Status as of 8 October 2026: one suspect is held in the Netherlands, a second is reportedly detained in Jordan, the FBI says "multiple subjects" have been arrested, no 2026 charges have been made public, and a ShinyHunters leak site was still posting new claimed victims on 1 October.
On 7 September 2026, Dutch police released a voice recording, a fragment of which was played on the TV programme Opsporing Verzocht. In it, a Dutch-speaking man calls the customer service desk of telecom operator Odido and introduces himself as a colleague from IT. He uses so much internal jargon that the employee believes him. The employee lands on a copy of Odido's login page and types a username, a password and then a verification code. According to the police, that call gave a criminal hacking and extortion group the data of more than six million Odido customers. Odido refused to pay, and the group posted the data on the dark web.
The release about the call does not name the group. Three weeks later, announcing the arrest of a 24-year-old Amsterdam man, the same police force described ShinyHunters as a criminal hacking and extortion group involved in many large data breaches, "such as those of Odido, Pornhub and TicketMaster." The same release says the man was not arrested in the Odido investigation, where police are still looking for leads, so nothing official ties him to that call.
If you arrived from a games search: this is not the Pokémon hobby of hunting rare "shiny" creatures, although the name and the Umbreon logo are borrowed from it. Below I map the group's aliases and its 2020 to 2026 timeline, separate what officials have confirmed from what the group claims, and map its methods to MITRE ATT&CK and to the controls that break them.
What Is ShinyHunters?
ShinyHunters is a financially motivated data theft and extortion group, and increasingly a brand, that steals large datasets and then sells them or threatens to publish them unless the victim pays. MITRE ATT&CK, which added it as group G1057 in July 2026, describes a collective "active since at least 2019 operating under the ShinyCorp persona" and associated with The Com, a loose online community whose members have also included Scattered Spider and LAPSUS$. The FBI's May 2026 public service announcement describes a group specializing in large-scale data breaches and extortion against tech, finance and retail companies.
The word "brand" matters. People tied to the name have been arrested in three separate waves: a French member was arrested in 2022 and sentenced in the US in 2024, four suspects were arrested in France in 2025, and two more were detained, one of them reportedly, in September 2026. The name kept working through all of it. Sekoia and Beazley Security put it bluntly in their 2026 history of the group: "ShinyHunters is less a group than a brand and business model that has outlived its founders."
For anyone doing cyber threat intelligence work, that changes the question. "Did ShinyHunters do this?" is too vague to answer. "Who got in, who stole the data, and who is extorting under the ShinyHunters name?" can be answered, and the answers are often three different sets of people.
The ShinyHunters Alias Map
Every major vendor tracks some slice of this activity under its own name, and the slices do not line up neatly. If vendor naming is new to you, read our explainer on threat actor naming conventions first.
| Name | Used by | What it covers |
|---|---|---|
| ShinyHunters, ShinyCorp | the group, press | brand, leak site, extortion |
| UNC6240 | Google, Mandiant | the extortion activity |
| Bling Libra | Unit 42 | ShinyHunters |
| G1057 | MITRE ATT&CK | ShinyHunters |
| UNC6040 | 2025 Salesforce vishing | |
| UNC6661 | 2026 SSO vishing | |
| Storm-3121 | Microsoft | access for extortion |
| UNC5537 | Mandiant | 2024 Snowflake thefts, link not Mandiant's |
| UNC6395 | 2025 Drift theft, not attributed | |
| Scattered LAPSUS$ Hunters | self-styled | Telegram alliance persona |

Figure 1: Three kinds of names point at ShinyHunters. On the left, vendor names for the same actor. On the right, intrusion clusters that vendors say fed ShinyHunters-branded extortion (solid) or that are only linked by claims, police statements or analyst inference (dashed amber). In the middle, the self-declared Scattered LAPSUS$ Hunters alliance. Diagram: CTI Academy.
