CSIDB logo
Incident

Bhinneka

Incident posture

Attack window
May 2020
Location
Indonesia
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 12:06

Linked entities

Victim
Bhinneka
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacking group known as Shiny Hunters flooded a dark web marketplace with stolen user databases from 11 different companies, leaking a combined total of 73.2 million user records. The campaign began with the sale of a 90 million record database from Indonesia's largest online store, followed by 22 million user records from a major Indian online learning platform. The group also claimed to have breached Microsoft's GitHub account earlier in the year, leaking files from private source code repositories. After samples of the data were reviewed and confirmed as credible, additional databases from other companies continued to be sold on the marketplace. Among the affected entities, ChatBooks began notifying its users of the breach once informed. The incidents were disclosed by cyber intelligence researchers, though several of the impacted companies had not publicly responded at the time of reporting.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early May 2020, a hacking group operating under the name "Shiny Hunters" began flooding a dark web hacking marketplace with user databases stolen from multiple companies, bringing the total amount of user records being sold to approximately 73.2 million across eleven different organizations. The wave of listings began over the weekend of May 2–3, 2020, with the appearance of a database containing over 90 million user records allegedly stolen from Tokopedia, Indonesia's largest online store. Shortly thereafter, the same actor listed a second database consisting of 22 million user records attributed to Unacademy, one of India's largest online learning platforms. Following outreach by BleepingComputer, Unacademy issued a statement confirming that the company had been breached, marking the first official acknowledgment among the affected organizations.

The activity continued in the following days when Shiny Hunters claimed to have compromised a Microsoft GitHub account earlier in 2020 and began leaking files from the company's private source code repositories. Although Microsoft did not publicly confirm the intrusion, sources cited by BleepingComputer indicated that the shared data corresponded to private repositories accessible only to Microsoft employees. With the addition of these three databases, Shiny Hunters had placed approximately 26 million accounts up for sale, with initial asking prices for each database ranging between $1,500 and $2,500. By May 9, 2020, the marketplace activity had expanded further to include eight additional databases, though the specific contents and origins of the newer listings had not yet been independently verified. The aggregate scope of the operation grew to encompass databases from eleven companies, with a combined total of roughly 73.2 million user records.

Several of the affected companies were contacted by BleepingComputer regarding the listings, but at the time of reporting none had responded with confirmation. One exception was ChatBooks, which began sending data breach notifications to its customers after being informed of the situation. Cyble, a cyber intelligence firm, alerted BleepingComputer on May 8, 2020, that Shiny Hunters had escalated their activity by flooding the market with new listings, prompting broader concern across the security community. Based on samples of user records examined by BleepingComputer, the data being sold appeared legitimate, although none of the databases had been fully confirmed as authentic by the affected organizations at the time the article was published. The actor continued to actively trade and promote the stolen data on the dark web marketplace throughout the period covered by the report.

Sources

Sources available to members: 1 source.

CSIDB