ShinyHunters Lists New Victims Including Zara, 7-Eleven, and Pitney Bowes in Alleged Data Release

The ShinyHunters group has claimed data breaches involving Zara, Pitney Bowes, Carnival Corporation, Canada Life, and potentially 7-Eleven and Mytheresa, exposing sensitive information primarily from Salesforce environments.
ShinyHunters leak site listing alleged breaches of Carnival, Zara, 7-Eleven, and other companies with downloadable datasets
ShinyHunters leak site listing newly added victims, including Carnival, Zara, and 7-Eleven, with claimed data releases after failed negotiations.

What began as a wave of ShinyHunters breach claims involving major brands including Carnival Corporation, Zara, 7-Eleven, Pitney Bowes, Canada Life and Mytheresa has since developed into a more substantiated data-extortion campaign, with several of the organizations confirming security incidents and some of the allegedly stolen datasets subsequently being published.

The later disclosures provide a clearer picture than was available when ShinyHunters initially named the companies. Carnival, 7-Eleven, Canada Life and Zara parent Inditex have acknowledged security incidents, although the companies have not necessarily confirmed every claim made by ShinyHunters about the attacks or stolen data.

Mytheresa data attributed to the campaign has also been independently cataloged following its release, while other details originally provided by ShinyHunters remain based on the group’s claims.

Carnival confirms breach affecting nearly 6 million people

Carnival Corporation confirmed that an attacker gained unauthorized access to part of its IT environment after using social engineering against an employee in April 2026.

According to regulatory breach notifications, Carnival determined that files containing personal information had been copied during the intrusion. A filing with the Maine Attorney General identified 5,995,277 affected individuals, making Carnival one of the largest confirmed incidents associated with this wave of ShinyHunters activity.

The information affected varies by individual. Carnival’s notification said compromised files contained personal information and that affected individuals would be told which data elements applied to them. The company offered 24 months of credit monitoring and identity protection services to eligible victims.

The incident later attracted regulatory scrutiny, with the Texas Attorney General opening an investigation into the breach in June.

ShinyHunters had previously claimed responsibility for the Carnival intrusion and threatened to release allegedly stolen data. Carnival’s subsequent disclosure confirms that unauthorized access and data theft occurred, although claims made independently by ShinyHunters about the contents and scale of its dataset should still be distinguished from information confirmed by the company.

7-Eleven confirms access to franchisee systems

7-Eleven also subsequently confirmed a breach after initially appearing in ShinyHunters’ extortion campaign.

The company said an unauthorized third party gained access on April 8, 2026 to certain systems used to store franchisee documents. 7-Eleven launched an investigation after discovering the intrusion and began notifying affected individuals.

ShinyHunters separately claimed to have stolen more than 600,000 records after accessing a Salesforce environment. The group later published an approximately 9.4 GB archive it attributed to 7-Eleven after its extortion attempt apparently failed.

Regulatory disclosures indicate that compromised information included sensitive personal data. However, 7-Eleven has not publicly validated all of ShinyHunters’ claims about the alleged Salesforce access, record count or contents of the group’s release.

The confirmation means 7-Eleven should no longer be treated simply as an unverified victim listing. The underlying breach is confirmed, while some of the technical and dataset claims remain attributable to ShinyHunters.

Canada Life completes investigation

Canada Life has also completed its investigation into a cyber incident involving unauthorized access to certain applications through an employee account.

The insurer said third-party cybersecurity specialists confirmed that the incident had been fully contained and that there was no evidence of continuing unauthorized activity in its environment.

Canada Life conducted a data analysis and notified individuals whose sensitive personal information was identified as affected. Those individuals were offered credit monitoring at no cost, while advisors and plan sponsors whose clients or members were affected were also notified.

The company additionally warned stakeholders about an increased risk of malicious communications following the incident.

Canada Life’s disclosure confirms unauthorized access and exposure of personal information, although it does not independently establish every detail ShinyHunters claimed about the incident.

