Widely attributedUnknown

ShinyHunters

Financially motivated threat group known for large-scale data theft and extortion, responsible for numerous high-profile database breaches sold on criminal forums.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
24.6
High signal strength
Mentions43
Sources11
High conf.19
Last seenJun 2026
First observed
Last active
Origin
Aliases
2
Techniques
0
Campaigns
0
TargetsTechnologyRetailTelecommunications
RegionsGlobal

Attribution signals

43 mentions · 11 sources
#1confirmedhigh
Unspecified
bushidotoken
Jun 2026

"Instructure confirmed that ShinyHunters had exploited a vulnerability in its "Free-for-Teacher" account creation system."

#2largely attributed tomoderate
Unspecified
coveware
Jun 2026

"The Snowflake-related breaches in 2024 and the CRM-focused attacks in 2025—largely attributed to Shiny Hunters—impacted organizations globally."

#3confirmedhigh
HUMINT
bleepingcomputer
Jun 2026

"Today, the threat actor confirmed to BleepingComputer that they were behind the attacks"

#4attributed tohigh
Infrastructure
mandiant
May 2026

"The credential harvesting domains attributed to UNC6661 commonly, but not exclusively, use the format sso.com or internal.com and have often been registered with NICENIC."

#5observedhigh
TTP match
mandiant
May 2026

"Mandiant has observed incidents where attackers impersonate support personnel from third-party vendors to gain access."

#6has been used byhigh
TTP match
eset
May 2026

"Technical controls such as detection of caller ID spoofing, and deepfake audio (which has been used by the ShinyHunters group)."

#7claimed responsibilityhigh
Unspecified
checkpoint
May 2026

"ShinyHunters claimed responsibility and said it stole more than 600,000 Salesforce records containing personal and corporate information"

#8assesseshigh
Victimology
mandiant
May 2026

"GTIG assesses that the group has targeted dozens of organizations across North America, Australia, and the UK."

Campaign: BlackFile
#9high
Unspecified
security-affairs
May 2026
#10demonstratedhigh
Unspecified
dark-reading
May 2026

"In January 2026, the ShinyHunters threat group demonstrated a bypass technique that compromised authentication apps and tokens across more than 100 organizations"

#11assesseshigh
InfrastructureTTP match
mandiant
May 2026

"GTIG assesses that the operations are independent."

Campaign: BlackFile
#12has continued to trackhigh
TTP matchVictimology
mandiant
May 2026

"GTIG has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand"

Campaign: BlackFile

Hedge terms observed

allegedlyare being targeted byassessesattributed tobreachedclaimedclaimed byclaimed responsibilityclaimsconfirmedconsistent withdemonstratedhas been used byhas continued to tracklargely attributed toleakedlinked tomay useobservedreportedlysufferedtook credit fortrackingunspecifiedwill widely adopt