counts, including computer fraud and wire fraud. DOJ does not name the cloud provider, but the details match the Snowflake campaign: it says he and co-conspirators compromised at least 165 customers of a US software-as-a-service company between February and October 2024, received more than US$2.5 million in ransom payments, and that Moucka personally obtained at least US$495,000. Sentencing is set for 27 October.

Neither Mandiant nor DOJ says "ShinyHunters." The link comes from elsewhere. Sekoia documents the ShinyHunters persona advertising Ticketmaster data on BreachForums in May 2024, and the Dutch police now list Ticketmaster among ShinyHunters breaches. Sekoia's summary is the one to remember: "The people doing the hacking and the brand doing the extorting were not necessarily the same people."

2025: Help Desk Vishing and Scattered LAPSUS$ Hunters

2025 is when the phone became the main entry point. Google's June 2025 report on UNC6040 described callers who "impersonate IT support personnel" and talk staff into authorizing a malicious connected app, "often a modified version of Salesforce's Data Loader," which then exports data in bulk. No Salesforce flaw was involved. In an August 2025 update to the same post, Google added that the extortion came "sometimes several months after the initial data theft," from actors it tracks as UNC6240, who "consistently claimed to be the threat group ShinyHunters."

The FBI's September 2025 FLASH added that UNC6040 had been calling victims' call centres since October 2024, posing as IT staff "addressing enterprise-wide connectivity issues," and that some victims then received extortion emails "allegedly from the ShinyHunters group." It also covered UNC6395, which used OAuth tokens stolen from the Salesloft Drift integration. Google's Drift advisory says UNC6395 ran from as early as 8 August to at least 18 August 2025 and hunted for AWS keys, passwords and Snowflake tokens in the exported Salesforce data. The advisory does not attribute it to ShinyHunters, which is why it is dashed in Figure 1.

Then came the alliance branding. On 8 August 2025, according to Sekoia, a Telegram channel appeared that merged the names of Scattered Spider, LAPSUS$ and ShinyHunters into "Scattered LAPSUS$ Hunters." Unit 42 assessed that the conglomerate is "likely composed of individuals tied to three groups," named Bling Libra (its name for ShinyHunters) as "the main culprit behind the extortion attempts," and recorded the launch on 3 October 2025 of a leak site naming 39 organizations whose Salesforce data the group claimed to hold. The persona is self-declared, and Sekoia cites interviews in which voices for ShinyHunters and LAPSUS$ denied belonging to it. Treat the name as marketing until someone shows membership.

Arrests did not stop it. On 25 June 2025, French authorities announced four arrests made two days earlier, which Sophos says targeted the "ShinyHunters," "Hollow," "Noct" and "Depressed" personas, tied to BreachForums. The Salesforce extortion site went live three months later.

2026: Zero-Days, Passkey Lures and the FBI Claim

2026 started where 2025 ended, on the phone. Google's January report describes UNC6661 callers claiming "that the company was updating MFA settings," sending staff to victim-branded sites, then registering their own MFA device. In one case the intruders enabled a Google Workspace add-on to delete Okta's "Security method enrolled" email so the employee would not notice. The extortion that followed, tracked as UNC6240, came with a 72-hour deadline, texts to employees and reports of DDoS attacks on victim websites. Google also saw harassment of victim personnel after intrusions by UNC6671, the cluster whose extortion emails were unbranded.

In May the group hit education at scale. Instructure's Canvas learning platform was breached twice in under two weeks, with login pages replaced by a ShinyHunters message during finals, and Instructure paid a ransom in exchange for what it called "shred logs." Four days later the FBI published PSA260515.

FBI IC3 public service announcement PSA260515 of 15 May 2026 on ShinyHunters, harassment and swatting

Figure 3: The FBI's 15 May 2026 warning refers to the learning platform attack without naming the platform, and spells out the pressure tactics: threatening calls and texts to victims and their families, swatting in some cases, and claims of compromising material that "frequently do not exist." This is the document ShinyHunters later said it hacked the FBI to dispute. Source: FBI IC3, PSA260515.

Then the group added exploits. Mandiant and Google attributed to UNC6240 the exploitation of CVE-2026-35273, a CVSS 9.8 remote code execution flaw in Oracle PeopleSoft, between 27 May and 9 June 2026, before Oracle's 10 June advisory. Google notified more than 100 organizations running potentially vulnerable systems, 68 percent of them in higher education. The attackers deployed MeshCentral agents disguised as Azure services.

Mandiant and GTIG blog text attributing the Oracle PeopleSoft CVE-2026-35273 zero-day campaign to UNC6240 (ShinyHunters)

Figure 4: Mandiant and Google's 11 June 2026 report attributes the PeopleSoft campaign to "UNC6240 (ShinyHunters)" in its opening sentence. Note the careful wording: the activity is "consistent with" exploitation of CVE-2026-35273 and predates Oracle's advisory. Source: Google Cloud blog, Mandiant and GTIG.

On 9 September Microsoft reported that since May 2026, callers posing as the IT helpdesk had been phoning and texting staff on their personal mobiles about urgent passkey, MFA or SSO changes, steering them into adversary-in-the-middle pages or device code phishing. The lure domains embed the target's name, as in company-name.secure-passkey[.]com. Microsoft says this access is used by several actors; the ShinyHunters link runs through Storm-3121.

Then September turned theatrical. On 18 September ShinyHunters broke into the Clop ransomware gang's leak site through a Grav CMS flaw and defaced it with Umbreon art; BleepingComputer confirmed the defacement, not the claimed data theft. On 22 September the group claimed it had breached the FBI through a "new" PeopleSoft zero-day, taking 2TB to 3TB of employee and applicant data, in retaliation for the May PSA. It told The Register the hack was "fundamentally a public relations and marketing initiative for our business." Three days later Mandiant reported renewed mass exploitation of the same CVE, using a request to /%50SEMHUB/ to slip past WAF rules that only blocked the literal /PSEMHUB/ path.

The ShinyHunters Arrests: Claim vs Confirmed

Most coverage of the ShinyHunters arrest news mixes what officials have put on the record with what the group or anonymous sources have said. Here they are side by side.

Statement Status Source
FBI jobs portal was breached incident confirmed, scope not FBI
2TB to 3TB stolen claim only the group
A "new" PeopleSoft zero-day doubtful (our inference) FBI via Reuters
Amsterdam arrest on 15 September confirmed Dutch police
He was held over Odido no, police say Dutch police
He is "one of the alleged leaders" FBI allegation FBI
He did the FBI or Clop hacks not alleged by officials none
A suspect is held in Jordan reported, not confirmed Reuters
"Multiple subjects" arrested confirmed, no details FBI
140+ organizations, US$70M+ FBI allegation FBI

The FBI's first statement said the point of breach was "still undetermined." On 5 October, FBI Cyber Division assistant director Brett Leatherman told Reuters that the incident occurred "as the result of a security failure of a platform managed by a third-party organization," after a contractor "failed to implement a security patch," and that the contractor had been removed. The FBI named neither the platform nor the vulnerability; Reuters' sources said the platform was PeopleSoft. My inference, not the FBI's: a missed patch fits the known CVE-2026-35273 better than the "new" zero-day the group claimed.

The Dutch police say the 24-year-old was detained on 15 September on suspicion of a role within ShinyHunters and participation in a criminal organization. His laptop, they add, held information about two murders that were to be committed abroad, with indications he ordered them, a suspicion they keep separate from the ShinyHunters case. A Rotterdam court kept him in custody for at least 90 more days. In a video statement, Leatherman called him "one of the alleged leaders" and said that since last year "this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments."

