ShinyHunters
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
ShinyHunters, also referred to as Shiny Hunters, is a hacking group that has been publicly linked to a series of data breaches and extortion campaigns originating from Russia. The actors have targeted a broad range of sectors including government and international organizations (such as the Council of Europe), retail corporations (JCPenney, Catalyst Brands, Bonobos), insurance regulators (National Association of Insurance Commissioners), higher education institutions (University of Nottingham, University of North Carolina at Chapel Hill, various California universities and K‑12 districts), healthcare providers (DentaQuest, Havenly), technology and software providers (Canvas LMS, Pixlr, BuyUCoin, MongoDB‑based services), media and entertainment platforms (Mashable, Pluto TV, Animal Jam, Wattpad), financial technology firms (Dave, Upstox), and numerous Indian‑based companies spanning fashion retail, food delivery, brokerage, dating apps, and cloud‑based services. Their activity has been observed across North America, Europe, and Asia, indicating a geographically dispersed focus rather than a single regional concentration.
The group’s observed tactics, techniques and procedures include the exploitation of unpatched zero‑day vulnerabilities, most notably in Oracle PeopleSoft, which they leveraged to breach over a hundred organizations in mid‑2026. They also repeatedly exploit cloud‑service misconfigurations, such as exposed Amazon Web Services buckets, improperly secured MongoDB instances, and compromised Slack accounts that were used to obtain AWS keys, as seen in the Animal Jam and Pixlr incidents. ShinyHunters frequently deploy ransomware‑style pop‑up messages demanding payment to prevent the release of stolen data, as demonstrated during the Canvas LMS attacks in May 2026, and they engage in direct extortion by threatening to publish data unless victims negotiate, a tactic seen in the RentoMojo and DentaQuest cases. Stolen data is routinely sold on hacker forums or leaked for free, with the group advertising databases from Tokopedia, Unacademy, BigBasket, Wattpad, Mathway and many others, and they have been observed cracking hashed passwords to create credential‑stuffing lists. Their operations are facilitated through interactions with data‑broker actors and the use of underground forums for distribution. While open sources identify the group’s location as Russia, no explicit state sponsorship or affiliation with a larger criminal consortium has been documented in the provided material. Representative campaigns highlighted in the reporting include the June 2026 Council of Europe breach, the May 2026 DentaQuest incident affecting millions of dental‑benefit members, the mid‑2026 Oracle PeopleSoft zero‑day campaign that hit numerous universities and businesses, and the May 2026 Canvas LMS ransomware‑style attacks that disrupted educational institutions across the United States. These examples illustrate the group’s reliance on exploiting technical vulnerabilities, leveraging cloud misconfigurations, and monetizing stolen information through extortion and data sales.
Incidents
Attributed incidents are available to members.
110 incidents