ShinyHunters Publishes Alleged One Medical, ICSecurity, Sysco, Deep Well Services, and Education Sector Data

ShinyHunters has moved several previously listed victims into the publication phase, including One Medical, Sysco, IC Security, Deep Well Services, and multiple educational institutions.
ShinyHunters leak site displaying alleged datasets associated with Sysco Corporation, One Medical, Deep Well Services, IC Security, Moody Bible Institute, Illinois Central College, and Houston Community College System.
The ShinyHunters leak site shows newly published entries for Sysco Corporation, One Medical, Deep Well Services, IC Security, Moody Bible Institute, Illinois Central College, and Houston Community College System. The group claims the organizations failed to reach agreements before leak deadlines expired and alleges the datasets contain customer, employee, student, payroll, donor, and internal corporate information.

The ShinyHunters extortion operation has published a new batch of alleged victim data, releasing datasets it claims belong to Sysco Corporation, One Medical, IC Security, Deep Well Services, Moody Bible Institute, Illinois Central College, and Houston Community College System after negotiations allegedly failed.

According to the threat actor, the alleged disclosures include customer information, employee records, Salesforce data, student records, payroll files, donor information, admissions data, and other internal corporate documents. BreachNews has not independently verified the authenticity of the alleged datasets.

Corporate and healthcare organizations allegedly published

Sysco Corporation is listed as containing more than 61 million Salesforce records across multiple tables. ShinyHunters claims the dataset includes customer information, employee records, personally identifiable information, and internal corporate data.

Amazon-owned One Medical is listed with an alleged dataset exceeding 8.8 TB. The threat actor has not publicly detailed the full contents of the claimed data.

IC Security appears on the leak site with what ShinyHunters claims are more than 2.7 million records and additional internal corporate information.

Deep Well Services is listed with approximately 53 GB of compressed data allegedly containing customer information, personally identifiable information, and internal company records.

Education sector data allegedly exposed

Moody Bible Institute, Illinois Central College, and Houston Community College System also appear in the latest publication batch.

For Moody Bible Institute, ShinyHunters claims to have released more than 23 GB of data spanning enrollment systems, donor relations databases, payroll records, communications platforms, admissions files, and student housing information.

Illinois Central College is listed as containing more than 28 GB of institutional data allegedly including payroll records, pension reporting files, financial aid information, enrollment exports, Workday data, and other administrative records.

Houston Community College System is described by the threat actor as containing hundreds of thousands of student records allegedly including names, addresses, phone numbers, email addresses, dates of birth, enrollment information, academic data, gender, ethnicity, student identifiers, and related educational records.

Claims follow earlier extortion campaign

All of the organizations appeared previously on the ShinyHunters leak site as part of the group’s ongoing extortion campaign. The latest update moves the organizations into the publication section of the leak site, where the group claims downloadable datasets are now available.

In each listing, ShinyHunters claims the affected organization failed to reach an agreement before publication deadlines expired. Several of the organizations had not issued public statements regarding the alleged releases at time of publication.

BreachNews will update this article if any of the affected organizations confirm an incident or provide additional information regarding the allegations.

Previous coverage

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site