Actor profile· ACT-004
ForensicPost
Actor index/ACT-004

ShinyHunters

ActiveFinancially motivatedData theft & extortionNo nation-state link established

A voice-phishing operation with a leak site attached. The group’s technical repertoire is unremarkable and its social repertoire is excellent: it calls help desks, gets credentials reset, enrols its own second factor, and reads the directory.

Relationship graph of linked incidents
32
Files naming the group
2020
First observed
34 d
Median access to listing
68%
Cases starting at a help desk
0
Zero-days attributed
Campaign timeline14 most recent of 32
JUL 2026Abbott Laboratories26-0714Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.JUL 2026Salesforce tenants26-0718Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.JUN 2026Kodak26-0616A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.JUN 2026Amazon One Medical26-0613A claimed 8.8 TB from legacy patient archives. Every property that makes a legacy system low priority makes it high value.JUN 2026DentaQuest26-0612Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.JUN 2026Allianz Life26-0610Most of 1.4 million customers, advisers and employees. A CRM accumulates every population an organisation tracks, and so does its blast radius.MAY 2026Udemy26-05301.4 million addresses, and instructor payout methods. A card can be reissued; a bank account configured to receive money cannot.MAY 2026Charter Communications26-0526A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.MAY 2026University of Nottingham26-0518455,000 addresses across decades of cohorts. An alumni relationship has no end date and no opt-out.MAY 2026Idaho State University26-0516No intrusion of its own — a dependency with a deadline, hitting the one week in the academic year with no slack in it.MAY 2026Instructure — Canvas26-0501The group claimed 3.65 TB across ~8,800 institutions, defaced hundreds of login portals, then settled. The proof of deletion was a log file it wrote itself.MAY 2026Medtronic26-0503A nine-million-record claim against corporate IT, with device manufacturing reported untouched. The separation is the finding.APR 2026SaaS tenants, multiple26-0429More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.APR 2026ADT26-0425Ten million claimed, 5.5 million verified. A leak-site figure is an advertisement written by the seller.
All 32 files naming ShinyHunters
The call script, six steps
01
Name the analyst
Sourced from a public profile, not from a breach.
02
Name the manager
Establishes the approval chain before it is asked for.
03
Use the internal phrase
“Device change,” not “password reset.”
04
Create mild time pressure
A meeting, never an emergency.
05
Enrol a second factor
Within fifteen minutes, before review.
06
Read, do not escalate
Read-only visibility is enough to map the business.
© 2026 ForensicPost Media · the desk · newsletter · attribution policyGlossary