ShinyHunters is a financially motivated cybercrime and data-extortion threat actor best known for large-scale theft of customer and enterprise data, subsequent extortion, and publication of stolen datasets on leak infrastructure. The group is widely associated with credential abuse, identity compromise, social engineering, and SaaS-focused intrusions rather than classic encryption-first ransomware operations. Reported aliases and tracking names include BLING_LIBRA, UNC6040, and UNC6240; some reporting also references claimed or possible false-flag use of the ShinyHunters name in ransom communications. ShinyHunters has been linked to intrusions affecting technology, healthcare, insurance, and other enterprise sectors, including incidents involving cloud identity providers, Microsoft 365 environments, SharePoint, Salesforce-related data, and other SaaS platforms. Recent activity indicates a strong emphasis on compromising the identity layer—especially single sign-on environments such as Microsoft Entra, Okta, and Google-based authentication ecosystems—and then pivoting into connected business applications for rapid data discovery and exfiltration. Observed and reported tradecraft includes voice phishing and other social-engineering techniques to induce helpdesk-assisted password resets, MFA resets, or device re-enrollment; abuse of weak recovery workflows; SIM-swapping-associated tactics; takeover of federated identity accounts; and theft of data from cloud storage and collaboration platforms. The actor’s operations are frequently characterized as extortion-by-exfiltration: obtaining access, stealing high-value data quickly, and using publication threats as leverage. In some cases, the group has also been associated with abuse of OAuth or other SaaS trust relationships. ShinyHunters has publicly claimed responsibility for multiple high-profile breaches and has been tied to leak-site publication of stolen data. In several incidents, however, public claims by the group exceeded what was independently verified, and some datasets attributed to ShinyHunters may have been independently obtained, purchased, or opportunistically republished by other actors. The group’s name has also been reused by unrelated criminals in secondary fraud and sextortion campaigns that leveraged previously leaked breach data to make false compromise claims appear credible. The actor has been associated with campaigns against healthcare and health-adjacent organizations, where reporting indicates a pattern of vishing-led compromise of enterprise identity systems followed by access to connected SaaS platforms and theft of sensitive records. Similar tactics have been described in incidents involving large enterprises where the group claimed compromise of Microsoft Entra single sign-on environments and subsequent exfiltration from Microsoft 365, SharePoint, and related services. ShinyHunters has also appeared in the broader cybercrime ecosystem as a downstream extortion and leak actor in incidents where another threat group conducted the initial intrusion or supply-chain compromise. In such cases, ShinyHunters has been observed publishing or claiming stolen datasets after the original theft, underscoring its role not only as an intrusion actor but also as a monetizer and amplifier of stolen data within criminal markets. The group is not a nation-state actor. It is best understood as a cybercriminal extortion operation centered on identity compromise, cloud and SaaS access, data theft, and public-pressure extortion, with a reputation for high-visibility claims and aggressive use of stolen information for coercion and monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
CVE-2026-35273 (Oracle PeopleSoft PeopleTools) : accès HTTP non authentifié, lié à ShinyHunters
Oracle E-Business Suite was the target of a large scale Cl0p ransomware campaign just months ago via CVE-2025-61882... A critical zero day in Oracle EBS Concurrent Processing, exploited by the Cl0p ransomware gang...
threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
According to data obtained from a public Telegram channel operated by the ShinyHunters team, the threat actor persona ‘Yukari’ exploited an Oracle Access Manager vulnerability (CVE-2021-35587). The attack targeted financial institutions and manufacturers.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware/data extortion attack against Ernst & Young and threatening to leak stolen data unless contact is made by 31 July 2026.
Conducting a ransomware/data extortion attack against RingCentral, claiming compromised data and threatening to leak it unless contact is made by 30 July 2026.
Claimed responsibility for the DentaQuest breach, allegedly stole 234 GB of data, and used extortion by publishing the data on a dark web leak site after ransom negotiations failed.
Claimed responsibility for the Medtronic corporate IT breach and alleged theft of millions of records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.