Active Threat: On June 18, 2026, ShinyHunters announced a major expansion of its leak infrastructure — adding mirrors, torrent networks, and a permanent hosting pledge. This is not a hypothetical risk. Over 109 confirmed victims across 14 countries in the last 12 months alone.

What Happened
They’ve been active since 2019. They’ve survived arrests, FBI takedowns, forum seizures, and the conviction of their own founder. And on June 18, 2026, the ShinyHunters cybercrime group made their boldest move yet: announcing a sweeping expansion of their leak infrastructure, promising that every file of stolen data they hold will remain online permanently — “until the end of time.”
In a fresh post on their Tor-hosted leak site, ShinyHunters announced the completion of new infrastructure upgrades — multiple mirror servers, torrent distribution networks with Proof-of-Work download queues, and a streamlined access system designed to survive any future law enforcement takedown attempts. The announcement coincided with a new research report from Cato Networks describing ShinyHunters as “a cybercrime brand that adapts faster than defenders and law enforcement can respond.”

Who Is ShinyHunters?
ShinyHunters is an English-speaking, financially motivated cybercrime group believed to be affiliated with The Com — a loose international network of young cybercriminals. Their name is derived from the Pokémon franchise, referencing the practice of hunting rare “shiny” variants of Pokémon.
What began as a data theft and dark web forum operation has evolved into a sophisticated criminal brand capable of outlasting takedowns, replacing arrested members, and continuously adapting its attack infrastructure. Despite the 2023 conviction of alleged founder Sébastien Raoult and multiple forum seizures (RaidForums, BreachForums), the group has continued operations without meaningful disruption.
How They Operate: The “Pay or Leak” Playbook
Unlike traditional ransomware groups, ShinyHunters does not encrypt files or lock systems. Their model is purely data-based extortion:
- Breach an organization and exfiltrate sensitive data
- Post a victim entry on their Tor leak site with a sample of stolen data as proof
- Set a short ransom deadline — typically 72 hours to two weeks
- If the victim pays: they claim data deletion (unverifiable)
- If the victim doesn’t pay: everything is published publicly and permanently
Important: Instructure (Canvas) paid ShinyHunters’ ransom in May 2026 and received a claimed confirmation of data deletion. Whether the data was actually destroyed — or had already been distributed across multiple infrastructure nodes — cannot be independently verified. The FBI advises strongly against paying.
How They Get In: Attack Methods
ShinyHunters uses a repeatable, multi-stage attack pattern across campaigns. Understanding their methods is the first step to blocking them.
ShinyHunters’ most effective entry method is vishing (voice phishing) — calling employees and impersonating IT staff to steal MFA codes and SSO credentials in real time.
Primary Attack Vectors
- Vishing (Voice Phishing): Operators call employees, impersonate IT support, direct them to a fake company SSO login page, capture credentials and live MFA codes, then enroll their own MFA device for persistent access
- OAuth & Token Abuse: Stolen authentication tokens (from third-party services like Anodot, Drift/Salesloft, Gainsight) are used to access downstream Salesforce, Snowflake, and BigQuery environments without credentials
- Zero-Day Exploitation: Exploited CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft’s Environment Management Hub — unauthenticated remote code execution — to breach over 100 organizations, mostly universities
- Supply Chain & SaaS Pivoting: Compromising one vendor or integration platform to access dozens or hundreds of downstream customers simultaneously
- Credential Harvesting Domains: Creating fake login pages mimicking company SSO portals to capture credentials at scale
2026 Attack Timeline: Who Got Hit
ShinyHunters uses a repeatable, multi-stage attack pattern across campaigns. Understanding their methods is the first step to blocking them.
ShinyHunters’ most effective entry method is vishing (voice phishing) — calling employees and impersonating IT staff to steal MFA codes and SSO credentials in real time.
Primary Attack Vectors
- Vishing (Voice Phishing): Operators call employees, impersonate IT support, direct them to a fake company SSO login page, capture credentials and live MFA codes, then enroll their own MFA device for persistent access
- OAuth & Token Abuse: Stolen authentication tokens (from third-party services like Anodot, Drift/Salesloft, Gainsight) are used to access downstream Salesforce, Snowflake, and BigQuery environments without credentials
- Zero-Day Exploitation: Exploited CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft’s Environment Management Hub — unauthenticated remote code execution — to breach over 100 organizations, mostly universities
- Supply Chain & SaaS Pivoting: Compromising one vendor or integration platform to access dozens or hundreds of downstream customers simultaneously
- Credential Harvesting Domains: Creating fake login pages mimicking company SSO portals to capture credentials at scale
2026 Attack Timeline: Who Got Hit
JANUARY 2026
Grubhub & Panera Bread
Grubhub breach linked to ShinyHunters; Panera Bread hit affecting ~5 million people via Microsoft Entra SSO exploitation.
FEBRUARY 2026
Wynn Resorts, Odido, Figure Technology
Wynn Resorts: 800,000+ customer and employee records. Odido: 6 million people affected (21 million records). Figure: 1 million records. All part of ShinyHunters’ Okta SSO campaign.
MARCH 2026
European Commission + Telus Corp
350GB leaked from the EU Commission affecting 42 internal clients. Telus: over 1 petabyte claimed, $65M ransom demanded, impacting dozens of companies including call records, FBI background checks, and Salesforce data.
APRIL–MAY 2026
Canvas LMS (Instructure) + ADT
Canvas: 275 million users at 8,809 institutions affected (3.65TB). Instructure paid the ransom by May 12. ADT: 5.5 million personal records stolen via a compromised Okta employee account.
MAY–JUNE 2026
DentaQuest + Oracle PeopleSoft Campaign
DentaQuest: 234GB published affecting 2.6 million dental Medicaid patients. 100+ organizations breached via Oracle PeopleSoft zero-day (CVSS 9.8), two-thirds of them universities.
JUNE 2026
Kodak + Council of Europe + Madison Square Garden
Kodak: 2.2M records; Council of Europe: 297GB including payroll, salaries, medical records, and bank details for 10,000+ staff since 2011. MSG: 45GB published including 26 million records with facial recognition surveillance data after missed June 15 ransom deadline — federal class action filed the following day.
JUNE 18, 2026
🔴 Infrastructure Expansion Announced
ShinyHunters announces mirrors, torrent distribution, and permanent hosting pledge. All leaked data — past and future — will remain online indefinitely.
Confirmed Major Victims: At a Glance
| Organization | Sector | Records / Data | Status |
| Canvas LMS (Instructure) | Education | 275M users, 3.65TB | Paid ransom |
| European Commission | Government | 350GB, 42 clients | Data leaked |
| Telus Corporation | Telecom | 1+ petabyte claimed | $65M ransom pending |
| Council of Europe | Government | 297GB, 10,000+ staff | Data leaked |
| Madison Square Garden | Entertainment | 45GB, 26M records | Leaked + class action |
| DentaQuest | Healthcare | 234GB, 2.6M patients | Data leaked |
| ADT | Home Security | 5.5M records | Data leaked |
| Kodak | Imaging | 2.2M records | Deadline passed |
| Panera Bread | Food / Retail | 5M people, 14M records | Data leaked |
| Wynn Resorts | Hospitality | 800,000+ records | Data leaked |
| 100+ Universities | Education | Via Oracle PeopleSoft CVE | Actively breached |
Is There a Resolution? What’s Been Done
Law enforcement has taken action — but ShinyHunters’ resilience has made each intervention temporary at best.
Law Enforcement Actions
- Sébastien Raoult convicted (2023): The alleged French founder was arrested in Morocco, extradited to the US, and convicted — but the group continued operating with new leadership
- RaidForums & BreachForums seized: Multiple forum takedowns disrupted their leak infrastructure, but ShinyHunters re-emerged on new platforms each time
- CISA KEV additions: CISA added the Oracle PeopleSoft zero-day (CVE-2026-35273) to its Known Exploited Vulnerabilities catalog on June 12, ordering federal agencies to apply mitigations by June 15
- Oracle patch: Oracle has published mitigations, but no full patch has been confirmed as of publication. PeopleSoft environments with the Environment Management Hub internet-accessible remain at risk
The hard truth: Despite multiple arrests and forum seizures, ShinyHunters has never been meaningfully disrupted for more than a few weeks. Their June 18, 2026 infrastructure expansion is a direct response to law enforcement pressure — designed to make future takedowns irrelevant.
What Your Organization Should Do Now
These aren’t future precautions — they’re immediate priorities given ShinyHunters’ confirmed active campaigns against organizations of every size and sector.
Deploy Phishing-Resistant MFA Immediately
ShinyHunters’ primary entry method is real-time MFA interception via vishing. Standard SMS-based or TOTP codes can be captured live during a call. Switch to hardware security keys (FIDO2/WebAuthn) or passkey-based authentication that cannot be intercepted over the phone.
Train Staff to Verify Unexpected IT Requests
Every employee who has access to company systems is a potential target. Establish a call-back verification protocol: if IT calls asking for credentials, employees hang up and call back on a known internal number. No legitimate IT team will object to this.
Audit and Restrict Third-Party OAuth Integrations
ShinyHunters has repeatedly used stolen OAuth tokens from third-party services (Anodot, Drift, Gainsight, Salesforce integrations) to pivot into primary environments. Audit every connected app, revoke unused tokens, and apply least-privilege access to all integrations.
Patch Oracle PeopleSoft Immediately
If your organization runs Oracle PeopleSoft PeopleTools 8.61 or 8.62 with the Environment Management Hub accessible from outside your network perimeter, apply Oracle’s published mitigations now. CISA has ordered federal agencies to act — private sector organizations should treat this with the same urgency.
Monitor for Credential Harvesting Domains
ShinyHunters creates fake SSO login pages mimicking their targets. Set up monitoring for newly registered domains that contain your organization’s name or brand (e.g., yourcompany-sso.com). Services like DNS twist or commercial brand monitoring tools can flag these automatically.
Have a Breach Response Plan Ready Before You Need It
ShinyHunters’ 72-hour deadlines are designed to prevent clear thinking. Organizations without a pre-established incident response plan make panicked decisions — including paying ransoms that don’t guarantee data deletion. Your plan should include legal counsel, a PR/communications team, law enforcement contacts (FBI), and a technical forensics partner.
Additional Technical Hardening
- Implement Zero Trust architecture — treat every access request as untrusted, even from inside your network
- Segment your network so data exfiltration from one system can’t drain your entire environment
- Deploy Data Loss Prevention (DLP) tools on SaaS platforms to detect and block large-scale data exports
- Enable Conditional Access policies in Okta, Azure AD, or your IdP — block login attempts from unfamiliar devices or locations
- Check HaveIBeenPwned regularly — breached credentials often appear there before organizations are aware






