< ciso
brief />
Tag Banner

All news with #shinyhunters tag

84 articles

RingCentral Breach Exposes Millions of Account Records

πŸ”’ In July 2026, the ShinyHunters extortion group claimed to have stolen personal data from RingCentral accounts after a reported social engineering intrusion. RingCentral acknowledged a security incident and said remediation steps were taken, noting services continued to operate and only a portion of customers were affected. Have I Been Pwned confirmed leaked data tied to 1.6 million accounts, including names, emails, phone numbers, and addresses.
read more β†’

ShinyHunters claims Brinks Home breach and data threat

πŸ”’ Brinks Home disclosed a security intrusion identified on July 20 and activated incident response procedures while engaging leading forensics experts. The company said alarm monitoring and system functionality were not impacted. Extortion group ShinyHunters claims to have stolen millions of Salesforce records and threatened to publish the data, though BleepingComputer has not verified the claims.
read more β†’

Health-ISAC warns of rising ShinyHunters data theft

πŸ”’ Health-ISAC warns healthcare and medtech organizations of an uptick in successful attacks by the extortion group ShinyHunters, which leverages supply-chain and identity attacks to breach cloud SaaS and storage platforms. Attacks commonly begin with vishing and social engineering to compromise SSO accounts (Okta, Microsoft Entra, Google), granting access to services like Salesforce, Microsoft 365, SharePoint, and others. The advisory urges hardening helpdesk and SSO procedures, adopting phishing-resistant MFA, treating SSO as Tier 0, and centralizing audit logs to detect large-scale cloud data theft.
read more β†’

ShinyHunters Claims Responsibility for EY Breach

πŸ” The ShinyHunters extortion group claims it conducted the Ernst & Young breach, asserting it obtained credentials via a supply-chain attack and accessed the firm's support systems. EY disclosed the incident after detecting unusual activity on April 23, noting attackers accessed a third-party support ticket platform between March 28 and April 12 and downloaded documents. The firm said stolen tickets may include client tax information and has offered affected clients 24 months of identity monitoring through Experian. EY has not confirmed ShinyHunters' claim or identified the compromised third-party service.
read more β†’

ShinyHunters leaks fuel $2,000 sextortion email scam

πŸ“§ Threat actors are using email addresses exposed in data leaks attributed to ShinyHunters to send sextortion messages demanding $2,000 in Bitcoin. The campaign reuses leaked emails and breached company names to make threats appear credible, though there is no evidence recipients’ devices were actually compromised. BleepingComputer confirmed the use of data from multiple ShinyHunters incidents and observed messages falsely claiming remote access to cameras and files to coerce payment.
read more β†’

Abbott investigates dual cybersecurity incidents amid claims

πŸ” Abbott Laboratories is probing two separate cybersecurity incidents after confirming unauthorized access to legacy Exact Sciences systems within its Cancer Diagnostics business and investigating a separate claim of a breach of its LabCentral portal. The company says the Cancer Diagnostics intrusion does not affect operations, products, manufacturing, or patient services and that legacy systems are separate from Abbott's main environment. Abbott engaged incident response teams, notified law enforcement, and does not expect a material business impact. The extortion gang ShinyHunters and another actor, ShadowByt3$, each claim to have exfiltrated different sets of data, though Abbott disputes some characterizations.
read more β†’

Defending SaaS OAuth Abuse Targeting Salesforce

πŸ”’ Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more β†’

Police point to Dutch suspects in Odido breach

πŸ”Ž The Dutch National Police report strong indications that Dutch-speaking attackers were involved in the February breach of telecom provider Odido. Investigators recovered traces including a phone call where an impersonator posing as an Odido IT employee used social engineering to enable a phishing-based data theft. Odido disclosed the incident affected millions of customers and that exposed records may include names, addresses, contact details, IBANs, and some ID numbers, while call records, billing data and passwords were not exposed. The extortion group ShinyHunters claimed responsibility and released a large archive of stolen records, and the gang has been linked to multiple vishing and SSO-targeting campaigns affecting major providers.
read more β†’

Kodak confirms data breach amid ShinyHunters claim

πŸ”’ Kodak has confirmed an investigation after an unauthorized third party gained temporary access to a limited amount of company data. The company engaged external cybersecurity experts and is working with law enforcement, asserting there is no threat to systems or operations. The ShinyHunters extortion group has claimed responsibility, alleging over 2.2 million records were stolen and threatening to leak the data.
read more β†’

Council of Europe Probes ShinyHunters Breach Claims

πŸ”Ž The Council of Europe is investigating claims by the ShinyHunters extortion group that it exfiltrated hundreds of thousands of HR and payroll records. The organization, representing 46 member states, said it is assessing the situation and cannot provide further comment. ShinyHunters posted on a dark web leak site, threatening to publish alleged files containing extensive personal and financial data if demands are not met.
read more β†’