Two details trip people up. First, Google deliberately splits access from extortion. In its January 2026 report it tracks the callers as UNC6661 and UNC6671 and the extortion as UNC6240, "to enable a more granular understanding of evolving partnerships and account for potential impersonation activity." Second, cross-vendor names are not one-to-one. Microsoft says Storm-3121 "conducts initial access activity leading to ShinyHunters and Falcon extortion," and names no Google cluster. Google ties the Falcon brand to UNC6671, a cluster whose operations it assesses as independent of ShinyHunters, and one lure domain on Microsoft's list, passkeyhelpdesk[.]com, is one Google saw used against victims later claimed by Falcon and Helix. My reading, which neither vendor states: Storm-3121 probably overlaps at least two Google clusters, UNC6671 and the access activity that feeds UNC6240's ShinyHunters extortion. Write "overlaps with," not "equals."
A Timeline From 2020 to 2026
The figure puts six years on a proportional axis. Read the empty stretches too: 2022 and early 2023 were quiet while the first prosecution moved through the courts, and the brand came back larger each time.

Figure 2: ShinyHunters from 2020 to 2026, split into campaigns and claims, research and advisories, and arrests and court actions. Bars show activity periods from DOJ, FBI, Google or Microsoft reports; amber dashed dots are claims or contested links. The September and October 2026 events are expanded in Figure 5. Diagram: CTI Academy.
2020 to 2023: Selling Databases on RaidForums
The early ShinyHunters was a data broker. The US Justice Department says that between April 2020 and July 2021 "ShinyHunters posted sales of hacked data from more than 60 companies" on RaidForums, EmpireMarket and Exploit, sometimes threatening to leak files if a victim did not pay. The method was unglamorous: phishing emails, fake login pages, then searching the stolen data for credentials to more systems, such as cloud storage.
In May 2020 the group offered 91 million Tokopedia records for US$5,000 as part of a batch of more than 160 million records, and claimed to have stolen more than 500GB from Microsoft's private GitHub repositories, which Microsoft said it was investigating. Wattpad's breach exposed almost 270 million records in June 2020, and Flashpoint noted that ShinyHunters claimed the hack but denied leaking the public copy.
The AT&T case is the one I use to teach humility. In August 2021 ShinyHunters advertised what it said was data on 70 million AT&T customers, and AT&T denied the data came from its systems. In March 2024, after a similar dataset leaked for free, AT&T said it covered about 73 million current and former account holders, without saying whether it came from AT&T or a vendor; at the time it was unclear whether the leak was linked to the 2021 listing. A denial is a data point, not a verdict.
Sebastien Raoult, a French citizen known as "Sezyo Kaizen" who DOJ says helped build the phishing sites, was arrested in Morocco in 2022, extradited in January 2023 and, on 9 January 2024, sentenced in Seattle to three years in prison and more than US$5 million in restitution for conspiracy to commit wire fraud and aggravated identity theft. Researchers have also traced the crew back to the earlier GnosticPlayers group, but Sekoia stresses that this lineage "rests substantially on researcher attribution rather than on confirmed admission."
2024: Snowflake and the Brand as Megaphone
In 2024 the brand got bigger than its crew. Mandiant tracked the theft of data from Snowflake customer accounts as UNC5537: the attackers logged in with credentials from old infostealer infections, "some of which dated as far back as 2020," on accounts without MFA, and Mandiant and Snowflake notified about 165 potentially exposed organizations. Our guide to infostealer malware and stealer logs explains how such credentials end up for sale.
On 5 August 2026, Connor Riley Moucka pleaded guilty to four counts, including computer fraud and wire fraud. DOJ does not name the cloud provider, but the details match the Snowflake campaign: it says he and co-conspirators compromised at least 165 customers of a US software-as-a-service company between February and October 2024, received more than US$2.5 million in ransom payments, and that Moucka personally obtained at least US$495,000. Sentencing is set for 27 October.
Neither Mandiant nor DOJ says "ShinyHunters." The link comes from elsewhere. Sekoia documents the ShinyHunters persona advertising Ticketmaster data on BreachForums in May 2024, and the Dutch police now list Ticketmaster among ShinyHunters breaches. Sekoia's summary is the one to remember: "The people doing the hacking and the brand doing the extorting were not necessarily the same people."
2025: Help Desk Vishing and Scattered LAPSUS$ Hunters
2025 is when the phone became the main entry point. Google's June 2025 report on UNC6040 described callers who "impersonate IT support personnel" and talk staff into authorizing a malicious connected app, "often a modified version of Salesforce's Data Loader," which then exports data in bulk. No Salesforce flaw was involved. In an August 2025 update to the same post, Google added that the extortion came "sometimes several months after the initial data theft," from actors it tracks as UNC6240, who "consistently claimed to be the threat group ShinyHunters."
