Skip to content
← All Threat Actors
Cybercrime critical International

ShinyHunters

Cybercrime group (international, members identified in France, US, and Morocco) · Financial — data theft, extortion, and underground data sales

Reports 3
Active Since 2020
Last Reported 13 Jun 2026
Sectors Targeted education, healthcare, finance, government, communications, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Vishing: phone-based social engineering to compromise identity provider accounts (Microsoft Entra, Okta)
  • Snowflake customer credential stuffing — exploiting accounts lacking MFA on cloud data warehouse instances
  • Large-scale database exfiltration from SaaS environments integrated with compromised identity providers
  • Single-extortion model: data publication threat without ransomware encryption
  • Underground forum data sales (BreachForums, Telegram channels)
  • Simultaneous targeting of multiple organisations sharing common infrastructure (Snowflake campaign, 165+ victims)

Known Targets

Ticketmaster/Live Nation (560M records, 2024 — Snowflake campaign)Santander Bank (30M customer records, 2024)Charter Communications (4.9M confirmed records, May 2026 — vishing)Advance Auto Parts, Neiman Marcus, Pure Storage (2024 Snowflake campaign)AT&T (73M records — legacy breach)Carnival Corporation (2026)

Analyst Notes

ShinyHunters rose to prominence through an unprecedented sequence of large-scale data breaches in 2020–2024, primarily targeting cloud-hosted data. The defining campaign was the 2024 Snowflake credential operation: by obtaining login credentials from infostealer logs and applying them against Snowflake instances without MFA enforcement, the group breached over 165 organisations simultaneously — including Ticketmaster (560M records) and Santander (30M records). Sébastien Raoult (French national) was sentenced to three years in US federal prison in May 2024; other members remain at large. The 2026 Charter Communications vishing breach demonstrates continued operational adaptation — shifting from cloud credential stuffing to identity-platform social engineering as MFA adoption increases. Consistent follow-through on publication threats means extortion demands carry credible deterrent weight.

Also Known As

Sp1d3r (forum handle)ShinyHunters