ShinyHunters exploited Oracle PeopleSoft zero‑day

πŸ”’ The ShinyHunters extortion group exploited an unpatched Oracle PeopleSoft remote code execution zero‑day (CVE-2026-35273) to compromise enterprise servers, steal data, and extort victims. Mandiant links the activity to UNC6240 and observed attacks from May 27 to June 9, before Oracle published its advisory on June 10. The flaw requires no authentication and exposes PeopleTools 8.61 and 8.62 installations with externally reachable Environment Management Hub endpoints. Universities were heavily targeted; mitigations focus on disabling or blocking PSEMHUB and hunting for post‑exploit indicators.
read more β†’

Oracle mitigates PeopleSoft zero-day used in data theft

πŸ”” Oracle warns of a critical PeopleSoft Suite zero-day, CVE-2026-35273, enabling unauthenticated remote code execution and carrying a CVSS 9.8 score. The flaw impacts PeopleSoft PeopleTools versions 8.61 and 8.62; Oracle released emergency mitigations and plans a patch. Threat actor ShinyHunters is linked to active exploitation and large-scale data theft across hundreds of instances. Administrators are urged to review logs and block identified IPs to assess compromise.
read more β†’

Nottingham University student-records breach affects 454,600

πŸ”’ The University of Nottingham confirmed a cyber incident that exposed a significant amount of student record data, affecting current students and alumni. The university reported the breach to the Information Commissioner's Office and Action Fraud and is working with the platform vendor on a forensic investigation. The ShinyHunters extortion group has claimed responsibility and posted an archive they say contains finance, payment, personal and academic data from multiple campuses.
read more β†’

ShinyHunters Target Oracle PeopleSoft Instances

πŸ›‘οΈ ShinyHunters are actively stealing data from Oracle PeopleSoft instances, claiming breaches across 300 instances at over 100 organizations. The actor says they used a mix of old and zero-day vulnerabilities in a "gadget chain," with many victims in the education sector. Exposed tooling, scripts, and IOCs were found in online directories, and impacted organizations are urged to check logs and begin incident response immediately.
read more β†’

DentaQuest breach exposed data of 2.6 million accounts

πŸ”’ DentaQuest, a major US dental benefits administrator, disclosed a cybersecurity incident after the extortion group ShinyHunters posted and later leaked over 234 GB of stolen data. The company confirmed limited disruption to services on June 2 and said it engaged external experts to investigate and contain the breach. Analysis by Have I Been Pwned found records for 2.6 million accounts in the leaked dataset, including emails, names, phone numbers, government IDs, insurance details, genders, and dates of birth.
read more β†’

Lessons from the Canvas LMS cyberattack

πŸ”’ Over May 6–7, 2026, Canvas LMS users encountered a defaced login page claiming a ShinyHunters extortion of Instructure, alleging theft of 3.65TB of data affecting about 275 million students, faculty, and staff across nearly 9,000 institutions. Instructure identified an exploited support-ticket vulnerability in its Free for Teacher environment and temporarily disabled that service while investigating. The incident disrupted finals and highlighted risks from centralized SaaS platforms, third-party dependencies, communications breakdowns and the evolving economics of extortion.
read more β†’

Charter Communications breach exposes 4.9M accounts

πŸ”’ The ShinyHunters extortion gang claims to have stolen personal details from 4.9 million Charter Communications accounts after a vishing attack in early April that compromised an employee's Microsoft Entra account. Charter confirmed the incident but says no sensitive PII or CPNI was exfiltrated, while Have I Been Pwned verified leaked records containing names, emails, addresses, phone numbers and some job titles. The group published stolen Salesforce data after a ransom was refused.
read more β†’

Charter Confirms Breach After ShinyHunters Extortion

πŸ”’ Charter Communications confirmed a data breach after the ShinyHunters extortion group claimed to have stolen millions of customer records. The company says it is notifying authorities and maintains that No sensitive personal information (PI) or CPNI was exfiltrated. ShinyHunters alleges the intrusion began via a vishing attack that compromised an employee's Microsoft Entra account and allowed access to Salesforce data.
read more β†’

7‑Eleven Breach Exposes Personal Data of 185K

πŸ” 7‑Eleven disclosed that an unauthorized party accessed franchisee document systems on April 8, 2026, resulting in a data theft. Have I Been Pwned analyzed the leaked files and found 185,300 unique email addresses and accompanying personal details, including names, dates of birth, phone numbers, and physical addresses. The ShinyHunters extortion gang claimed responsibility after publishing a large archive they said came from 7‑Eleven's Salesforce environment.
read more β†’

FBI Issues Advisory After ShinyHunters Breach of Canvas LMS

⚠️ The FBI's IC3 issued an advisory on 15 May 2026 about the ShinyHunters extortion gang breaching an online learning management system used by US educational institutions. Although the advisory avoided naming the vendor, reporting and Instructure's confirmation made clear Canvas was affected and the company reportedly paid a ransom after receiving alleged 'shred logs'. The FBI warns victims not to engage with extortionists, enable multi‑factor authentication, and remain vigilant against phishing, harassment, and swatting; students and staff should assume their data may be exposed and await official guidance.
read more β†’