The FBI's September 2025 FLASH added that UNC6040 had been calling victims' call centres since October 2024, posing as IT staff "addressing enterprise-wide connectivity issues," and that some victims then received extortion emails "allegedly from the ShinyHunters group." It also covered UNC6395, which used OAuth tokens stolen from the Salesloft Drift integration. Google's Drift advisory says UNC6395 ran from as early as 8 August to at least 18 August 2025 and hunted for AWS keys, passwords and Snowflake tokens in the exported Salesforce data. The advisory does not attribute it to ShinyHunters, which is why it is dashed in Figure 1.
Then came the alliance branding. On 8 August 2025, according to Sekoia, a Telegram channel appeared that merged the names of Scattered Spider, LAPSUS$ and ShinyHunters into "Scattered LAPSUS$ Hunters." Unit 42 assessed that the conglomerate is "likely composed of individuals tied to three groups," named Bling Libra (its name for ShinyHunters) as "the main culprit behind the extortion attempts," and recorded the launch on 3 October 2025 of a leak site naming 39 organizations whose Salesforce data the group claimed to hold. The persona is self-declared, and Sekoia cites interviews in which voices for ShinyHunters and LAPSUS$ denied belonging to it. Treat the name as marketing until someone shows membership.
Arrests did not stop it. On 25 June 2025, French authorities announced four arrests made two days earlier, which Sophos says targeted the "ShinyHunters," "Hollow," "Noct" and "Depressed" personas, tied to BreachForums. The Salesforce extortion site went live three months later.
2026: Zero-Days, Passkey Lures and the FBI Claim
2026 started where 2025 ended, on the phone. Google's January report describes UNC6661 callers claiming "that the company was updating MFA settings," sending staff to victim-branded sites, then registering their own MFA device. In one case the intruders enabled a Google Workspace add-on to delete Okta's "Security method enrolled" email so the employee would not notice. The extortion that followed, tracked as UNC6240, came with a 72-hour deadline, texts to employees and reports of DDoS attacks on victim websites. Google also saw harassment of victim personnel after intrusions by UNC6671, the cluster whose extortion emails were unbranded.
In May the group hit education at scale. Instructure's Canvas learning platform was breached twice in under two weeks, with login pages replaced by a ShinyHunters message during finals, and Instructure paid a ransom in exchange for what it called "shred logs." Four days later the FBI published PSA260515.

Figure 3: The FBI's 15 May 2026 warning refers to the learning platform attack without naming the platform, and spells out the pressure tactics: threatening calls and texts to victims and their families, swatting in some cases, and claims of compromising material that "frequently do not exist." This is the document ShinyHunters later said it hacked the FBI to dispute. Source: FBI IC3, PSA260515.
Then the group added exploits. Mandiant and Google attributed to UNC6240 the exploitation of CVE-2026-35273, a CVSS 9.8 remote code execution flaw in Oracle PeopleSoft, between 27 May and 9 June 2026, before Oracle's 10 June advisory. Google notified more than 100 organizations running potentially vulnerable systems, 68 percent of them in higher education. The attackers deployed MeshCentral agents disguised as Azure services.

Figure 4: Mandiant and Google's 11 June 2026 report attributes the PeopleSoft campaign to "UNC6240 (ShinyHunters)" in its opening sentence. Note the careful wording: the activity is "consistent with" exploitation of CVE-2026-35273 and predates Oracle's advisory. Source: Google Cloud blog, Mandiant and GTIG.
On 9 September Microsoft reported that since May 2026, callers posing as the IT helpdesk had been phoning and texting staff on their personal mobiles about urgent passkey, MFA or SSO changes, steering them into adversary-in-the-middle pages or device code phishing. The lure domains embed the target's name, as in company-name.secure-passkey[.]com. Microsoft says this access is used by several actors; the ShinyHunters link runs through Storm-3121.
