Tag

#ShinyHunters

29 stories taggedShinyHunters.

Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

ShinyHunters Claims FBI Hack Exploiting Oracle Flaw

The cybercrime group says it breached FBI systems using a critical Oracle software vulnerability. The FBI is investigating the claim.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit enterprise server rack with amber warning LEDs reflecting off glossy black cabinet doors,
Vulnerabilities

ShinyHunters Hit Oracle PeopleSoft Bug That Hands Over the Whole System

A critical flaw in Oracle's PeopleSoft business software is under active attack, with federal agencies given days to patch.

3 min read
Full-frame edge-to-edge photoreal image of a dimly lit server rack in a data centre, one blade server pulled halfway out, a single red status LED glowing among
Ransomware

ShinyHunters defaces Cl0p's leak site and claims it grabbed the gang's Tor keys

The extortion crew says it walked out with source code, server logs, and the private keys that identify Cl0p's dark-web address. The fight traces back to a stolen Oracle exploit.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a smartphone lying face-up on a dark office desk, screen showing a generic unknown-caller interface glowing
Identity & Access

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts

Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

4 min read
A government database interface with law enforcement query fields displayed, surrounded by security breach notification alerts and credential verification failu
Breaches

ShinyHunters Claims Theft of 200,000+ Florida Driver Records From State DMV System

The extortion crew says it abused a password-reset flaw in Florida's law-enforcement lookup tool, DAVID, and posted Jeffrey Epstein's record as proof.

4 min read
A medical oxygen tank and mobility equipment arranged on a residential bedroom nightstand, with a laptop displaying encrypted patient file symbols slightly out
Breaches

AdaptHealth Confirms 4.1 Million Patients Hit in Breach Tied to ShinyHunters

The home medical supplier says a contractor's account was tricked open in June, giving intruders a path into patient records across all 50 states.

3 min read
A phishing email in an inbox with a spoofed Trezor security alert subject line, security warning indicators, and behind it visible records of a breached third-p
Breaches

Trezor's email system hijacked to send fake 'security alert' phishing to customers

Criminals used a breached third-party email provider to send phishing from a real Trezor address, weeks after a separate shipping-partner breach ballooned to 81,000 customers.

4 min read
A smartphone screen showing compromised account login alerts and unauthorized phone plan changes, Canadian mobile carrier customer service portal open in backgr
Breaches

Telus Customers Hit by Account Breach Spanning More Than a Year

Canada's second-largest phone company says criminals used stolen login details to break into customer accounts, access personal data, and in some cases quietly change people's phone plans.

3 min read
A computer server room with glowing neural network visualizations on displays, an open access panel revealing circuitry, and a shadowy figure's hand reaching to
Threat Intelligence

Spies and Criminals Are Stealing AI Systems, Not Just Data

Google's threat research team says nation-state hackers and extortion gangs are now going after the AI models, cloud accounts, and secret access keys that companies use to run artificial intelligence, turning those stolen assets into weapons for their own attacks.

4 min read
A classroom setting with empty student desks and computers, a digital lock icon broken open on one screen, file folders and educational materials scattered, rep
Breaches

Mathspace breach exposes data on more than 1 million students, parents and staff

Attackers exploited a flaw in the maths platform's internal reporting tool, part of a wider campaign tied to the ShinyHunters extortion crew.

4 min read
A cybersecurity operations center with multiple monitors showing successful threat detection and blocked breach attempts, representing defended systems
Threat Intelligence

ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.

A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

3 min read
A sprawling pharmaceutical warehouse or distribution center at night, with security lights illuminating rows of shelving units and inventory, a single door or a
Breaches

McKesson Confirms Break-In After Hackers Claim 284 Million Patient Records Stolen

The US pharmaceutical distribution giant says intruders reached third-party apps holding limited data. The ShinyHunters gang claims a haul far larger than McKesson admits.

4 min read
A dark web marketplace interface with leaked data packages displayed, showing file sizes and customer record counts, with a workwear brand's data dump highlight
Breaches

ShinyHunters dumps 12.9 million Carhartt customer records after ransom refusal

The extortion crew says it grabbed 50GB from the workwear brand's Databricks cloud analytics platform. Carhartt walked away from a $3.3 million demand, and the data is now public.

4 min read
A smartphone screen showing an incoming call from an unknown number, with subtle security icons and dashboard glimpses visible in the background blur
Identity & Access

ShinyHunters phoned a ReliaQuest employee, and one of them fell for it

The security firm says a vishing call led to a view-only peek at its Okta dashboard, but device-trust rules stopped anything worse.

3 min read
A dark desktop workspace with multiple monitors displaying fragmented data streams and breach notifications, a phone sitting nearby suggesting communications in
Breaches

ShinyHunters Claims 1.6 Million Records Stolen from RingCentral

The extortion group published 280 gigabytes of alleged RingCentral data after the company refused to pay. Names, addresses, phone numbers and email addresses are now circulating freely.

3 min read
© 2026 Threat Vectr