ShinyHunters

☆ pin
Also known as Shinyhunters, UNC6240, Bling Libra, UNC6040, UNC6395, GRUB1, Storm-3138, Icarus
Reports
96
First seen
Oct 15, 2025
Last seen
Aug 14, 2026
Motivation
Financial

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×52
United States×52
United Kingdom×4
European Union×2
Netherlands×1
France×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1190 Exploit Public-Facing Application ×31T1005 Data from Local System ×29T1566 Phishing ×28T1041 Exfiltration Over C2 Channel ×24T1078 Valid Accounts ×21T1486 Data Encrypted for Impact ×16T1195 Supply Chain Compromise ×16T1110 Brute Force ×13T1567 Exfiltration Over Web Service ×10T1598 Phishing for Information ×9T1059 Command and Scripting Interpreter ×8T1087 Account Discovery ×7

Indicators

cve ×181domain ×112ip_v4 ×68hash_sha256 ×38hash_md5 ×18filename ×11hash_sha1 ×6bitcoin_address ×1url ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

RingCentral data breach exposed info of 1.6 million accounts

Bleeping Computer
High

Shinyhunters publishes Metabase as new ransomware victim

ransomware.live
High

Shinyhunters publishes Sharecare, Inc. data after failed ransom negotiation

ransomware.live
High

Shinyhunters publishes Carhartt, Inc. as ransomware victim

ransomware.live
High

Shinyhunters claims Cook Medical LLC as ransomware victim

ransomware.live
High

Shinyhunters claims Baxter International breach with 7.1M Salesforce records

ransomware.live
High

Education Under Attack: The Pattern Behind Recent University Breaches

Huntress Blog
Medium

Shinyhunters claims new victim on ransomware.live

ransomware.live
High

Shinyhunters claims breach of Lumenis Ltd with 1.1M records and 176GB data

ransomware.live
High

Shinyhunters publishes Questel SAS victim on ransomware.live

ransomware.live
High

Shinyhunters claims breach of Alcon Inc. with 25M Salesforce records

ransomware.live
High

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Bleeping Computer
High

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

The Hacker News
High

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Bleeping Computer
High

Ernst & Young data breach claimed by ShinyHunters extortion gang

Bleeping Computer
High

Shinyhunters claims BH Security, LLC breach with 4.9M Salesforce records

ransomware.live
High

Shinyhunters claims RingCentral breach, demands extortion payment by 30 July 2026

ransomware.live
High

Shinyhunters claims breach of Ernst & Young, threatens data release

ransomware.live
Medium

ShinyHunters data leaks fuel $2,000 sextortion email scam

Bleeping Computer
High

Check Point Threat Intelligence Report – 20 July 2026

Check Point Research
High

Abbott Laboratories investigating two cyber incidents amid ShinyHunters and ShadowByt3$ extortion claims

Bleeping Computer
High

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

The Hacker News
High

Shinyhunters publishes Exact Sciences Corporation (Abbott) as ransomware victim

ransomware.live
Critical

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

The Hacker News
High

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft Threat Intelligence
High

Check Point Threat Intelligence Report – 13 July 2026

Check Point Research
High

Dutch police indicate local hackers involved in Odido telecom breach

Bleeping Computer
High

Medtronic notifies 3.8 million patients of data breach linked to ShinyHunters

The Record (Recorded Future News)
High

Medtronic notifies customers of ShinyHunters data breach affecting 9 million records

Bleeping Computer
High

CERT-EU Cyber Brief June 2026 – Multi-Sector Espionage, Ransomware, and Zero-Days

CERT-EU Threat Intel

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.