ShinyHunters has added BOK Financial and Novocure Limited to its data leak site, giving both companies until the end of Aug. 24 to make contact before the group claims it will publish allegedly stolen data.
The listings were updated on Aug. 22 and carry identical “final warning” notices. ShinyHunters also applied the same Aug. 24 deadline to an earlier listing published on Aug. 20 that identifies the alleged victim only as “Cyrus” followed by several redacted characters.
ShinyHunters has not disclosed what information it allegedly obtained from any of the 3 organizations, how much data may be involved, or how the purported compromises occurred. BreachNews has not independently verified the claims.
BOK Financial and Novocure span banking and oncology
BOK Financial is a Tulsa, Oklahoma-based regional financial services company with more than $50 billion in assets and operations spanning consumer banking, commercial banking and wealth management. The company serves customers nationwide and maintains a significant presence across the Midwest, Southwest and Rocky Mountain regions.
Despite the potentially sensitive nature of information held by a financial institution, ShinyHunters has not claimed that customer accounts, financial records, credentials or any other specific category of BOK Financial data was compromised.
Novocure operates in a very different sector. The company is a global oncology business that develops and commercializes Tumor Treating Fields, an electric-field-based cancer therapy used for several aggressive forms of cancer. Novocure operates across North America, Europe, the Middle East and Asia.
The ShinyHunters listing provides no indication whether its alleged access to Novocure involved corporate systems, employee information, research, patient-related information or other data. No evidence supporting either company’s alleged compromise was included with the listings.
BOK Financial and Novocure had not issued public statements addressing the ShinyHunters claims at time of publication.
Redacted Cyrus listing joins the Aug. 24 deadline
A third listing, originally posted on Aug. 20, identifies its alleged victim only as “Cyrus” followed by several obscured characters. ShinyHunters has not publicly revealed the organization’s complete name through the listing.
BreachNews is not attempting to identify the organization based solely on the partially disclosed name. Without a complete company name, supporting evidence or details about the alleged intrusion, the claim is particularly difficult to independently corroborate.
ShinyHunters continues its final-warning campaign
The latest claims continue a pattern seen across recent ShinyHunters listings. The group gives alleged victims a short period to establish contact while threatening to publish purportedly stolen information and cause additional unspecified “digital problems” if its demands are ignored.
Earlier this week, BreachNews reported that ShinyHunters added Logitech and Streamlabs to its data leak site with similar final-warning language and a deadline to make contact.
The identical wording now directed at BOK Financial, Novocure and the partially redacted Cyrus organization suggests ShinyHunters is applying the same public pressure strategy across multiple alleged victims simultaneously.
The Aug. 24 deadline has not yet passed. None of the 3 current listings provides enough public evidence to independently establish that ShinyHunters successfully compromised the organizations or obtained data from their systems.
BreachNews will continue monitoring the claims for company disclosures, additional evidence or publication of the allegedly stolen information.











