Blog Details

A figure in a glowing mask with X eyes and a stitched mouth stands by text: “SHINYHUNTERS Is Back — And They're Promising Your Data Stays Online Forever.” Binary code, hacking icons, and data breach warnings fill the background.

ShinyHunters Is Back — And They’re Promising Your Data Stays Online Forever

Active Threat: On June 18, 2026, ShinyHunters announced a major expansion of its leak infrastructure — adding mirrors, torrent networks, and a permanent hosting pledge. This is not a hypothetical risk. Over 109 confirmed victims across 14 countries in the last 12 months alone.

Four statistic boxes show the impact of recent data breaches: 109+ confirmed victims in 12 months, 275M online data records stolen from Canvas LMS, 350GB leaked from European Commission, $65M ransom demanded from Telus Corp by ShinyHunters.

What Happened

They’ve been active since 2019. They’ve survived arrests, FBI takedowns, forum seizures, and the conviction of their own founder. And on June 18, 2026, the ShinyHunters cybercrime group made their boldest move yet: announcing a sweeping expansion of their leak infrastructure, promising that every file of stolen data they hold will remain online permanently — “until the end of time.”

In a fresh post on their Tor-hosted leak site, ShinyHunters announced the completion of new infrastructure upgrades — multiple mirror servers, torrent distribution networks with Proof-of-Work download queues, and a streamlined access system designed to survive any future law enforcement takedown attempts. The announcement coincided with a new research report from Cato Networks describing ShinyHunters as “a cybercrime brand that adapts faster than defenders and law enforcement can respond.”

A highlighted text box explains that for data breach victims, "permanent" means leaked info is online forever—court takedowns are less effective. Below, text notes cybercriminals like ShinyHunters now favor public exposure threats over ransomware.

Who Is ShinyHunters?

ShinyHunters is an English-speaking, financially motivated cybercrime group believed to be affiliated with The Com — a loose international network of young cybercriminals. Their name is derived from the Pokémon franchise, referencing the practice of hunting rare “shiny” variants of Pokémon.

What began as a data theft and dark web forum operation has evolved into a sophisticated criminal brand capable of outlasting takedowns, replacing arrested members, and continuously adapting its attack infrastructure. Despite the 2023 conviction of alleged founder Sébastien Raoult and multiple forum seizures (RaidForums, BreachForums), the group has continued operations without meaningful disruption.

How They Operate: The “Pay or Leak” Playbook

Unlike traditional ransomware groups, ShinyHunters does not encrypt files or lock systems. Their model is purely data-based extortion:

  • Breach an organization and exfiltrate sensitive data
  • Post a victim entry on their Tor leak site with a sample of stolen data as proof
  • Set a short ransom deadline — typically 72 hours to two weeks
  • If the victim pays: they claim data deletion (unverifiable)
  • If the victim doesn’t pay: everything is published publicly and permanently

Important: Instructure (Canvas) paid ShinyHunters’ ransom in May 2026 and received a claimed confirmation of data deletion. Whether the data was actually destroyed — or had already been distributed across multiple infrastructure nodes — cannot be independently verified. The FBI advises strongly against paying.

How They Get In: Attack Methods

ShinyHunters uses a repeatable, multi-stage attack pattern across campaigns. Understanding their methods is the first step to blocking them.

ShinyHunters’ most effective entry method is vishing (voice phishing) — calling employees and impersonating IT staff to steal MFA codes and SSO credentials in real time.

Primary Attack Vectors

  • Vishing (Voice Phishing): Operators call employees, impersonate IT support, direct them to a fake company SSO login page, capture credentials and live MFA codes, then enroll their own MFA device for persistent access
  • OAuth & Token Abuse: Stolen authentication tokens (from third-party services like Anodot, Drift/Salesloft, Gainsight) are used to access downstream Salesforce, Snowflake, and BigQuery environments without credentials
  • Zero-Day Exploitation: Exploited CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft’s Environment Management Hub — unauthenticated remote code execution — to breach over 100 organizations, mostly universities
  • Supply Chain & SaaS Pivoting: Compromising one vendor or integration platform to access dozens or hundreds of downstream customers simultaneously
  • Credential Harvesting Domains: Creating fake login pages mimicking company SSO portals to capture credentials at scale

2026 Attack Timeline: Who Got Hit

ShinyHunters uses a repeatable, multi-stage attack pattern across campaigns. Understanding their methods is the first step to blocking them.

