ShinyHunters has updated its data leak site with a new wave of alleged victims, threatening to publish data belonging to the Council of Europe, American Tower Corporation, JCPenney, Madison Square Garden Sports Corp., Ralph Lauren, and Nexstar if negotiations fail before a series of June deadlines.
The threat actor claims to have compromised large volumes of employee, customer, payroll, financial, and corporate information across the six organizations. The claims remain unverified, and BreachNews has not independently confirmed the authenticity of any of the datasets described in the listings.
Several of the organizations are facing leak deadlines between June 14 and June 16, with ShinyHunters repeatedly warning that data will be released if contact is not established before those dates.
Council of Europe claim contains extensive personnel data allegations
The most detailed listing targets the Council of Europe, an international organization headquartered in Strasbourg that promotes human rights, democracy, and the rule of law across Europe.
ShinyHunters claims to possess more than 297 GB of data comprising over 429,000 files allegedly obtained from multiple Council of Europe departments and administrative units.
According to the listing, the purported dataset includes more than 409,000 payslips covering over 10,000 staff members between 2011 and 2026, alongside CVs, personnel files, payroll exports, performance evaluations, absence records, interpreter scheduling information, and other internal administrative documents.
The threat actor further claims the data contains employee names, addresses, phone numbers, dates of birth, salary information, bank account details, tax records, social security information, medical records, and other human resources data.
The Council of Europe listing carries a June 16 deadline.
American Tower allegedly impacted by telecom-related data exposure
American Tower Corporation also appears on the leak site with a claimed deadline of June 15.
ShinyHunters alleges it obtained more than 5.2 million records containing customer and landowner information, along with internal corporate data.
The listing additionally claims the dataset includes GPS information for tower assets and plaintext physical access codes for telecommunications infrastructure across the United States.
If authentic, exposure of infrastructure-related information could present risks beyond traditional identity theft concerns, although the scope and accuracy of the claims remain unverified.
Retail and media organizations added to leak site
Several well-known commercial organizations were also added or updated on the leak site during the latest round of extortion activity.
- JCPenney and subsidiaries under Catalyst Brands and Authentic Brands Group: The threat actor claims to possess employee records containing Social Security numbers, dates of birth, W-2 tax forms, payroll information, and scans of government-issued identification documents.
- Madison Square Garden Sports Corp.: ShinyHunters alleges it obtained more than 26 million records containing customer information and internal corporate data.
- Ralph Lauren Corporation: The listing claims more than 220 GB of data was compromised, including customer information, transaction records, and documents relating to future product releases.
- Nexstar Media Group: The actor alleges theft of more than 1 million Salesforce records along with additional internal corporate information.
Leak deadlines continue to pressure organizations
Each listing includes nearly identical messaging warning organizations to make contact before specified deadlines or face publication of the allegedly stolen data.
The postings form part of a broader extortion campaign that has seen ShinyHunters repeatedly target large enterprises, educational institutions, healthcare organizations, and government entities throughout 2026.
Recent claims attributed to the group include the now confirmed breach of the University of Nottingham and multiple organizations reportedly affected through broader data theft and extortion operations.
At the time of publication, BreachNews had not identified public statements addressing the claims from the organizations named in the latest leak site update.
Update: Since publication, data allegedly linked to the organizations named in this report has been published online. Readers can find the latest developments in our follow-up coverage: ShinyHunters Publishes Alleged Data From American Tower, JCPenney, Ralph Lauren, and Other Victims and ShinyHunters Publishes Alleged Council of Europe HR and Payroll Dataset After Leak Deadline Expires.












