CSIDB logo
Incident

Styleshare

Incident posture

Attack window
May 2020
Location
Indonesia
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 11:59

Linked entities

Victim
Styleshare
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacking group known as Shiny Hunters flooded a dark web marketplace with stolen user databases from 11 different companies, including Styleshare, in a single week. The combined leaks exposed approximately 73.2 million user records, with databases sold individually at prices ranging from $1,500 to $3,500. The group had previously gained attention for selling data from other major platforms before rapidly expanding the volume of breached information offered for sale. Samples of the stolen records appeared legitimate based on review, though not all affected companies had confirmed the breaches at the time of reporting. The incident is part of a broader pattern of high-volume data theft and resale affecting multiple organizations within a short timeframe.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In May 2020, a hacking group identified as Shiny Hunters began flooding a dark web hacking marketplace with user databases stolen from multiple companies, ultimately putting records from 11 different organizations up for sale. The wave of listings represented a combined total of approximately 73.2 million user records. The activity began over the weekend preceding May 9, 2020, with the appearance of a database tied to Tokopedia, Indonesia's largest online store, which contained more than 90 million user records. Within days, the group expanded its postings to include a database of 22 million user records belonging to Unacademy, one of India's largest online learning platforms. After being contacted about the listing, Unacademy issued a statement confirming that the company had been breached. The initial asking prices for these individual databases ranged between $1,500 and $2,500, though at least one listing—ChatBooks—saw its price increase to $3,500 shortly after it was posted.

Midweek, Shiny Hunters escalated their activity by claiming to have compromised a Microsoft GitHub account earlier in the year, an intrusion they used to obtain and leak files from private source code repositories. While Microsoft did not officially acknowledge that its GitHub account had been breached, sources cited in reporting indicated that the data shared was indeed drawn from private repositories accessible only to Microsoft employees. Following the public exposure of these three early incidents, which together accounted for roughly 26 million accounts being offered for sale, ChatBooks began sending data breach notifications to its own users in response to the appearance of its records on the marketplace. The reports received by affected users marked one of the first formal responses by a victim company during this series of postings.

By late in the week, cyber intelligence firm Cyble informed BleepingComputer that Shiny Hunters had expanded the operation dramatically, "flooding the market" with databases from additional companies and bringing the total number of organizations whose data was being offered up to 11. Review of sample user records shared with BleepingComputer indicated that the breaches appeared legitimate, although the reports had not been fully confirmed at the time of publication. Outreach attempts to the newly identified affected companies had likewise not produced responses. The cumulative scope of the operation—spanning an Indonesian e-commerce platform, an Indian education company, a major software vendor's code repositories, a book-related service, and other unnamed organizations—made the campaign one of the more prolific dark web data sales events of the period. The pattern of listings, combined with the steady pricing and the rapid succession of postings, established the Shiny Hunters group as the central actor behind the breaches being advertised.

Sources

Sources available to members: 1 source.

CSIDB