ShinyHunters Targets Kimberly-Clark in Data Breach Extortion Claim

ShinyHunters has named Kimberly-Clark in an extortion claim, threatening to publish allegedly stolen data and cause additional digital disruption after Sept. 16.
ShinyHunters data leak site listing Kimberly-Clark with a final warning and Sept. 16, 2026 deadline.
ShinyHunters lists Kimberly-Clark on its data leak site, threatening to publish allegedly stolen data and cause additional digital disruption if the company does not engage by Sept. 16, 2026.

ShinyHunters has named Kimberly-Clark in a new data breach and extortion claim, threatening to publish allegedly stolen data and cause additional digital disruption if the consumer products giant does not engage with the group by Sept. 16, 2026.

The threat appeared in a listing updated Sept. 13 and labeled as a final warning. ShinyHunters gave Kimberly-Clark a deadline to make contact before it claims it will leak data and create additional unspecified digital problems for the company.

The group has not disclosed what information it allegedly obtained from Kimberly-Clark, how much data may have been stolen, or how it purportedly gained access to the company. The current listing also provides no record count or other technical details that would independently demonstrate the scope of a compromise.

Kimberly-Clark had not issued any public statement confirming the ShinyHunters claim at time of publication. BreachNews also found no public disclosure detailing a newly identified material cybersecurity incident related to the claim.

Sept. 16 deadline raises prospect of data publication

ShinyHunters’ current listing gives Kimberly-Clark until Sept. 16 before the group says it will publish the allegedly stolen information.

The threat goes beyond a data leak. ShinyHunters also warned of additional “digital” problems if Kimberly-Clark does not engage, although the group did not explain what form that activity might take.

The vague language leaves open several possibilities but does not establish that ShinyHunters has the ability to disrupt Kimberly-Clark’s systems. There is currently no evidence of an operational disruption connected to the claim.

The lack of details about the alleged stolen data is also notable. ShinyHunters has provided more extensive information in some of its recent extortion campaigns, including claimed data volumes, affected systems or categories of stolen records. In the Kimberly-Clark listing, the group has so far focused almost entirely on its deadline and threat of publication.

ShinyHunters continues aggressive extortion campaign

The Kimberly-Clark claim follows a series of high-profile ShinyHunters extortion attempts targeting major organizations across multiple industries.

Recent victims and alleged targets have included McKesson, Neogen, Jack Henry and Elekta, while the group has also targeted Florida’s motor vehicle agency and medical technology company Medela.

The FBI has warned that ShinyHunters specializes in large-scale data theft and extortion and frequently uses aggressive pressure tactics against organizations it claims to have compromised. Those tactics can include threatening communications, harassment and the eventual publication of stolen information when victims refuse to pay.

The bureau has also cautioned that threat actors can use both genuine and exaggerated claims of access to increase pressure on targeted organizations.

Kimberly-Clark claim remains unconfirmed

Kimberly-Clark is one of the world’s largest consumer products manufacturers, with brands spanning personal care, family care and professional products. Its portfolio includes widely recognized brands such as Huggies, Kleenex, Kotex, Cottonelle and Scott.

The company sells products across more than 175 countries and regions, giving any potential compromise of its corporate environment significant international relevance.

At this stage, however, there is no independent confirmation of ShinyHunters’ claimed access or evidence establishing what systems or information may have been affected.

The Sept. 16 deadline could provide additional evidence if ShinyHunters follows through on its threat to publish data. Any material released by the group would still need to be assessed to determine whether it is authentic, current and genuinely originated from Kimberly-Clark.

Until then, the incident remains an extortion claim by ShinyHunters rather than a confirmed Kimberly-Clark data breach.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site