Attribution: Financially motivated cybercriminal group, suspected French-speaking members
Primary Operations: Data extortion, enterprise data theft, cloud and SaaS compromises, credential theft, source code theft
ShinyHunters is a financially motivated cybercrime collective known for large-scale data exfiltration and extortion operations targeting enterprise platforms, particularly cloud-hosted environments. Active since at least 2020, the group has evolved into a high-volume threat actor focused on extracting and monetizing sensitive corporate and customer data through coordinated leak campaigns, ransom demands, and direct data sales.
The group operates a public-facing leak and extortion model, where organizations are listed alongside breach claims, dataset descriptions, and deadline-driven warnings. Their approach centers on breaching organizations, exfiltrating data at scale, and pressuring victims to pay under threat of public exposure.
Recent activity shows a consistent focus on SaaS platforms, CRM systems, and internal corporate environments. ShinyHunters frequently combines technical compromise with psychological pressure, using public messaging to frame victims as negligent and to accelerate negotiations.
Latest activity
Recent BreachNews coverage of ShinyHunters activity.
- August 2026: ShinyHunters lists Metabase on its leak site with an alleged 7.1 GB data archive available for download
- August 2026: Baxter International, Cook Medical, Carhartt, and Sharecare added to the leak site as ShinyHunters escalates its extortion campaign
- August 2026: Questel, Alcon, and Lumenis added to the leak site with alleged Salesforce data and internal corporate files
- July 2026: EY, RingCentral, and Brinks Home added to the leak site as the group claims responsibility for EY’s previously disclosed breach
- July 2026: Ingram Content Group and Fluke Corporation added to the leak site
- July 2026: Glendale Community College data allegedly published after the extortion deadline
- July 2026: ICSecurity, One Medical, and NAIC added to the extortion campaign
- July 2026: One Medical, ICSecurity, Sysco, Deep Well Services, and education-sector data allegedly published
- July 2026: Council of Europe HR and payroll data allegedly published
All ShinyHunters coverage
Throughout 2026, ShinyHunters has significantly increased both the volume and visibility of its operations, shifting from isolated breach claims to coordinated multi-company campaigns and rapid follow-through on extortion threats.
The following articles track alleged and confirmed ShinyHunters activity covered by BreachNews:
- ShinyHunters lists Metabase with alleged 7.1 GB data archive
- ShinyHunters claims Baxter breach, publishes Cook Medical, Carhartt, and Sharecare data
- ShinyHunters lists Questel, Alcon, and Lumenis in latest extortion campaign
- ShinyHunters adds EY, RingCentral, and Brinks Home to leak site
- ShinyHunters adds Ingram Content Group and Fluke Corporation to leak site
- ShinyHunters allegedly publishes Glendale Community College data
- ICSecurity, One Medical, and NAIC added to extortion campaign
- One Medical, ICSecurity, Sysco, Deep Well Services, and education-sector data allegedly published
- Council of Europe HR and payroll data allegedly published
- Council of Europe, American Tower, JCPenney, Ralph Lauren, Madison Square Garden Sports, and Nexstar threatened
- American Tower, JCPenney, Ralph Lauren, Madison Square Garden Sports, and Nexstar datasets allegedly published
- Kodak and Deep Well Services added to leak site
- Sysco Salesforce breach claim
- 4 U.S. colleges targeted
- University of Nottingham breach claim
- Oracle PeopleSoft exploitation linked to ShinyHunters activity
- Instructure confirms ransom payment
- GeForce NOW database sale claim
- Addi breach claim
- Vimeo compromise claim
- Charter Communications data release claim
- DentaQuest data release claim
- BCD Travel breach claim
- Charter Communications, DentaQuest, and Baker Distributing added to campaign
- Houghton Mifflin Harcourt extortion claim
- Instructure confirms data breach
- Accord Healthcare dataset release
- Udemy dataset leak claim
- Marcus & Millichap breach claim
- ADT extortion claim
- Anthropic data sale claim
- Carnival Corporation breach claim
- Vercel confirms internal breach
- Amtrak, McGraw Hill, Kemper, and others targeted
- Rockstar Games confirms breach
- European Commission incident
- Cisco extortion claim
- Hallmark Cards breach claim
- Zara, 7-Eleven, and Pitney Bowes added to campaign
In multiple cases, the group has followed through on threats by publishing data after deadlines passed, reinforcing the credibility of their extortion model.
Tactics and operational patterns
ShinyHunters demonstrates a consistent operational model centered on data exfiltration rather than encryption-based ransomware. Key tactics include:
- Data-first extortion: Prioritizing theft and public exposure over system disruption
- Deadline-driven pressure: Issuing final warning notices with specific leak dates
- Public negotiation tactics: Using public listings to pressure organizations and shape narrative
- Mass data packaging: Structuring datasets for resale or publication
- Cloud and SaaS targeting: Focusing on Salesforce, cloud storage, and internal platforms
Salesforce campaign and enterprise targeting
A major component of ShinyHunters’ recent activity involves large-scale data extraction from Salesforce environments and similar cloud-based platforms. These incidents often involve misconfigured access controls or exposed data pathways, allowing unauthenticated or low-privilege access to sensitive datasets.
The scale of these operations suggests repeatable techniques and potentially automated scanning and extraction workflows targeting misconfigured enterprise systems.
Shift toward data sales and intellectual property
In addition to traditional extortion, ShinyHunters has increasingly moved toward direct data sales, offering datasets, internal systems, and in some cases alleged intellectual property for purchase.
This includes recent listings involving internal corporate data, enterprise system access, and experimental AI-related assets, indicating a broader monetization strategy beyond customer data alone.
Behavior and messaging strategy
The group frequently uses confrontational messaging in its listings, accusing organizations of failing to protect user data and framing payment as a responsible decision. Public posts often include countdowns, warnings, and reputational pressure tactics designed to force rapid engagement.
Unlike quieter threat actors, ShinyHunters relies heavily on visibility and narrative control as part of its operational model.
Recent trends
Activity in 2026 reflects increased automation, higher targeting volume, and more aggressive follow-through on extortion threats. The group’s ability to consistently target enterprise environments suggests ongoing access to vulnerable systems or effective exploitation of common misconfigurations.
The shift toward combining breach claims, public pressure, and data sales positions ShinyHunters as one of the most active and visible financially motivated threat actors currently operating.
Notes
All breach claims attributed to ShinyHunters should be treated as unverified unless confirmed by affected organizations or independently validated. However, the group’s history of publishing data following failed negotiations indicates that many claims warrant serious attention.
Update (August 13, 2026): Updated the profile with ShinyHunters’ latest activity, including the alleged Metabase breach, new listings involving Baxter International, Cook Medical, Carhartt, and Sharecare, and the group’s latest extortion warnings.