ShinyHunters’ most effective entry method is vishing (voice phishing) — calling employees and impersonating IT staff to steal MFA codes and SSO credentials in real time.

Primary Attack Vectors

  • Vishing (Voice Phishing): Operators call employees, impersonate IT support, direct them to a fake company SSO login page, capture credentials and live MFA codes, then enroll their own MFA device for persistent access
  • OAuth & Token Abuse: Stolen authentication tokens (from third-party services like Anodot, Drift/Salesloft, Gainsight) are used to access downstream Salesforce, Snowflake, and BigQuery environments without credentials
  • Zero-Day Exploitation: Exploited CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft’s Environment Management Hub — unauthenticated remote code execution — to breach over 100 organizations, mostly universities
  • Supply Chain & SaaS Pivoting: Compromising one vendor or integration platform to access dozens or hundreds of downstream customers simultaneously
  • Credential Harvesting Domains: Creating fake login pages mimicking company SSO portals to capture credentials at scale


2026 Attack Timeline: Who Got Hit

JANUARY 2026
Grubhub & Panera Bread

Grubhub breach linked to ShinyHunters; Panera Bread hit affecting ~5 million people via Microsoft Entra SSO exploitation.

FEBRUARY 2026
Wynn Resorts, Odido, Figure Technology

Wynn Resorts: 800,000+ customer and employee records. Odido: 6 million people affected (21 million records). Figure: 1 million records. All part of ShinyHunters’ Okta SSO campaign.

MARCH 2026
European Commission + Telus Corp

350GB leaked from the EU Commission affecting 42 internal clients. Telus: over 1 petabyte claimed, $65M ransom demanded, impacting dozens of companies including call records, FBI background checks, and Salesforce data.

APRIL–MAY 2026
Canvas LMS (Instructure) + ADT

Canvas: 275 million users at 8,809 institutions affected (3.65TB). Instructure paid the ransom by May 12. ADT: 5.5 million personal records stolen via a compromised Okta employee account.

MAY–JUNE 2026
DentaQuest + Oracle PeopleSoft Campaign

DentaQuest: 234GB published affecting 2.6 million dental Medicaid patients. 100+ organizations breached via Oracle PeopleSoft zero-day (CVSS 9.8), two-thirds of them universities.

JUNE 2026
Kodak + Council of Europe + Madison Square Garden

Kodak: 2.2M records; Council of Europe: 297GB including payroll, salaries, medical records, and bank details for 10,000+ staff since 2011. MSG: 45GB published including 26 million records with facial recognition surveillance data after missed June 15 ransom deadline — federal class action filed the following day.

JUNE 18, 2026
🔴 Infrastructure Expansion Announced

ShinyHunters announces mirrors, torrent distribution, and permanent hosting pledge. All leaked data — past and future — will remain online indefinitely.

Confirmed Major Victims: At a Glance

OrganizationSectorRecords / DataStatus
Canvas LMS (Instructure)Education275M users, 3.65TBPaid ransom
European CommissionGovernment350GB, 42 clientsData leaked
Telus CorporationTelecom1+ petabyte claimed$65M ransom pending
Council of EuropeGovernment297GB, 10,000+ staffData leaked
Madison Square GardenEntertainment45GB, 26M recordsLeaked + class action
DentaQuestHealthcare234GB, 2.6M patientsData leaked
ADTHome Security5.5M recordsData leaked
KodakImaging2.2M recordsDeadline passed
Panera BreadFood / Retail5M people, 14M recordsData leaked
Wynn ResortsHospitality800,000+ recordsData leaked
100+ UniversitiesEducationVia Oracle PeopleSoft CVEActively breached

Is There a Resolution? What’s Been Done

Law enforcement has taken action — but ShinyHunters’ resilience has made each intervention temporary at best.

