Desk live·
ForensicPost
Cloud/Tokens/File 26-0429

ShinyHunters Campaign Compromised More Than a Thousand Organisations via Device Code Phishing

Reporting on the wider ShinyHunters campaign describes device code phishing as a core method, more than a thousand organisations compromised and 1.5 billion records claimed. The technique scales because consent does.

Constructed geometry · not a chart of case data
TargetSaaS tenants, multiple
ActorShinyHunters
S. Rosler10 min readConfidence: medium2 sources reviewed

Reporting on the campaign running through 2025 into 2026 describes device code phishing as a core method, with more than a thousand organisations compromised and 1.5 billion records claimed.

The organisation count is the figure worth attending to. The record claim originates with the group, describes deduplication nobody can check, and is exactly the sort of number a leak site publishes to be quoted.

Consent Scales In A Way Exploitation Does Not

An exploit-driven campaign is bounded by the vulnerable population and decays as patches roll out. A consent-driven campaign has no such ceiling. There is nothing to patch, the technique works identically against every tenant, and its effectiveness depends on human behaviour rather than software version.

It is also cheap to industrialise. Once the call script works, the constraint is calling capacity, and reporting describes exactly that division of labour — social engineering capability paired with automated extraction tooling.

Why The Defensive Advice Keeps Failing

The standard guidance is to train users to recognise the call. That has been the guidance for years, against a technique whose success rate has not visibly declined, aimed at people whose job requires cooperating with IT requests under time pressure.

The controls that actually bound this are architectural rather than educational: restrict who may authorise applications, restrict which applications may be authorised, alert on new grants, and give refresh tokens a lifetime. All of them reduce someone’s convenience, which is why they remain uncommon.

How we reported this

Compiled from public reporting, listed below. The 1.5 billion record figure and the organisation count originate with the attacking group; we reproduce them as claims and do not treat them as established. Corrections: corrections@forensicpost.com.

Sources
  1. How three techniques are behind ShinyHunters’ 2026 campaignsPush Security
  2. Threat spotlight: ShinyHunters data breach targets SalesforceReliaQuest
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary