ShinyHunters has resurfaced on new dark web infrastructure and posted fresh extortion claims involving O’Reilly Automotive and DexCom, days after the FBI publicly warned remaining members of the hacking group to come forward.
BreachNews observed the new ShinyHunters data leak site on Oct. 1 after the group’s previously monitored site became unavailable. The timing is notable because the infrastructure change follows increased law enforcement pressure against ShinyHunters, but there is currently no evidence establishing why the previous site went offline.
The new site lists O’Reilly Automotive and DexCom, Inc. as alleged victims and threatens to publish purportedly stolen data from both companies by the end of Friday if they do not contact the group.
ShinyHunters has not disclosed what information it allegedly obtained from either company, how much data it claims to possess or how the organizations were purportedly compromised.
BreachNews has not independently verified that ShinyHunters breached either company. Neither O’Reilly Automotive nor DexCom had issued a public statement confirming the claims at time of publication.
New infrastructure appears after FBI warning
The appearance of the new leak site comes at a particularly turbulent time for ShinyHunters.
On Sept. 29, the FBI publicly addressed remaining members of the group following the arrest of an alleged ShinyHunters leader in the Netherlands.
FBI Cyber Division Assistant Director Brett Leatherman said ShinyHunters and its alleged co-conspirators have breached more than 140 organizations since 2025 and collected at least $70 million in extortion payments.
“The longer you stay in this, the more we learn about you,” Leatherman warned remaining members in an FBI video. “You know how to find us, and we know how to find you.”
The bureau’s unusually direct warning followed the arrest of a 24-year-old Amsterdam man in the ShinyHunters investigation.
Dutch authorities arrested the suspect on Sept. 15 and accused him of participating in a criminal organization and playing a role within ShinyHunters. The Rotterdam District Court subsequently ordered him to remain in pre-trial detention while investigators continue examining seized evidence.
ShinyHunters has reportedly denied that the arrested man is associated with the group.
Previous ShinyHunters leak site goes offline
The ShinyHunters leak site previously monitored by BreachNews became unavailable following the FBI’s public warning.
By Oct. 1, BreachNews had identified a new ShinyHunters onion service carrying the group’s branding and new alleged victim listings.
The proximity between the FBI announcement, disappearance of the previously monitored site and appearance of new infrastructure makes the sequence noteworthy. However, BreachNews has found no evidence that law enforcement seized the previous site or that the FBI warning directly caused it to go offline.
The FBI said during its warning that arrests and seized infrastructure can provide investigators with information about other participants in cybercrime operations, but the bureau did not announce a seizure of ShinyHunters’ leak site.
The new onion address is not being published by BreachNews.
O’Reilly Automotive threatened with Friday publication
One of the first new organizations listed on the replacement site is O’Reilly Automotive, a major U.S. automotive parts retailer.
ShinyHunters claims it possesses data belonging to the company and says it will publish the information by the end of Friday unless O’Reilly makes contact.
The listing was marked as new and updated Oct. 1.
No samples or technical evidence reviewed by BreachNews independently establish that ShinyHunters successfully compromised O’Reilly Automotive.
The group has also provided no details about the alleged attack vector, systems affected, volume of information obtained or types of data purportedly stolen.
O’Reilly Automotive had not issued any public statement confirming a ShinyHunters breach at time of publication.
DexCom named in second extortion claim
ShinyHunters posted an almost identical threat against DexCom, a medical technology company best known for its continuous glucose monitoring systems.
The Oct. 1 listing claims DexCom data will also be published by the end of Friday unless the company contacts the group.
ShinyHunters did not specify whether the purported information involves customers, patients, employees, corporate systems or another category of data.
No volume, file count or evidence demonstrating possession of DexCom information was included in the claim reviewed by BreachNews.
DexCom had not issued any public statement confirming the alleged breach at time of publication.
Given DexCom’s role in healthcare technology, any confirmed exposure involving patient or health information could carry additional privacy implications. There is currently no evidence establishing that ShinyHunters obtained those types of records.
Fresh claims follow FBIjobs.gov cyberattack
The new extortion claims also follow ShinyHunters’ highly publicized cyberattack involving the FBI’s recruitment infrastructure.
As BreachNews previously reported, the FBI began investigating unauthorized activity affecting FBIjobs.gov after ShinyHunters claimed it compromised the recruitment system and stole between 2 TB and 3 TB of information.
The group subsequently distributed thousands of purported FBI personnel records to journalists in an attempt to substantiate its claims.
The FBI later reportedly acknowledged that employee information was stolen, although the bureau has not confirmed the full amount of data or breadth of access claimed by ShinyHunters.
ShinyHunters has maintained that the FBI operation was not financially motivated and was not intended as an extortion attack.
ShinyHunters signals operations are continuing
The appearance of replacement infrastructure and 2 new corporate extortion claims suggests the ShinyHunters operation remains active despite mounting international law enforcement pressure.
The FBI has publicly encouraged remaining participants to come forward, Dutch authorities have said additional arrests remain possible and investigators are examining evidence seized during the Amsterdam arrest.
Against that backdrop, the new O’Reilly Automotive and DexCom listings appear designed to demonstrate continued operational activity.
Whether ShinyHunters possesses the data it claims remains unverified. The Friday publication deadline could provide additional evidence if the group follows through, while statements from either company could clarify whether security incidents have been detected.
BreachNews is continuing to monitor the new ShinyHunters infrastructure and the status of both claims.












