Index live· 1,284 files · 148 editions
ForensicPost

Search the index

33 results
Try
Results for “ShinyHunters”Newest first
26-0714
File

Thirty Million Rows, Claimed. A Limited Number of Systems, Confirmed

Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.

ShinyHuntersVishing → SSO (claimed)HealthcareIdentity
Sev 4TargetAbbott LaboratoriesActorShinyHuntersUSA
26-0718
File

Vendor Analysis Maps Three ShinyHunters Attack Paths Into Salesforce Tenants

Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.

ShinyHuntersMultiple pathsCloudMethod
Sev 3TargetSalesforce tenantsActorShinyHunters
26-0616
File

ShinyHunters Claim 2.2 Million Records From Kodak

A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.

ShinyHuntersUnauthorised accessManufacturingIdentity
Sev 3TargetKodakActorShinyHunters
26-0613
File

ShinyHunters Claim 8.8TB From Amazon One Medical Legacy Archives

A claimed 8.8 TB from legacy patient archives. Every property that makes a legacy system low priority makes it high value.

ShinyHuntersLegacy archive accessHealthcareHealthcare
Sev 4TargetAmazon One MedicalActorShinyHunters
26-0612
File

DentaQuest Data Published After Extortion Demand Refused

Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.

ShinyHuntersCredential compromiseHealthcareHealthcare
Sev 4TargetDentaQuestActorShinyHunters
26-0610
File

Allianz Life Breach Affected Most of Its 1.4 Million Customers

Most of 1.4 million customers, advisers and employees. A CRM accumulates every population an organisation tracks, and so does its blast radius.

ShinyHuntersSocial engineeringInsuranceInsurance
Sev 4TargetAllianz LifeActorShinyHunters
26-0530
File

Udemy Breach Exposed 1.4 Million Addresses and Instructor Payout Details

1.4 million addresses, and instructor payout methods. A card can be reissued; a bank account configured to receive money cannot.

ShinyHuntersUnder reviewEducationSaaS
Sev 3TargetUdemyActorShinyHunters
26-0526
File

Charter Discloses Vishing Breach Affecting 4.9 Million Customer Accounts

A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.

ShinyHuntersVishing → EntraTelecomIdentity
Sev 4TargetCharter CommunicationsActorShinyHunters
26-0518
File

University of Nottingham: 455,000 Email Addresses Exposed, ShinyHunters Claim

455,000 addresses across decades of cohorts. An alumni relationship has no end date and no opt-out.

ShinyHuntersSystem compromiseEducationEducation
Sev 3TargetUniversity of NottinghamActorShinyHunters
26-0516
File

Finals Week Was Cancelled at a University That Was Never Attacked

No intrusion of its own — a dependency with a deadline, hitting the one week in the academic year with no slack in it.

ShinyHuntersVendor incidentEducationEducation
Sev 3TargetIdaho State UniversityActorShinyHunters
26-0501
File

Instructure Paid, and Got Shred Logs Back

The group claimed 3.65 TB across ~8,800 institutions, defaced hundreds of login portals, then settled. The proof of deletion was a log file it wrote itself.

ShinyHuntersService weaknessEducationEducation
Sev 5TargetInstructure — CanvasActorShinyHunters
26-0503
File

Nine Million Claimed, and the Devices Kept Working

A nine-million-record claim against corporate IT, with device manufacturing reported untouched. The separation is the finding.

ShinyHuntersHealthcareMedical devices
Sev 3TargetMedtronicActorShinyHunters
26-0429
File

ShinyHunters Campaign Compromised More Than a Thousand Organisations via Device Code Phishing

More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.

ShinyHuntersDevice code phishingCloudTokens
Sev 4TargetSaaS tenants, multipleActorShinyHunters
26-0425
File

Ten Million Claimed, Five and a Half Million Verified

Ten million claimed, 5.5 million verified. A leak-site figure is an advertisement written by the seller.

ShinyHuntersUnder reviewRetailVerification
Sev 3TargetADTActorShinyHunters
26-0424
File

Luxury Houses Share a Customer List and a Platform

Separate houses, one platform. A luxury purchase history is a map of where valuable objects live.

ShinyHuntersSocial engineering → CRMRetailRetail
Sev 3TargetAdidas, Pandora, LVMH housesActorShinyHunters
26-0423
File

Six Hundred Thousand Claimed, 185,000 Stood Up

600,000 claimed, 185,300 verified — and a franchise structure where the brand, the data holder and the notifier are three parties.

ShinyHuntersSalesforce misconfigurationRetailVerification
Sev 3Target7-ElevenActorShinyHunters
26-0414
File

Misconfigured Salesforce Environment Exposed 13.5 Million McGraw Hill Accounts

13.5 million accounts reachable because the environment was configured to permit it. Nobody had to be clever.