The Jordan detention rests on a Reuters report, citing three sources, that a suspect known online as "Rey," reportedly a teenager, was detained on 29 September and is cooperating with the FBI. The FBI declined to comment on specific arrests but said it had "worked with partners to arrest multiple subjects." Neither suspect has been publicly charged, which is why this article does not name them.

Day-by-day swimlane from 9 September to 8 October 2026 comparing ShinyHunters claims, official statements and research

Figure 5: Thirty days in three lanes. Everything the group said sits in the amber left lane; only the middle lane is on the record from police or the FBI. The Amsterdam arrest came three days before the Clop defacement and a week before the FBI claim. Diagram: CTI Academy.

One more caution. The group told BleepingComputer the arrested Dutchman "has no association with us," and KrebsOnSecurity reported that the suspect known as Rey reused the Umbreon imagery tied to the Dutchman's old alias in an apparent attempt to frame him. Logos are cheap to copy, so never attribute on one.

How ShinyHunters Operates: TTPs Mapped to MITRE ATT&CK

Strip away the theatre and the playbook is short: get a person to hand over access, keep it, pull data out of SaaS in bulk, then make the victim afraid. The table maps what Google, Microsoft and the FBI describe to ATT&CK. MITRE's own G1057 entry lists some of these technique IDs; where the "In G1057" column says no, the mapping is ours, not MITRE's. I checked every ID on attack.mitre.org on 8 October 2026.

Behaviour ATT&CK In G1057 Seen in
Voice phishing as IT support T1566.004, T1598.004 no 2025-2026
Posing as staff or helpdesk T1684.001 parent only all vishing
Lookalike domains T1583.001 yes 2026
AiTM credential capture T1557 no Microsoft 2026
Device code phishing T1528 yes, other use Microsoft 2026
Attacker MFA registration T1556.006, T1098.005 no 2026
Valid cloud accounts T1078.004 yes all
Connected app or OAuth tokens T1550.001 yes Salesforce, Drift
Bulk Salesforce export T1213.006 yes Salesforce
SharePoint, OneDrive access T1530 yes, other use 2026
Deleting alert emails T1070.008 no Google 2026
Exploiting PeopleSoft T1190 yes 2026
Web shell, MeshAgent T1505.003, T1219 T1219 only 2026
Extortion T1657 yes throughout
DDoS for pressure T1498 no Google 2026

Three notes. MITRE files the Salesforce theft under T1213.006 (Databases); T1213.004 (Customer Relationship Management Software) fits just as well, and I would tag both. Older reports cite Impersonation as T1656; on the current ATT&CK site that ID redirects to T1684.001. And harassment of employees' families and swatting have no dedicated ATT&CK technique; MITRE folds the extortion calls into T1657. Track them in your own taxonomy; for the people targeted they are the worst part of the playbook. Our piece on the psychology of social engineering explains why the urgent "IT needs you to fix this now" call works so well.

Attack chain from help desk call to extortion with ATT&CK IDs and a defender control point at each step

Figure 6: The help desk vishing chain from research to extortion, with an ATT&CK technique for each step (our mapping; the table above shows which IDs MITRE's G1057 entry lists) and the control that breaks it. The cheapest break points are at the top: a callback rule at the help desk and phishing-resistant MFA stop most of the chain before any data moves. Diagram: CTI Academy.

Detection and Hardening Against ShinyHunters Tactics

None of this needs new products, just a few settings and a few logs. In rough order of payoff:

How to Profile an Actor Like ShinyHunters

Almost every shortcut fails on ShinyHunters, which makes it a good training case. Here is the method I use for any brand-shaped actor.

  1. Split the layers. Keep separate records for the persona or brand, each intrusion cluster, each person, and the infrastructure. "ShinyHunters breached X" usually compresses three claims into one.
  2. Type every alias link. Record whether a link means "same actor," "provided access to," "claims membership of" or "overlaps with," with source and date. Figure 1 is that table as a picture.
  3. Keep a claims ledger. For each statement, note who said it and who, if anyone, verified it independently. The FBI zero-day claim went from unverified to doubtful in two weeks.
  4. Distrust cheap artifacts. Logos, avatars and Telegram handles can be copied in seconds, and in this case possibly were.
  5. Say how confident you are. Use estimative language and say what would change your mind.

