< ciso
brief />
Tag Banner

All news with #shinyhunters tag

101 articles

FBI Removes Contractor Over ShinyHunters Job Portal Breach

πŸ”’ The FBI removed an Accenture contractor after an alleged role in a ShinyHunters breach that exposed thousands of bureau employees' personal data. Reuters sources say the incident stemmed from a third-party platform security failure where a contractor failed to apply an explicit patch. The FBI cited mitigation steps and removal of the contractor, while Accenture affirmed continued support for the FBI mission. Reports indicate the exploited platform was Oracle PeopleSoft and the attack leveraged a CVE-2026-35273 bypass.
read more β†’

Suspected ShinyHunters Member Reportedly Detained in Jordan

πŸ” Reports indicate a suspected ShinyHunters member known as "Rey" (identified as Saif al-Din Khader) was detained in Jordan and is cooperating with the FBI and international law enforcement. Sources say he is assisting by walking investigators through his devices and communications to help identify other group members. The arrest follows an FBI probe into a claimed ShinyHunters breach of FBI systems and comes after other recent arrests tied to the group.
read more β†’

FBI Urges ShinyHunters Members to Surrender Now

πŸ›‘οΈ The FBI thanked Dutch police for arresting a 24-year-old suspected of playing a leadership role in the ShinyHunters gang, and warned remaining members to come forward while they still can. The arrest followed revelations that ShinyHunters breached the FBI job application portal, exposing Social Security numbers and sensitive medical records of about 5,000 staff. The group claims to have exploited a patched Oracle PeopleSoft flaw and has since escalated activity, including extortion attempts against other cybercrime groups.
read more β†’

ShinyHunters suspect arrested and probed for murder plots

πŸ” Dutch police arrested a 24-year-old Amsterdam man on September 15 on suspicion of involvement with the ShinyHunters cybercrime group, and investigators say his laptop contained details of two alleged murder plots abroad. Authorities are treating the homicide allegations separately from cybercrime probes and have extended his detention for three months while digital forensic work continues. The suspect, identified by reporting as Pepijn van der Stap, previously served prison time for data theft and later worked as a penetration tester.
read more β†’

FBI urges ShinyHunters members to surrender now

πŸ›‘οΈ The FBI has publicly urged members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested an alleged leader on September 15. Authorities found extensive data on the suspect's laptop, including details about planned murders, and the suspect remains in pre-trial detention for at least 90 days. The FBI says ShinyHunters has breached over 140 organizations and extorted at least $70 million, often targeting SSO, third-party vendors, and cloud SaaS platforms.
read more β†’

Dutch Police Arrest Suspect Linked to ShinyHunters

πŸ”’ Dutch authorities confirmed the arrest of a 24-year-old Amsterdam resident in an investigation into the hacker group ShinyHunters. The suspect is due to appear before the Rotterdam District Court on September 29, 2026, after being taken into custody on September 15. Independent reporting identified the individual as Pepijn van der Stap (aka Umbreon), who previously worked in cybersecurity and was linked to earlier data thefts.
read more β†’

Dutch police arrest former hacker linked to ShinyHunters

πŸ“° Dutch authorities arrested a 23-year-old convicted cybercriminal, identified by sources as Pepijn van der Stap, on suspicion of aiding the ShinyHunters hacking collective in data thefts and extortion. Van der Stap β€” previously convicted in 2023 and released in December 2025 β€” had presented himself as reformed while working in offensive security. Following his detention, ShinyHunters escalated attacks, claiming breaches of the FBI jobs site and extorting other groups, exploiting a PeopleSoft flaw (CVE-2026-35273). Investigations continue into ties between ShinyHunters, a rival teenage operator known as Rey, and recent large-scale data thefts.
read more β†’

Attackers Bypass WAFs to Exploit Oracle PeopleSoft

πŸ›‘οΈ Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273, CVSS 9.8) by activity linked to ShinyHunters/UNC6240. The campaign weaponizes a modified exploit that URL-encodes the character "P" to bypass WAF rules, targeting multiple sectors globally and deploying web shells, trojanized installers, and backdoors. Affected organizations are urged to apply patches, disable or remove the PSEMHUB component, inspect logs and web directories, rotate credentials, and hunt for signs of data exfiltration and persistence.
read more β†’

ShinyHunters renews PeopleSoft exploit campaign

πŸ” Mandiant and Google Threat Intelligence Group (GTIG) report that UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft by URL-encoding the vulnerable /PSEMHUB/ path to bypass WAF rules. The actor deployed web shells and a trojanized binary (Ple64.exe) loading the SIDEEYE backdoor, expanding targeting across education, technology, healthcare, government and more. Immediate patching, WAF normalization, and mitigation guidance are recommended.
read more β†’

ShinyHunters Claims Hack of Clop Ransomware Group

πŸ›‘οΈ The ShinyHunters gang claims to have breached the Clop ransomware group's dark web leak site, defacing it on 18 September and posting a message stating β€œTHIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”. They say they stole private keys, server data, activity logs and IP addresses that could identify Clop members, and left a ransom demand directing Clop to contact them. The incident appears to be part of a wider feud between the two groups dating to 2025 over claimed ownership of Oracle E-Business Suite exploits, including CVE-2025-61882.
read more β†’