ShinyHuntersMisconfigurationEducationEducation
Sev 3TargetMcGraw HillActorShinyHunters
26-0314
File

ShinyHunters Campaign Hit Public-Facing Salesforce Experience Cloud Portals

Hundreds of organisations claimed through public portals working exactly as configured. The guest user profile is a permission set nobody designed.

ShinyHuntersPortal misconfigurationCloudSaaS
Sev 4TargetSalesforce Experience Cloud tenantsActorShinyHunters
26-0224
File

Employee Compromise at Figure Technology Solutions Affected 967,000 Accounts

967,000 accounts at a lending platform. Underwriting assembles identity, income and obligations — including for people who were declined.

ShinyHuntersEmployee social engineeringFinanceIdentity
Sev 4TargetFigure Technology SolutionsActorShinyHunters
26-0202
File

Panera Bread Breach Exposed 5.1 Million Loyalty Accounts

5.1 million loyalty accounts. Nothing sensitive by field name; a good deal sensitive by implication.

ShinyHuntersSystem compromiseRetailRetail
Sev 2TargetPanera BreadActorShinyHunters
25-1029
File

ShinyHunters Used Stolen CRM Data to Phish the Affected Firms' Own Clients

There is no version of “monitor your accounts” that helps somebody who has already taken the call.

ShinyHuntersTargeted phishingCloudExtortion
Sev 4TargetTenant clients and personnelActorShinyHunters
25-0923
File

One Technique, One Platform, Several Hundred Companies

What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.

ShinyHuntersConsent phishingCloudExtortion
Sev 4TargetSaaS platform tenantsActorShinyHunters
25-0830
File

Nine ShinyHunters Victims Notified Separately With No Connecting Statement

A regulator receiving a dozen filings describing the same technique could warn the market. That is not a new obligation — it is a use of filings that already exist.

ShinyHuntersSocial engineeringMultipleAnalysis
Sev 4TargetMultiple sectorsActorShinyHunters
25-0815b
File

Workday Says Core Platform and Customer Tenants Were Not Affected

A boundary between corporate systems and customer tenants held under live attack. This corpus rarely gets to observe that.

ShinyHuntersSocial engineeringCloudAnalysis
Sev 2TargetWorkdayActorShinyHunters
25-0806b
File

Attackers Posing as HR and IT Staff Phoned Workday Employees

An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.

ShinyHuntersVoice and SMS phishingCloudIdentity
Sev 3TargetWorkdayActorShinyHunters
25-0813
File

Attackers Registered Their Own MFA Device After Phishing an SSO Code

A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.

ShinyHuntersMFA enrolmentCloudIdentity
Sev 4TargetEnterprise SSO accountsActorShinyHunters
25-0810
File

Two and a Half Million Records at a Company That Sells Security

Whatever the constraint was, it was not budget, headcount, expertise or tooling.

ShinyHuntersThird-party platformCloudCloud
Sev 3TargetGoogleActorShinyHunters
25-0806
File

Operators Posing as IT Staff Had Employees Authorise a Connected App

Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.

ShinyHuntersConsent phishingCloudIdentity
Sev 4TargetEnterprise SaaS tenantsActorShinyHunters
25-0727
File

TransUnion Reports 4.4 Million Affected After Salesforce Database Reached

The bureau’s customers are lenders. The people in the database are its product.

ShinyHuntersThird-party platformFinanceFinance
Sev 4TargetTransUnionActorShinyHunters
25-0717
File

Allianz Life Reports 1,497,036 Affected After CRM Social Engineering

Reachable, taken, and published are three populations. Almost every affected count in this database is one of them without saying which.

ShinyHuntersSocial engineeringInsuranceInsurance
Sev 4TargetAllianz LifeActorShinyHuntersUSA
25-0601
File

Insurance Combines Wide Intermediary Access With Unsupervised Platforms

A service desk supporting agents and brokers is supporting people it does not know by sight.

ShinyHuntersSocial engineeringInsuranceInsurance
Sev 3TargetInsurance sectorActorShinyHunters
25-0529
File

Farmers Insurance Compromise Affected More Than 1.1 Million Customers

The peer-warning argument only helps organisations that are not first. Hindsight makes May look like August.

ShinyHuntersThird-party platformInsuranceInsurance
Sev 4TargetFarmers InsuranceActorShinyHunters
ACT-004
Actor

ShinyHunters

Voice phishing into identity providers, then leak-site extortion. Active since 2020.

VishingSSOLeak siteData theft
Profile
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging