Skip to main content
Mallory
Back to intelligence
underground-data-leakransomware-group-operationmass-credential-exposurehealthcare-sector-threat

ShinyHunters Publishes Stolen Data From Bumble, Match Group, and Dozens of Firms

Updated 4d agoFirst seen May 1, 202628 sources

ShinyHunters has published a broad trove of allegedly stolen data affecting more than 40 organizations across retail, healthcare, hospitality, insurance, and consumer services, with reporting tying the leak campaign to victims including Bumble, Match Group, Mytheresa, Zara, Carnival, and 7-Eleven. Researchers said the exposed material includes personally identifiable information, customer and transaction records, internal corporate files, and multi-terabyte datasets; one of the largest alleged exposures involved Medtronic, where roughly 9 million records were reportedly listed before that entry was later removed from the leak site.

The campaign reflects ShinyHunters' continued shift from ransomware-style encryption to data theft and extortion, with the group allegedly threatening to keep victim data available indefinitely on criminal platforms. Separate reports said the actors claimed to have stolen about 10 million records from dating-app companies, while researchers also linked leaked Bumble data to the same operation after an earlier claim that roughly 30GB had been taken from the company. The disclosures echo a wider criminal pattern in which stolen sensitive data is leaked to pressure victims after exfiltration, including in healthcare breaches such as the Change Healthcare incident.

Share:
ShinyHunters Publishes Stolen Data From Bumble, Match Group, and Dozens of Firms
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

25 events from the most recent confirmed update back to the earliest known activity.

25 EVENTS
Jun 1, 20264d ago

DentaQuest linked to ShinyHunters after alleged 233GB data drop

A Troy Hunt weekly update cited DentaQuest as an example in the ongoing ShinyHunters campaign, stating that an alleged 233GB dataset from the organization was dropped shortly after it was mentioned. This adds DentaQuest as a newly disclosed victim in the group's 2026 data-theft and extortion activity.

Troy Hunt: Weekly Update 506
May 21, 202615d ago

ShinyHunters claims theft of 14 million Panera Bread records

Daily Dark Web reported that ShinyHunters claimed to have stolen 14 million records from Panera Bread. This adds Panera Bread as a newly disclosed victim in the broader ShinyHunters data-theft and extortion campaign.

Panera Bread Data Breach: ShinyHunters Claims 14 Million Records Stolen - Daily Dark Web
Apr 23, 20261mo ago

ShinyHunters threatens indefinite exposure of stolen victim data

By late April 2026, reporting described ShinyHunters as shifting from file encryption to pure data theft and extortion, with threats to keep victim data available indefinitely on underground platforms. The campaign was said to expose millions of records and terabytes of stolen information.

Medtronic listing is removed from the ShinyHunters leak site

Later reporting said Medtronic, initially highlighted as a major victim with about nine million allegedly compromised records, was subsequently removed from the leak site. The removal suggested a possible ransom payment or ongoing negotiation, though this was not confirmed.

Apr 18, 20262mo ago

Inditex acknowledges Zara-related breach tied to former technology provider

Inditex said unauthorized access affected group databases in an incident tied to a former technology provider after Zara was named in ShinyHunters leak threats. The company said passwords, payment cards, and other payment methods were not exposed.

Zara, Carnival, 7-Eleven hit with ransomware threat​ | Cybernews
Apr 1, 20262mo ago

Mytheresa data leaked after ShinyHunters ransom deadline expires

In April 2026, Mytheresa was identified as a victim of the ShinyHunters extortion group in a pay-or-leak incident. After the ransom deadline passed, the group publicly released stolen data reportedly including 84,000 unique email addresses, customer contact and purchase details, and partial payment card information.

Have I Been Pwned: Mytheresa Data Breach
Mar 25, 20262mo ago

ShinyHunters threatens Ameriprise Financial with 200GB data leak

Cybernews reported that ShinyHunters threatened Ameriprise Financial and claimed to hold about 200GB of stolen data. The report adds Ameriprise as a newly disclosed victim in the group’s 2026 data-theft and extortion campaign.

Hackers threaten Ameriprise Financial with 200GB data leak​ | Cybernews
Mar 19, 20263mo ago

Aura confirms ShinyHunters breach affecting at least 900,000 people

Aura confirmed it was breached in an incident linked to ShinyHunters and said at least 900,000 individuals were impacted. The disclosure adds Aura as a newly identified victim in the group’s 2026 data-theft and extortion campaign.

Hacked: Aura confirms at least 900k impacted by ShinyHunters breach - Cyber Daily
Feb 27, 20263mo ago

Odido linked to ongoing ShinyHunters leak campaign

The Register reported that Dutch telecom provider Odido was affected as ShinyHunters leak activity continued, adding Odido as a newly disclosed victim in the broader 2026 publication wave. The report also indicated Dutch police were supporting the company in response to the incident.

Dutch cops back Odido as ShinyHunters leaks continue
Feb 20, 20263mo ago

ShinyHunters demands $1.5M over alleged Wynn Resorts data theft

The Register reported that ShinyHunters demanded $1.5 million from Wynn Resorts to prevent the leak of allegedly stolen data. The report adds Wynn Resorts as a newly disclosed victim in the group’s 2026 data-theft and extortion campaign.

ShinyHunters demands $1.5M not to leak Wynn Resorts data
Feb 14, 20264mo ago

Canada Goose says ShinyHunters leak came from older breach

Canada Goose said a Valentine's Day dataset attributed to ShinyHunters, reportedly containing more than 600,000 records, did not result from a new security incident at the company. The retailer said the leaked data appeared to stem from an older breach and that it was reviewing the dataset to verify its accuracy and scope.

Canada Goose downplays ShinyHunters data leak | brief | SC Media
Jan 29, 20264mo ago

ShinyHunters claims theft of 10 million dating-app records

The Register reported that ShinyHunters claimed it had stolen 10 million records from dating apps. This marked a public escalation in the group’s claims around consumer-platform data exposure.

Reports link Bumble data to ShinyHunters leak listings

Cybernews reported that Bumble-related data associated with the Hives group was found in ShinyHunters leak postings, warning that the company was among the exposed organizations. The reporting connected Bumble to the broader January 2026 publication wave.

ShinyHunters allegedly breaches Bumble and offers 30GB of data

A Daily Dark Web report said ShinyHunters allegedly breached Bumble Inc. and claimed to possess about 30GB of stolen data. This appears to be the earliest referenced event tied to the later Bumble-related reporting.

Jan 26, 20264mo ago

Additional victims are posted in the same ShinyHunters leak wave

Further leak-site postings continued during the same week after the first January 23 listing, expanding the scope of the campaign. Reported victims included major brands such as Mytheresa, Zara, Carnival, 7-Eleven, and Medtronic.

Jan 23, 20264mo ago

ShinyHunters begins publishing a new multi-victim data trove

According to later reporting, the earliest listing in a large ShinyHunters leak campaign appeared on January 23, 2026. The trove reportedly involved around 40 organizations across sectors including retail, insurance, and hospitality.

May 31, 20242y ago

ShinyHunters claims Santander breach and offers data on 30 million customers

BleepingComputer reported that ShinyHunters claimed to have breached Santander and was selling data allegedly tied to 30 million customers. This adds Santander as a newly disclosed victim in the group’s activity prior to the later 2025–2026 campaign entries.

ShinyHunters claims Santander breach, selling data for 30M customers
Jan 22, 20215y ago

Bonobos breach reported after 70GB database leak

BleepingComputer reported that clothing retailer Bonobos suffered a data breach and that a 70GB database was leaked by a hacker. The report adds Bonobos as another disclosed victim in the broader ShinyHunters-linked retail data exposure campaign.

Bonobos clothing store suffers a data breach, hacker leaks 70GB database
Jan 20, 20215y ago

ShinyHunters publishes 1.9 million stolen Pixlr user credentials

SiliconANGLE reported that ShinyHunters published 1.9 million stolen user credentials from photo editing site Pixlr. The report adds Pixlr as another disclosed victim in the group’s early multi-company data theft and exposure campaign.

ShinyHunters publishes 1.9M stolen user credentials from photo editing site Pixlr - SiliconANGLE
Nov 5, 20206y ago

ShinyHunters leaks 5.22GB Mashable database

Hackread reported that ShinyHunters leaked a 5.22GB database allegedly belonging to Mashable.com. The report identifies Mashable as another victim in the group’s 2020 multi-company data exposure campaign.

ShinyHunters hacker leaks 5.22GB worth of Mashable.com database
Jul 28, 20206y ago

ShinyHunters linked to leak of 386 million records from 18 companies

Security Affairs reported that ShinyHunters leaked more than 386 million user records stolen from 18 companies. The report documents an earlier large-scale multi-victim data exposure campaign attributed to the group, predating the later 2025–2026 incidents in the existing timeline.

ShinyHunters leaked over 386 million user records from 18 companies
May 29, 20206y ago

Minted confirms breach as ShinyHunters sell stolen database

Minted confirmed a data breach after ShinyHunters offered the company's database for sale. The incident identifies Minted as an additional victim in the group's 2020 data-theft campaign.

Minted confirms data breach as Shiny Hunters sell its database
May 11, 20206y ago

Zoosk dating profiles offered for sale by ShinyHunters

Graham Cluley reported that millions of Zoosk dating profiles were put up for sale by the hacking group ShinyHunters. The report identifies Zoosk as another victim in the group's early 2020 multi-company data theft and exposure campaign.

Hacking group puts millions of Zoosk dating profiles up for sale • Graham Cluley

TechRadar reports ShinyHunters leaking millions of user details

TechRadar reported that ShinyHunters was leaking millions of user details, documenting an early phase of the group's 2020 multi-victim data exposure activity. The report indicates the campaign was already affecting multiple organizations before later victim-specific disclosures such as Minted and Mashable.

ShinyHunters leak millions of user details | TechRadar
May 9, 20206y ago

ZDNet reports ShinyHunters selling 73 million user records

ZDNet reported that the hacker group ShinyHunters was selling more than 73 million user records on the dark web. The report marks an early public disclosure of the group’s 2020 multi-victim data theft and sale activity before later victim-specific reports such as Zoosk and Minted.

A hacker group is selling more than 73 million user records on the dark web | ZDNET
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.