ShinyHunters Publishes Alleged Data From American Tower, JCPenney, Ralph Lauren and Other Victims

ShinyHunters says it has begun releasing data from several previously listed victims after alleged negotiations failed, escalating its ongoing extortion campaign.
Screenshot of the ShinyHunters leak site showing newly published alleged datasets linked to American Tower Corporation, JCPenney, Madison Square Garden Sports, Ralph Lauren, and Nexstar. The page also includes a service notice announcing infrastructure upgrades and additional file distribution capabilities.
ShinyHunters claims it has released datasets associated with American Tower, JCPenney, Madison Square Garden Sports, Ralph Lauren, and Nexstar after alleged negotiations failed. The threat actor also announced infrastructure upgrades and expanded file distribution capabilities on its leak platform.

ShinyHunters has escalated its ongoing extortion campaign by allegedly releasing data associated with several previously listed victims, including American Tower Corporation, JCPenney, Madison Square Garden Sports, Ralph Lauren, and Nexstar.

The development comes days after the threat actor warned that multiple organizations faced imminent data leaks if negotiations failed. BreachNews previously reported on those extortion claims in its coverage of ShinyHunters’ latest victim listings.

According to new postings published by the group on June 16 and June 17, the affected organizations allegedly failed to reach agreements with the threat actor, prompting the release of datasets that ShinyHunters claims contain customer information, employee records, corporate documents, and other internal data.

As with all threat actor claims, the scope and authenticity of the allegedly leaked information have not been independently verified.

Multiple organizations move from extortion phase to alleged data release

Among the most significant new listings is American Tower Corporation, where ShinyHunters claims to have released more than 100GB of compressed data allegedly containing millions of records tied to customers, landowners, corporate operations, and telecommunications infrastructure.

JCPenney and several affiliated brands were also added to the release section of the leak site. The threat actor alleges the dataset contains employee and identity-related records, payroll information, tax documents, and other personnel data.

Additional listings published by the group include Madison Square Garden Sports, Ralph Lauren, and Nexstar. ShinyHunters claims these datasets contain varying combinations of customer information, internal corporate documents, and business records.

Infrastructure update signals long-term distribution plans

Alongside the new releases, ShinyHunters published a notice outlining infrastructure upgrades to its leak platform.

The group claimed its primary file-hosting infrastructure was undergoing maintenance and stated that additional mirrors and distribution methods were being deployed to improve access to allegedly leaked datasets.

According to the notice, the threat actor intends to expand the availability of released files through multiple hosting locations and alternative download mechanisms.

The announcement may indicate that ShinyHunters expects additional leak activity as its current extortion campaign continues.

Latest development follows expanding victim list

ShinyHunters has remained one of the most active data extortion groups tracked by BreachNews in recent weeks, with the actor repeatedly targeting organizations across retail, telecommunications, education, technology, healthcare, and financial sectors.

The group’s recent activity has included claims involving major corporations, universities, healthcare providers, and government-related entities. BreachNews maintains a dedicated ShinyHunters threat actor profile tracking the group’s campaigns and alleged victims.

The latest releases suggest that at least some organizations previously listed on the group’s leak site have now progressed beyond the negotiation phase and into public exposure.

Questions remain over scope and impact

While ShinyHunters has published descriptions, record counts, and download listings for the alleged datasets, independent verification of the full contents remains ongoing.

The group has been linked to numerous high-profile data theft and extortion campaigns in recent years, and several past claims have later been corroborated through victim disclosures, regulatory filings, or analysis of released data.

However, the precise scope of the newly published datasets, including the number of affected individuals and the sensitivity of the information involved, has not yet been independently confirmed.

BreachNews has not independently verified the alleged datasets, and the extent of any response from the affected organizations remains unclear at the time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map