Then September turned theatrical. On 18 September ShinyHunters broke into the Clop ransomware gang's leak site through a Grav CMS flaw and defaced it with Umbreon art; BleepingComputer confirmed the defacement, not the claimed data theft. On 22 September the group claimed it had breached the FBI through a "new" PeopleSoft zero-day, taking 2TB to 3TB of employee and applicant data, in retaliation for the May PSA. It told The Register the hack was "fundamentally a public relations and marketing initiative for our business." Three days later Mandiant reported renewed mass exploitation of the same CVE, using a request to /%50SEMHUB/ to slip past WAF rules that only blocked the literal /PSEMHUB/ path.
The ShinyHunters Arrests: Claim vs Confirmed
Most coverage of the ShinyHunters arrest news mixes what officials have put on the record with what the group or anonymous sources have said. Here they are side by side.
| Statement | Status | Source |
|---|---|---|
| FBI jobs portal was breached | incident confirmed, scope not | FBI |
| 2TB to 3TB stolen | claim only | the group |
| A "new" PeopleSoft zero-day | doubtful (our inference) | FBI via Reuters |
| Amsterdam arrest on 15 September | confirmed | Dutch police |
| He was held over Odido | no, police say | Dutch police |
| He is "one of the alleged leaders" | FBI allegation | FBI |
| He did the FBI or Clop hacks | not alleged by officials | none |
| A suspect is held in Jordan | reported, not confirmed | Reuters |
| "Multiple subjects" arrested | confirmed, no details | FBI |
| 140+ organizations, US$70M+ | FBI allegation | FBI |
The FBI's first statement said the point of breach was "still undetermined." On 5 October, FBI Cyber Division assistant director Brett Leatherman told Reuters that the incident occurred "as the result of a security failure of a platform managed by a third-party organization," after a contractor "failed to implement a security patch," and that the contractor had been removed. The FBI named neither the platform nor the vulnerability; Reuters' sources said the platform was PeopleSoft. My inference, not the FBI's: a missed patch fits the known CVE-2026-35273 better than the "new" zero-day the group claimed.
The Dutch police say the 24-year-old was detained on 15 September on suspicion of a role within ShinyHunters and participation in a criminal organization. His laptop, they add, held information about two murders that were to be committed abroad, with indications he ordered them, a suspicion they keep separate from the ShinyHunters case. A Rotterdam court kept him in custody for at least 90 more days. In a video statement, Leatherman called him "one of the alleged leaders" and said that since last year "this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments."
The Jordan detention rests on a Reuters report, citing three sources, that a suspect known online as "Rey," reportedly a teenager, was detained on 29 September and is cooperating with the FBI. The FBI declined to comment on specific arrests but said it had "worked with partners to arrest multiple subjects." Neither suspect has been publicly charged, which is why this article does not name them.

Figure 5: Thirty days in three lanes. Everything the group said sits in the amber left lane; only the middle lane is on the record from police or the FBI. The Amsterdam arrest came three days before the Clop defacement and a week before the FBI claim. Diagram: CTI Academy.
One more caution. The group told BleepingComputer the arrested Dutchman "has no association with us," and KrebsOnSecurity reported that the suspect known as Rey reused the Umbreon imagery tied to the Dutchman's old alias in an apparent attempt to frame him. Logos are cheap to copy, so never attribute on one.
How ShinyHunters Operates: TTPs Mapped to MITRE ATT&CK
Strip away the theatre and the playbook is short: get a person to hand over access, keep it, pull data out of SaaS in bulk, then make the victim afraid. The table maps what Google, Microsoft and the FBI describe to ATT&CK. MITRE's own G1057 entry lists some of these technique IDs; where the "In G1057" column says no, the mapping is ours, not MITRE's. I checked every ID on attack.mitre.org on 8 October 2026.