Zara parent Inditex confirms third-party database access

Inditex, the parent company of Zara, confirmed unauthorized access to databases hosted by a third party containing information related to customer transactions.

The company traced the access to a security incident affecting a former technology provider that also impacted other international companies.

Inditex said its own operations and systems were not affected and specifically stated that the affected databases did not contain names, addresses, passwords, bank card details or other payment information. The company activated its security procedures and began notifying relevant authorities after discovering the incident.

That distinction is important when evaluating the earlier ShinyHunters listing. The existence of an Inditex-related security incident is confirmed, but descriptions of allegedly stolen Zara data published independently by ShinyHunters should not automatically be treated as equivalent to the scope confirmed by Inditex.

Mytheresa data receives independent validation

The Mytheresa claim has also gained additional support since the original ShinyHunters listing.

Data attributed to a Mytheresa breach has been verified and added to the Have I Been Pwned breach database. The exposed information is described as including names, email addresses, phone numbers, physical addresses, purchase information, salutations and partial credit card data.

That provides independent evidence that a Mytheresa dataset circulated following the claimed breach. However, it does not by itself establish every aspect of ShinyHunters’ account of how the data was obtained.

Pitney Bowes adds to the Salesforce connection

Pitney Bowes was another organization associated with the campaign, with the incident involving unauthorized access to information stored in its Salesforce environment.

The exposed information was reported to include business and customer contact information such as names, email addresses, phone numbers, physical addresses and job-related information.

The Pitney Bowes incident contributed to a broader pattern of ShinyHunters targeting environments containing large collections of structured enterprise data, particularly CRM and cloud platforms.

However, the incidents covered in this campaign should not be treated as the result of a single vulnerability or access technique. Confirmed disclosures point to different routes into victim environments, including compromised employee identities and third-party technology providers.

Data publication became part of the pressure campaign

The most significant development since the original ShinyHunters listings is that the campaign moved beyond threats against several victims.

ShinyHunters has repeatedly used public listings and deadlines to pressure organizations into negotiations before publishing allegedly stolen information when an agreement is not reached. The 7-Eleven release is one example from this wave, with the group publishing an archive after previously threatening the company.

That model differs from traditional ransomware operations that rely primarily on file encryption to disrupt a victim. ShinyHunters frequently focuses on exfiltrating high-value information and using the threat of disclosure as the primary source of leverage.

Published datasets can also make breach claims easier to assess. Once data becomes available, independent services and researchers can examine the records and establish whether at least portions appear authentic, rather than relying exclusively on record counts and descriptions supplied by the threat actor.

Several datasets associated with ShinyHunters activity have subsequently been cataloged by Have I Been Pwned.

Confirmation does not validate every ShinyHunters claim

The developments since the original report illustrate an important distinction when tracking data-extortion groups.

A company confirming unauthorized access does not necessarily confirm the threat actor’s attribution, claimed record count, initial access method or description of stolen data. Likewise, the appearance of authentic records in a published dataset can substantiate a data theft without establishing every claim made by the group responsible for distributing it.

In this campaign, several organizations that were initially known only through ShinyHunters listings subsequently disclosed genuine security incidents. Other elements of the group’s claims remain unverified or extend beyond what affected companies have publicly acknowledged.

The pattern nevertheless strengthens the significance of ShinyHunters’ broader extortion activity. The group has repeatedly demonstrated an ability to obtain large collections of enterprise and customer information and, in multiple cases, follow through on threats to publish data when negotiations fail.

BreachNews continues to track new claims, confirmed incidents and subsequent data releases in the ShinyHunters threat actor profile.


Update (September 7, 2026): BreachNews substantially revised this report to incorporate subsequent company disclosures, regulatory notifications and independent validation of datasets released after the original ShinyHunters claims. The updated article distinguishes confirmed security incidents from elements of the group’s claims that remain unverified.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site