Law Enforcement Actions

  • Sébastien Raoult convicted (2023): The alleged French founder was arrested in Morocco, extradited to the US, and convicted — but the group continued operating with new leadership
  • RaidForums & BreachForums seized: Multiple forum takedowns disrupted their leak infrastructure, but ShinyHunters re-emerged on new platforms each time
  • CISA KEV additions: CISA added the Oracle PeopleSoft zero-day (CVE-2026-35273) to its Known Exploited Vulnerabilities catalog on June 12, ordering federal agencies to apply mitigations by June 15
  • Oracle patch: Oracle has published mitigations, but no full patch has been confirmed as of publication. PeopleSoft environments with the Environment Management Hub internet-accessible remain at risk

The hard truth: Despite multiple arrests and forum seizures, ShinyHunters has never been meaningfully disrupted for more than a few weeks. Their June 18, 2026 infrastructure expansion is a direct response to law enforcement pressure — designed to make future takedowns irrelevant.

What Your Organization Should Do Now

These aren’t future precautions — they’re immediate priorities given ShinyHunters’ confirmed active campaigns against organizations of every size and sector.

Deploy Phishing-Resistant MFA Immediately

ShinyHunters’ primary entry method is real-time MFA interception via vishing. Standard SMS-based or TOTP codes can be captured live during a call. Switch to hardware security keys (FIDO2/WebAuthn) or passkey-based authentication that cannot be intercepted over the phone.

Train Staff to Verify Unexpected IT Requests

Every employee who has access to company systems is a potential target. Establish a call-back verification protocol: if IT calls asking for credentials, employees hang up and call back on a known internal number. No legitimate IT team will object to this.

Audit and Restrict Third-Party OAuth Integrations

ShinyHunters has repeatedly used stolen OAuth tokens from third-party services (Anodot, Drift, Gainsight, Salesforce integrations) to pivot into primary environments. Audit every connected app, revoke unused tokens, and apply least-privilege access to all integrations.

Patch Oracle PeopleSoft Immediately

If your organization runs Oracle PeopleSoft PeopleTools 8.61 or 8.62 with the Environment Management Hub accessible from outside your network perimeter, apply Oracle’s published mitigations now. CISA has ordered federal agencies to act — private sector organizations should treat this with the same urgency.

Monitor for Credential Harvesting Domains

ShinyHunters creates fake SSO login pages mimicking their targets. Set up monitoring for newly registered domains that contain your organization’s name or brand (e.g., yourcompany-sso.com). Services like DNS twist or commercial brand monitoring tools can flag these automatically.

Have a Breach Response Plan Ready Before You Need It

ShinyHunters’ 72-hour deadlines are designed to prevent clear thinking. Organizations without a pre-established incident response plan make panicked decisions — including paying ransoms that don’t guarantee data deletion. Your plan should include legal counsel, a PR/communications team, law enforcement contacts (FBI), and a technical forensics partner.

Additional Technical Hardening

  • Implement Zero Trust architecture — treat every access request as untrusted, even from inside your network
  • Segment your network so data exfiltration from one system can’t drain your entire environment
  • Deploy Data Loss Prevention (DLP) tools on SaaS platforms to detect and block large-scale data exports
  • Enable Conditional Access policies in Okta, Azure AD, or your IdP — block login attempts from unfamiliar devices or locations
  • Check HaveIBeenPwned regularly — breached credentials often appear there before organizations are aware

A blue box titled "Executive Summary" summarizes information about the ShinyHunters cybercrime group, highlighting their history, online forever presence, recent attack, scale, and data leak methods in concise bullet points.
A section of text with bullet points about cybersecurity: one notes Oracle has issued mitigations but no patch; another suggests steps like deploying MFA, training on phishing, auditing third-party OAuth tokens to enhance online security and reduce data breach risks from groups like ShinyHunters.
A red box with a lock icon and bold text: "ShinyHunters doesn’t send warning shots. If they have your online data, the clock is already ticking." Below, smaller text explains how to protect organizations from a data breach.

Leave A Comment

At vero eos et accusamus et iusto odio digni goikussimos ducimus qui to bonfo blanditiis praese. Ntium voluum deleniti atque.

Melbourne, Australia
(Sat - Thursday)
(10am - 05 pm)