| Behaviour | ATT&CK | In G1057 | Seen in |
|---|---|---|---|
| Voice phishing as IT support | T1566.004, T1598.004 | no | 2025-2026 |
| Posing as staff or helpdesk | T1684.001 | parent only | all vishing |
| Lookalike domains | T1583.001 | yes | 2026 |
| AiTM credential capture | T1557 | no | Microsoft 2026 |
| Device code phishing | T1528 | yes, other use | Microsoft 2026 |
| Attacker MFA registration | T1556.006, T1098.005 | no | 2026 |
| Valid cloud accounts | T1078.004 | yes | all |
| Connected app or OAuth tokens | T1550.001 | yes | Salesforce, Drift |
| Bulk Salesforce export | T1213.006 | yes | Salesforce |
| SharePoint, OneDrive access | T1530 | yes, other use | 2026 |
| Deleting alert emails | T1070.008 | no | Google 2026 |
| Exploiting PeopleSoft | T1190 | yes | 2026 |
| Web shell, MeshAgent | T1505.003, T1219 | T1219 only | 2026 |
| Extortion | T1657 | yes | throughout |
| DDoS for pressure | T1498 | no | Google 2026 |
Three notes. MITRE files the Salesforce theft under T1213.006 (Databases); T1213.004 (Customer Relationship Management Software) fits just as well, and I would tag both. Older reports cite Impersonation as T1656; on the current ATT&CK site that ID redirects to T1684.001. And harassment of employees' families and swatting have no dedicated ATT&CK technique; MITRE folds the extortion calls into T1657. Track them in your own taxonomy; for the people targeted they are the worst part of the playbook. Our piece on the psychology of social engineering explains why the urgent "IT needs you to fix this now" call works so well.

Figure 6: The help desk vishing chain from research to extortion, with an ATT&CK technique for each step (our mapping; the table above shows which IDs MITRE's G1057 entry lists) and the control that breaks it. The cheapest break points are at the top: a callback rule at the help desk and phishing-resistant MFA stop most of the chain before any data moves. Diagram: CTI Academy.
Detection and Hardening Against ShinyHunters Tactics
None of this needs new products, just a few settings and a few logs. In rough order of payoff:
- Make the help desk the hardest target. No password or MFA resets on inbound calls. Call back on a number from the directory, require a manager or video check for privileged accounts, and alert on every helpdesk-initiated reset, as Microsoft recommends. Tell staff that IT will never call their personal mobile to enrol a passkey.
- Use phishing-resistant MFA and protect enrolment. FIDO2 keys, passkeys and Windows Hello defeat the AiTM pages. Microsoft also advises Conditional Access that requires a fresh sign-in, a managed device or trusted location and phishing-resistant MFA to register security info, blocks registration on high sign-in risk, and blocks device code flow wherever there is no business need.
- Alert on new MFA methods. A new phone, authenticator or software token on an account that just had an odd sign-in is the strongest single signal in this chain. Send enrolment notices to the SOC as well as the user, since Google watched the intruders delete them from the user's mailbox.
- Govern OAuth and connected apps. In Salesforce, follow its social engineering guidance: restrict who can authorize connected apps, review who holds "Customize Application" with "Modify All Data" or "Manage Connected Apps," allowlist known apps and set login IP ranges. In Entra, restrict user consent and review service principals holding Mail.Read, Files.Read.All or Directory.Read.All.
- Watch export volume. Salesforce Event Monitoring and Transaction Security Policies can alert on large downloads. In Microsoft 365, the hunting queries in Microsoft's report flag one account or app, from one IP address, making eight or more paged Graph requests (such as $top, $skip, delta and search) across at least four distinct paths in 15 minutes, then correlate that with SharePoint, OneDrive and mailbox access.
- Keep secrets out of SaaS records. The Drift campaign pulled Salesforce objects such as support cases and accounts, then searched them for AWS keys, passwords and Snowflake tokens. Search your CRM and ticketing data for credentials and rotate what you find.
- Patch PeopleSoft properly. Mandiant says to apply Oracle's patch, disable the EMHub service or remove the PSEMHUB application, and search WebLogic logs for /PSEMHUB/ and any percent-encoded variant. A WAF string match is not a fix.
- Rehearse the extortion phase. The FBI advises victims not to pay or engage and to verify contacts through known channels. Plan for calls to staff and families, and verify any data sample before reacting.
How to Profile an Actor Like ShinyHunters
Almost every shortcut fails on ShinyHunters, which makes it a good training case. Here is the method I use for any brand-shaped actor.
- Split the layers. Keep separate records for the persona or brand, each intrusion cluster, each person, and the infrastructure. "ShinyHunters breached X" usually compresses three claims into one.
