#ShinyHunters
18 stories taggedShinyHunters.

ShinyHunters Claims 1.6 Million Records Stolen from RingCentral
The extortion group published 280 gigabytes of alleged RingCentral data after the company refused to pay. Names, addresses, phone numbers and email addresses are now circulating freely.

Brinks Home Confirms Breach as ShinyHunters Threatens to Leak 4.9 Million Salesforce Records
The residential security company says its alarm systems were not affected, but the extortion group claims to hold customer contacts, employee data and millions of support chat logs.

ShinyHunters Are Phoning Hospital Help Desks: Health-ISAC Sounds the Alarm
A wave of voice-phishing calls is tricking healthcare staff into handing over single sign-on access, and the data theft is following fast.

ShinyHunters claims Ernst & Young breach, points to supply-chain attack
The extortion crew says stolen credentials from a third-party supplier gave them access to EY's Jira, GitHub and Azure. The accounting giant has not confirmed the group's role.

DentaQuest Data Breach: Up to 23 Million People's Dental and Health Records Exposed
A three-day network intrusion at one of America's largest dental benefits administrators may have handed criminals the Social Security numbers, treatment records, and government IDs of tens of millions of people.

Scammers Recycle ShinyHunters Breach Data to Power $2,000 Sextortion Emails
A campaign running since April uses email addresses from old ShinyHunters leaks to make fake extortion threats look personal.

How ShinyHunters walked into Salesforce accounts without breaking anything
Microsoft says a year of data theft from Salesforce tenants leaned on trusted app connections, not a platform bug.

Dutch Police Say Local Hackers Helped Pull Off the Odido Breach That Exposed 6.2 Million Customers
A phone call to customer service, a fake IT worker, and a phishing page: how criminals allegedly walked out with data on nearly every Odido subscriber.

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then hoovers up company documents from Microsoft SharePoint.

ShinyHunters Breach Hits Medtronic: 3.8 Million Patients' Medical Records Stolen
The extortion group ShinyHunters broke into the medical device maker's systems in April 2026, walking away with names, Social Security numbers, and sensitive health details belonging to nearly four million people.

Medtronic tells customers their personal data was stolen in ShinyHunters raid
The medical device giant confirms hackers rifled through its corporate systems for nearly a week in April, exposing names, Social Security numbers and health details.

NAIC Says ShinyHunters Walked Out With Public Data and Stale Logs After PeopleSoft Zero-Day Hit
The regulator-of-regulators confirms an Oracle PeopleSoft zero-day was the entry point, but disputes the extortion crew's claims about what was taken.

ShinyHunters Doesn't Need Malware. That's the Point.
The group's latest breaches are a reminder that stolen credentials and patience beat zero-days most days of the week.

ShinyHunters Rode a PeopleSoft Zero-Day Into University Networks
A CVSS 9.8 RCE flaw in Oracle PeopleSoft gave UNC6240 a two-week head start before Oracle even confirmed the bug existed.

ShinyHunters Hit Universities Through PeopleSoft Zero-Day Before Oracle Patch
Mandiant ties a two-week extortion spree against Oracle PeopleSoft deployments to UNC6240, the cluster better known as ShinyHunters.