ShinyHunters breaches Clop leak site, claims keys

πŸ”’ The ShinyHunters extortion group breached and defaced the Clop (Cl0p) ransomware gang's Tor data leak site after exploiting an alleged unauthenticated file upload flaw in Grav CMS. The attackers uploaded a taunting text file and replaced the site with ASCII art, claiming to have obtained server data, logs, source code, and the onion service's private keys. BleepingComputer confirmed the defacement and file upload but has not independently verified theft of logs or keys, while ShinyHunters says it will extort Clop within 72 hours.
read more β†’

Florida DMV DAVID Database Breach Confirmed

πŸ›‘οΈ The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a breach of its DAVID driver database after the ShinyHunters extortion group claimed to have compromised the system. The agency says the intrusion involved compromised credentials from a single Plant City Police Department user improperly stored on a personal device and that the incident was quickly mitigated. FLHSMV is coordinating with state authorities and treating the matter as an ongoing criminal investigation.
read more β†’

ShinyHunters claims Florida DMV data breach

πŸ”’ ShinyHunters says it accessed the Florida Department of Highway Safety and Motor Vehicles' DAVID system and stole over 200,000 records, publishing a screenshot tied to Jeffrey Epstein as proof. The group set a September 11 deadline to negotiate before releasing additional data and claims to have exploited a password-reset weakness to compromise multiple DMV accounts. The alleged intrusion could expose sensitive personal identifiers that enable identity theft and fraud. While IDScan has confirmed a related Nexus ID-scan exposure, the Florida DMV has not publicly verified ShinyHunters' claim.
read more β†’

Mathspace data breach exposes over 1 million records

πŸ”’ Mathspace disclosed that attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access and stealing personal information belonging to students, staff, and parents in Australia and New Zealand. The company confirmed the intrusion was first leveraged on August 10, with data downloaded on August 27 and a breach confirmed on September 3, 2026. Mathspace says 1,079,819 people were affected but asserts that no passwords, authentication tokens, SSO or API credentials, or academic records were exposed. The firm warned those affected to monitor for suspicious account activity and noted the incident is part of a wider series of Metabase compromises linked to threat actors like ShinyHunters.
read more β†’

Trezor Data Breach Now Affects 81,000 Customers

🚨 Trezor disclosed that an August data breach at its logistics partner ShipMonk has expanded to affect 81,000 customers after an additional 67,000 U.S. customers were found impacted. The exposed data includes full names, shipping addresses, email addresses, phone numbers, and order numbers for customers who ordered during specific periods between 2019 and 2026. Trezor confirmed its own systems and devices were not compromised and warned customers to expect increased phishing and fraud risk. The incident stems from a Metabase vulnerability and extortion attempts linked to the ShinyHunters gang.
read more β†’

Trezor: ShipMonk breach exposed 67,000 US customers

πŸ“£ Trezor disclosed that 67,000 additional U.S. customers were impacted by a ShipMonk breach, exposing names, emails, phone numbers, shipping addresses, and order numbers from Nov 2019 to Aug 2021. The company emphasized that hardware wallet security was not affected and that it had repeatedly requested deletion of customer data. ShipMonk reportedly used a Metabase instance vulnerable to CVE-2026-72898, and the incident is tied to the ShinyHunters extortion gang.
read more β†’

ReliaQuest: ShinyHunters Social Engineering Incident

πŸ›‘οΈ ReliaQuest disclosed a social engineering campaign by ShinyHunters that briefly exposed its identity dashboard but said claims of a compromise or ransomware targeting are false. The attacker used a lookalike domain and fake SSO page, convincing one employee to approve a push and gain a brief, view-only session. ReliaQuest emphasized robust controlsβ€”device trust, session termination, password expiry and auth resetsβ€”prevented access to applications or customer data.
read more β†’

RingCentral Breach Exposes Millions of Account Records

πŸ”’ In July 2026, the ShinyHunters extortion group claimed to have stolen personal data from RingCentral accounts after a reported social engineering intrusion. RingCentral acknowledged a security incident and said remediation steps were taken, noting services continued to operate and only a portion of customers were affected. Have I Been Pwned confirmed leaked data tied to 1.6 million accounts, including names, emails, phone numbers, and addresses.
read more β†’

ShinyHunters claims Brinks Home breach and data threat

πŸ”’ Brinks Home disclosed a security intrusion identified on July 20 and activated incident response procedures while engaging leading forensics experts. The company said alarm monitoring and system functionality were not impacted. Extortion group ShinyHunters claims to have stolen millions of Salesforce records and threatened to publish the data, though BleepingComputer has not verified the claims.
read more β†’

Health-ISAC warns of rising ShinyHunters data theft

πŸ”’ Health-ISAC warns healthcare and medtech organizations of an uptick in successful attacks by the extortion group ShinyHunters, which leverages supply-chain and identity attacks to breach cloud SaaS and storage platforms. Attacks commonly begin with vishing and social engineering to compromise SSO accounts (Okta, Microsoft Entra, Google), granting access to services like Salesforce, Microsoft 365, SharePoint, and others. The advisory urges hardening helpdesk and SSO procedures, adopting phishing-resistant MFA, treating SSO as Tier 0, and centralizing audit logs to detect large-scale cloud data theft.
read more β†’