ShinyHackers
Attribution profile
- Type
- Criminal
- Location
- -
- Known incidents
- 1 incident
- Sources
- 0 sources
- First seen
- 2026-05-01
- Last seen
- 2026-05-01
- Updated
- 2026-08-16 02:33
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is referenced under the alias ShinyHackers in open‑source threat‑intelligence sources.
No public reporting provides details on the actor’s origins, formation date, or organizational hierarchy.
Consequently, characteristics such as size, funding, or technical sophistication cannot be affirmed from the available material.
The sole cyber‑event described in the supplied context occurred on 2026‑05‑01 and involved a voice‑phishing campaign.
The perpetrators of that campaign were identified as the hacker groups ShinyHunters and Qilin, not ShinyHackers.
The attack targeted the real‑estate services firm Cushman & Wakefield.
Unauthorized access was gained to clients’ personal data, including names, dates of birth, Social Security numbers, driver’s license numbers and financial information.
Following the breach, a proposed class‑action lawsuit alleged that Cushman & Wakefield failed to adequately protect the exposed data.
The lawsuit claimed that the lapse led to identity theft, fraud and associated stress for the affected individuals.
Cushman & Wakefield has publicly characterized the litigation as baseless and maintained that the breach was limited in scope.
A separate class action was filed by a former employee, asserting that the firm inadequately monitored its employee 401(k) plan for climate‑related financial risks.
The incident was reported by the New York Post on 2026‑05‑12 in an article titled “Class action targets Cushman & Wakefield over data breach”.
Because the supplied material does not link ShinyHackers to the Cushman & Wakefield event, no specific targeting patterns, sectors or regions can be attributed to the actor.
Likewise, no details about strategic objectives such as financial gain, espionage or disruption can be inferred for ShinyHackers from the given information.
The absence of any publicly disclosed malware families, initial‑access vectors, tooling preferences or affiliations means those aspects of the actor’s profile remain undetermined.
Therefore, the only verifiable fact about ShinyHackers in the current context is the existence of its alias.
Any further description would require additional evidence not present in the provided sources.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 0 sources.