- Type every alias link. Record whether a link means "same actor," "provided access to," "claims membership of" or "overlaps with," with source and date. Figure 1 is that table as a picture.
- Keep a claims ledger. For each statement, note who said it and who, if anyone, verified it independently. The FBI zero-day claim went from unverified to doubtful in two weeks.
- Distrust cheap artifacts. Logos, avatars and Telegram handles can be copied in seconds, and in this case possibly were.
- Say how confident you are. Use estimative language and say what would change your mind.
Reading a case like this teaches the vocabulary; making the calls yourself on a cluster with no name attached is a different skill. For structured practice in grading evidence and writing an actor profile a decision maker can act on, our Threat Actor Profiling & Attribution learning path is built around that work. For where ShinyHunters sits among this year's wider trends, see what the big 2026 threat reports agree and disagree on.

Figure 7: The path takes you through infrastructure, behaviour and persona analysis on an unnamed activity cluster and ends with a written actor intelligence product. Source: CTI Academy, Threat Actor Profiling & Attribution learning path page (linked above).
What We Don't Know Yet
- Charges. No indictment or Dutch charge has been made public for the 2026 arrests, so roles and names remain unconfirmed.
- Who did the September operations. Officials have not tied the arrested Dutchman to the FBI or Clop intrusions, and the group denies any link to him.
- What the FBI lost. The bureau confirms an incident on a third-party platform. The volume, the systems reached and the medical records that Reuters' sources describe are not confirmed by the FBI.
- How the FBI counts. "More than 140 organizations" and "at least $70 million" are allegations. The FBI has not said what "since last year" covers or how the figures were built.
- The alliance. Who actually belongs to Scattered LAPSUS$ Hunters, and whether it is more than a shared channel, is still unclear.
- Whether arrests end it. The 2022 and 2025 arrests did not. Reuters reported that the group's leak site went offline on 30 September, but on 1 October, according to Cybernews, a site at a new address listed two new claimed victims. Watch for new leak site posts, new Tox IDs and changed extortion email styles over the next quarter.
Frequently Asked Questions
What is ShinyHunters?
ShinyHunters is a financially motivated cybercrime group, and a brand, that steals large datasets from companies and then sells them or extorts the victims by threatening to publish them. It has been publicly active since 2020, and MITRE ATT&CK, which tracks it as group G1057, dates it to at least 2019. Since 2025 its intrusions have mostly started with help desk vishing against SSO and SaaS accounts.
Is ShinyHunters related to Pokémon shiny hunting?
Only by name. The group borrowed the term for hunting rare "shiny" Pokémon and uses the Pokémon Umbreon as its logo. ShinyHunters itself is a data theft and extortion operation with no connection to the game or its players.
Who was arrested in the ShinyHunters investigation?
Dutch police arrested a 24-year-old Amsterdam man on 15 September 2026 on suspicion of a role in ShinyHunters, and the FBI called him one of the group's alleged leaders. Reuters reported that a second suspect, known online as Rey, was detained in Jordan on 29 September. The FBI says multiple subjects have been arrested, but no charges have been made public.
Did ShinyHunters really hack the FBI?
The FBI confirmed an incident affecting its jobs portal. Its cyber division later said it was caused by a contractor failing to patch a platform managed by a third party, and the contractor was removed. The group's claims of 2TB to 3TB of stolen data and a new zero-day are not verified, and in our reading the patch statement points away from a new zero-day.
Is ShinyHunters the same as Scattered Spider or Scattered LAPSUS$ Hunters?
No. Scattered Spider and LAPSUS$ are separate groups from the same loose community, known as The Com. Scattered LAPSUS$ Hunters is a self-declared alliance persona that appeared on Telegram in August 2025, and Unit 42 assesses it likely includes individuals tied to all three. Its membership is claimed rather than proven.
What is UNC6240?
UNC6240 is the name Google Threat Intelligence and Mandiant use for the extortion activity that claims to be ShinyHunters. Google tracks the people who get initial access separately, for example UNC6040 for the 2025 Salesforce vishing and UNC6661 for the 2026 SSO vishing, because access and extortion are not always done by the same people.
How does ShinyHunters break into companies?