Reading a case like this teaches the vocabulary; making the calls yourself on a cluster with no name attached is a different skill. For structured practice in grading evidence and writing an actor profile a decision maker can act on, our Threat Actor Profiling & Attribution learning path is built around that work. For where ShinyHunters sits among this year's wider trends, see what the big 2026 threat reports agree and disagree on.

CTI Academy Threat Actor Profiling and Attribution learning path page with sections, lessons and missions

Figure 7: The path takes you through infrastructure, behaviour and persona analysis on an unnamed activity cluster and ends with a written actor intelligence product. Source: CTI Academy, Threat Actor Profiling & Attribution learning path page (linked above).

What We Don't Know Yet

Frequently Asked Questions

What is ShinyHunters?

ShinyHunters is a financially motivated cybercrime group, and a brand, that steals large datasets from companies and then sells them or extorts the victims by threatening to publish them. It has been publicly active since 2020, and MITRE ATT&CK, which tracks it as group G1057, dates it to at least 2019. Since 2025 its intrusions have mostly started with help desk vishing against SSO and SaaS accounts.

Is ShinyHunters related to Pokémon shiny hunting?

Only by name. The group borrowed the term for hunting rare "shiny" Pokémon and uses the Pokémon Umbreon as its logo. ShinyHunters itself is a data theft and extortion operation with no connection to the game or its players.

Who was arrested in the ShinyHunters investigation?

Dutch police arrested a 24-year-old Amsterdam man on 15 September 2026 on suspicion of a role in ShinyHunters, and the FBI called him one of the group's alleged leaders. Reuters reported that a second suspect, known online as Rey, was detained in Jordan on 29 September. The FBI says multiple subjects have been arrested, but no charges have been made public.

Did ShinyHunters really hack the FBI?

The FBI confirmed an incident affecting its jobs portal. Its cyber division later said it was caused by a contractor failing to patch a platform managed by a third party, and the contractor was removed. The group's claims of 2TB to 3TB of stolen data and a new zero-day are not verified, and in our reading the patch statement points away from a new zero-day.

Is ShinyHunters the same as Scattered Spider or Scattered LAPSUS$ Hunters?

No. Scattered Spider and LAPSUS$ are separate groups from the same loose community, known as The Com. Scattered LAPSUS$ Hunters is a self-declared alliance persona that appeared on Telegram in August 2025, and Unit 42 assesses it likely includes individuals tied to all three. Its membership is claimed rather than proven.

What is UNC6240?

UNC6240 is the name Google Threat Intelligence and Mandiant use for the extortion activity that claims to be ShinyHunters. Google tracks the people who get initial access separately, for example UNC6040 for the 2025 Salesforce vishing and UNC6661 for the 2026 SSO vishing, because access and extortion are not always done by the same people.

How does ShinyHunters break into companies?

Mostly by phone. Callers pose as IT support, send staff to a fake SSO or passkey page or a device code prompt, register their own MFA method, then export data from Salesforce, Microsoft 365 and other SaaS apps. In 2026 it also exploited an Oracle PeopleSoft flaw, CVE-2026-35273, against internet-facing servers.

How can organizations defend against ShinyHunters-style help desk vishing?

Ban resets on inbound calls and verify callers by calling back on a known number. Move to phishing-resistant MFA, protect MFA registration with Conditional Access, block device code flow, and alert on every new MFA method. Then restrict connected apps and OAuth consent, and alert on bulk exports from CRM and Microsoft Graph.

Sources

Continue with the Threat Actor Profiling & Attribution Learning Path

Start Learning Path

Related Articles

Read more at CTI Academy Blog