CSIDB logo
Incident

Dave

Incident posture

Attack window
Nov 2020
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2025-11-21 00:00

Linked entities

Victim
Dave
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Nov 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A threat actor known as ShinyHunters compromised multiple entities including Dave.com, leading to unauthorized distribution of databases. Following a dispute over an alleged breach of exclusivity in a data sale, a banned forum member retaliated by leaking databases from several companies on a Russian-language forum. The leaked data was swiftly deleted, and the member's account was deactivated shortly thereafter. The incident involved databases from various organizations, though it remains unclear whether all affected parties were initially aware of the breaches.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The incident involving ShinyHunters in November 2020 centered on unauthorized data breaches and subsequent leaks of multiple corporate databases, accompanied by disputes within cybercriminal forums. On or around November 12, threat actors associated with ShinyHunters advertised and distributed stolen databases from entities including Animal Jam, eatigo, Peatix, Redmart, Pluto.tv, Storybird, Homechef, and others. Evidence suggested some affected organizations might not have been aware of the breaches at the time of exposure, prompting external outreach by journalists for verification. Concurrently, a dispute erupted on a hacking forum when a user accused ShinyHunters and a data broker known as "ExpertData" of breaching an exclusivity agreement. The complainant alleged he had paid tens of thousands of dollars for sole access to certain datasets, only to discover the data had been redistributed afterward. Forum administrators banned the aggrieved buyer rather than addressing the alleged fraud, escalating tensions.

In retaliation, the banned individual migrated to a Russian-language cybercrime forum and publicly released multiple databases without charge, including those from Eatigo, Eskimi, Geniusu, Glofox, JoinPiggy, Peatix, Pluto, Nitrogo, and Redmart. These retaliatory leaks were short-lived, as the datasets were deleted within hours, and the user’s account was deactivated within 24 hours. The rapid removal limited widespread access to the data, though the exposure still posed risks to the affected organizations and their users. No specific containment or remediation actions by the victim companies were detailed in available reports, leaving the full operational and financial impacts unquantified. The incident underscored the volatile nature of cybercriminal ecosystems, where internal disputes can trigger secondary data exposures beyond the initial breaches.

Sources

Sources available to members: 1 source.

CSIDB