CSIDB logo
Incident

Star Tribune

Incident posture

Attack window
May 2020
Location
Indonesia
Status
Historical
CIA posture
Available to members
Updated
2026-02-03 05:20

Linked entities

Victim
Star Tribune
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacking group known as Shiny Hunters leaked and sold databases containing approximately 73.2 million user records stolen from 11 companies on a dark web marketplace. The compromised data included accounts from multiple organizations, such as an Indonesian online store, an Indian e-learning platform, and a major technology firm's private source code repositories. While some affected entities confirmed breaches and notified users, others remained unresponsive to inquiries. Samples of the stolen records appeared legitimate, though full verification was pending. The group initially priced individual databases between $1,500 and $3,500, adjusting amounts over time as they continued releasing additional datasets.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In May 2020, the hacker group Shiny Hunters initiated a widespread data breach campaign by selling stolen user databases on dark web marketplaces. The activity began with the sale of 91 million user records from Tokopedia, Indonesia's largest online marketplace, followed by 22 million records from Unacademy, a major Indian online learning platform. After BleepingComputer contacted Unacademy about the breach, the company confirmed the incident and issued a public statement acknowledging unauthorized access to their systems. Shiny Hunters subsequently claimed responsibility for breaching Microsoft's GitHub account earlier that year, leaking files from private source code repositories. While Microsoft did not officially confirm the GitHub compromise, sources familiar with the matter verified to BleepingComputer that the leaked repositories contained proprietary code accessible only to Microsoft employees.

The group expanded their operations by flooding dark web markets with data from eleven companies, totaling 73.2 million compromised user records. Initial pricing for these databases ranged from $1,500 to $2,500, though some listings like ChatBooks' records later increased to $3,500. Cybersecurity firm Cyble alerted BleepingComputer about the surge in Shiny Hunters' marketplace listings, which included additional unconfirmed breaches beyond the initial three high-profile incidents. ChatBooks began notifying affected users after media reports surfaced, though most targeted companies had not publicly acknowledged breaches or responded to inquiries at the time of reporting. BleepingComputer examined samples of the leaked data and found them consistent with legitimate breaches, though full verification remained pending. The cumulative exposure spanned multiple industries and geographic regions, with compromised credentials posing reuse risks across other platforms where victims maintained accounts.

Sources

Sources available to members: 1 source.

CSIDB