Minted
Incident posture
Timeline
Summary
A hacking group known as Shiny Hunters flooded a dark web marketplace with databases stolen from multiple companies, including a large batch of user records from the design marketplace Minted. The stolen data, which appeared legitimate based on reviewed samples, was offered for sale alongside other databases from at least ten additional firms, bringing the total amount of compromised user records being trafficked to over 73 million. The breach exposed user account information, and the incident was part of a broader campaign in which the same threat actor also listed data from other major platforms, prompting some affected organizations to begin issuing breach notifications to their customers.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In May 2020, a hacking group identifying itself as Shiny Hunters began flooding a dark web hacking marketplace with a large number of stolen user databases, advertising records stolen from multiple companies over a short period. The activity was first observed over the preceding weekend when the group started selling a database containing more than 90 million user records allegedly taken from Tokopedia, Indonesia's largest online store, with initial asking prices reported between $1,500 and $2,500 per database. Shortly after that initial listing, Shiny Hunters offered for sale a second database containing approximately 22 million user records that they claimed belonged to Unacademy, one of India's largest online learning platforms; after being contacted about the listing, Unacademy issued a statement confirming that the company had been breached. A third high-profile listing followed on Wednesday, when the group claimed to have compromised a Microsoft GitHub account earlier in the year and began leaking files described as belonging to Microsoft's private source code repositories. Although Microsoft did not officially confirm the breach, sources indicated to BleepingComputer that the shared data appeared to consist of private repositories accessible only to Microsoft employees. Across these three early listings alone, roughly 26 million accounts were being advertised for sale, and pricing fluctuated after initial posting, with the ChatBooks data set eventually being offered at a higher price of $3,500.
Following reporting on those initial breaches, ChatBooks began issuing data breach notifications to its users, indicating that the company acknowledged its users' data had been exposed. The pace of listings then accelerated significantly when cyber intelligence firm Cyble informed BleepingComputer that Shiny Hunters had begun "flooding the market" with additional stolen databases, bringing the total number of affected companies whose data was being advertised up to eleven. In aggregate, the group claimed to be selling user records totaling approximately 73.2 million across all of the listed companies. BleepingComputer reviewed samples of the user records from the various listings and reported that the data appeared to be legitimate, though the breaches had not been fully confirmed at the time of reporting. After learning about the expanded set of databases being offered, BleepingComputer reached out to the affected companies for comment but had not received responses prior to the article's posting. The reporting did not specify which of the eleven companies had been contacted or which had responded, and it did not provide confirmation statements from any of the newly added victims beyond the earlier Unacademy confirmation and the subsequent ChatBooks notification activity. The article's focus remained on the volume and rapid cadence of the group's listings rather than on the technical details of how each individual company had been compromised, and no specific attack vectors, exploitation timelines, or intrusion methods were described for the broader set of eleven victims. The incident as reported centers on the mass advertisement of aggregated user records on a dark web marketplace, the involvement of the Shiny Hunters group across multiple separate claimed breaches, and the early-stage outreach by media and intelligence researchers to the affected organizations, several of which had yet to publicly acknowledge the incidents at the time the article was published.
Sources
Sources available to members: 1 source.