Desk live·
ForensicPost
Breaches/Analysis/File 25-0830

Nine ShinyHunters Victims Notified Separately With No Connecting Statement

Google, Allianz Life, Farmers, TransUnion, Workday, Pandora, Cisco, Chanel, Qantas. Each notified separately. Nobody was obliged to publish the sentence connecting them.

Constructed geometry · not a chart of case data
TargetMultiple sectors
ActorShinyHunters
D. Kennedy12 min readConfidence: medium3 sources reviewed

Organisations reported as affected by the 2025 SaaS-platform campaign include Google, Allianz Life, Farmers Insurance, TransUnion, Workday, Pandora, Cisco, Chanel and Qantas, across insurance, credit reporting, retail, aviation, technology and luxury goods.

Every Notification Described One Company’s Incident

Each organisation notified its own regulators and its own affected individuals, correctly, on its own timetable, describing what happened to it.

None was obliged to say — and most were not in a position to know — that a dozen other organisations were experiencing the same technique in the same months. The pattern existed only above the level at which anyone reports.

This desk filed the identical structure at 25-0710, where three LVMH brands disclosed separately under a shared parent, and at 25-1027, where a vendor breach produced obligations that ran in series. It is the same gap seen a third way.

Researchers Do The Work No Regime Requires

The campaign was assembled by vendors and journalists comparing incidents after the fact — the process at 25-0529, where a May compromise became campaign evidence months later.

That work is unfunded by any obligation, performed by parties with commercial motives, and is the only mechanism producing the most operationally useful fact about any of these incidents: that the technique was in active use against a whole class of organisations.

A Cross-Incident Notification Duty Would Close It

A regulator receiving multiple filings describing the same technique against the same platform class is uniquely positioned to warn the rest of the market — earlier, more authoritatively, and without a commercial interest.

That is not a new obligation on organisations. It is a use of filings that already exist. The 24/72-hour regime at 25-1119 would supply the raw material, and this desk has found no regime that does it. Graded medium: the victim list is as reported and campaign membership was determined by researchers, not by any authority.

This is an analysis file

Built on published campaign reporting, listed below. Campaign membership is as attributed by researchers; this desk has not independently established that every named organisation was affected by the same activity. Corrections: corrections@forensicpost.com.

Sources
  1. Data breaches 2025: complete list and statisticsDexpose
  2. Top 10 data breaches of 2025 and what caused themGuardz
  3. Salesforce cyber-attack expands impact: Farmers Insurance and TransUnion added to breach listCybersecurity Insiders
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary