ShinyHunters
Cybercrime group (international, members identified in France, US, and Morocco) · Financial — data theft, extortion, and underground data sales
Tactics, Techniques & Procedures (TTPs)
- Vishing: phone-based social engineering to compromise identity provider accounts (Microsoft Entra, Okta)
- Snowflake customer credential stuffing — exploiting accounts lacking MFA on cloud data warehouse instances
- Large-scale database exfiltration from SaaS environments integrated with compromised identity providers
- Single-extortion model: data publication threat without ransomware encryption
- Underground forum data sales (BreachForums, Telegram channels)
- Simultaneous targeting of multiple organisations sharing common infrastructure (Snowflake campaign, 165+ victims)
Known Targets
Analyst Notes
ShinyHunters rose to prominence through an unprecedented sequence of large-scale data breaches in 2020–2024, primarily targeting cloud-hosted data. The defining campaign was the 2024 Snowflake credential operation: by obtaining login credentials from infostealer logs and applying them against Snowflake instances without MFA enforcement, the group breached over 165 organisations simultaneously — including Ticketmaster (560M records) and Santander (30M records). Sébastien Raoult (French national) was sentenced to three years in US federal prison in May 2024; other members remain at large. The 2026 Charter Communications vishing breach demonstrates continued operational adaptation — shifting from cloud credential stuffing to identity-platform social engineering as MFA adoption increases. Consistent follow-through on publication threats means extortion demands carry credible deterrent weight.
Also Known As
Intelligence Reports
ShinyHunters Weaponised Oracle PeopleSoft Zero-Day Against 100+ Universities and Enterprises: CVE-2026-35273
ShinyHunters (UNC6240) exploited a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft as a zero-day for two weeks before any patch existed, breaching more than 100 organisations — 68% of them universities. CISA added CVE-2026-35273 to its KEV catalog on 12 June 2026.
ShinyHunters Publishes 234 GB of DentaQuest Healthcare Data After Ransom Talks Fail
The ShinyHunters extortion group has published 234 GB of data stolen from DentaQuest, a dental benefits administrator serving 32 million Americans. The leaked dataset includes healthcare enrollment records, Medicaid IDs, and personal information for an estimated 2.6 million individuals.
ShinyHunters Publishes Charter Communications Customer Data After Vishing Compromise
ShinyHunters extortion group has published data from Charter Communications after a vishing attack compromised a Microsoft Entra account and enabled access to Charter's Salesforce environment. At least 4.9 million customer records confirmed; the group claims 42 million.