Mostly by phone. Callers pose as IT support, send staff to a fake SSO or passkey page or a device code prompt, register their own MFA method, then export data from Salesforce, Microsoft 365 and other SaaS apps. In 2026 it also exploited an Oracle PeopleSoft flaw, CVE-2026-35273, against internet-facing servers.
How can organizations defend against ShinyHunters-style help desk vishing?
Ban resets on inbound calls and verify callers by calling back on a known number. Move to phishing-resistant MFA, protect MFA registration with Conditional Access, block device code flow, and alert on every new MFA method. Then restrict connected apps and OAuth consent, and alert on bulk exports from CRM and Microsoft Graph.
Sources
- Politie: Suspect arrested in investigation into hacker group ShinyHunters (in Dutch), 29 Sep 2026
- Politie: Police share voice of suspect in Odido hack investigation (in Dutch), 7 Sep 2026
- FBI: ShinyHunters arrest announcement video, 29 Sep 2026
- FBI: Statement on compromise of fbijobs.gov portal, 23 Sep 2026
- FBI IC3: PSA260515, ShinyHunters attacks learning management system, 15 May 2026
- FBI: FLASH-20250912-001 on UNC6040 and UNC6395, 12 Sep 2025
- US DOJ: Member of notorious international hacking crew sentenced to prison, 9 Jan 2024
- US DOJ: Canadian man pleads guilty to hacking US cloud storage provider, 5 Aug 2026
- MITRE ATT&CK: ShinyHunters, G1057
- Mandiant and GTIG: ShinyHunters targets education sector with Oracle PeopleSoft exploit, 11 Jun 2026
- Mandiant and GTIG: ShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft, 25 Sep 2026
- Mandiant: Vishing for access, tracking the expansion of ShinyHunters-branded SaaS data theft, 30 Jan 2026
- GTIG: UNC6671 rebrands, multi-brand vishing extortion, 6 Aug 2026
- GTIG: Welcome to BlackFile, inside a vishing extortion operation (UNC6671), 15 May 2026
- GTIG: The cost of a call, from voice phishing to data extortion (UNC6040), 4 Jun 2025, updated Aug 2025
- GTIG: Widespread data theft targets Salesforce instances via Salesloft Drift (UNC6395), 26 Aug 2025
- Mandiant: UNC5537 targets Snowflake customer instances, 10 Jun 2024
- Microsoft Security: Passkey-themed social engineering leads to identity and cloud compromise, 9 Sep 2026
- Unit 42: The golden scale, Bling Libra and the evolving extortion economy, 10 Oct 2025
- Sophos: Taking the shine off BreachForums, 26 Jun 2025
- Sekoia and Beazley Security: Gotta breach 'em all, the journey of ShinyHunters, 1 Oct 2026
- Salesforce: Protect your Salesforce environment from social engineering threats, Mar 2025
- ESET WeLiveSecurity: Over 160 million user records put up for sale on the dark web, 11 May 2020
- SC Media: Shiny Hunters bursts onto dark web scene, 8 May 2020
- Have I Been Pwned: Wattpad data breach
- Flashpoint: Wattpad hack, Jul 2020
- Infosecurity Magazine: AT&T denies data breach, 23 Aug 2021
- Al Jazeera: AT&T says data of 73 million customers leaked on dark web, 31 Mar 2024
- Inside Higher Ed: Instructure pays ransom to Canvas hackers, 11 May 2026
- CNN: Canvas hack, what we know about the apparent cyberattack, 7 May 2026
- BleepingComputer: ShinyHunters hacks Clop leak site, 19 Sep 2026
- BleepingComputer: ShinyHunters claims FBI hack, 22 Sep 2026
- BleepingComputer: Dutch police confirm arrest in ShinyHunters hacking investigation, 28 Sep 2026
- The Register: ShinyHunters tells The Reg it hacked the FBI to protect its business, 25 Sep 2026
- The Register: FBI confirms multiple arrests related to ShinyHunters hack, 5 Oct 2026
- CSO Online: FBI removes contractor working with its PeopleSoft system after data breach, says report, 6 Oct 2026
- Silicon UK: ShinyHunters-linked hacker arrested in Jordan (citing Reuters), 7 Oct 2026
- KrebsOnSecurity: ShinyHunters extorted Boeing spin-off prior to arrests, 7 Oct 2026