Topic · 15 stories
ShinyHunters: hacker group, breaches and news
In short
ShinyHunters is a cybercrime group that steals large corporate and government databases and demands payment to keep them private, then leaks the files if the deadline passes. In 2026 it claimed attacks on the FBI, McKesson, the Council of Europe and Florida's driver database. Two suspected members were detained, one in the Netherlands on September 15 and one in Jordan, reported in October, yet the group keeps announcing new victims.
What is ShinyHunters
ShinyHunters is a cybercriminal extortion group that steals large databases from companies and institutions and demands payment to keep them private. It runs a pay-or-leak model: instead of encrypting systems like typical ransomware, it threatens to publish the stolen files on its own dark-web site and does so when the deadline passes. TechTimes describes it as a cybercrime brand that has survived arrests and infrastructure seizures and says it has claimed over 40 breaches in 2026 alone. Experts describe the people behind it as mainly young, English-speaking hackers focused on data theft and extortion.
One caveat applies to everything below: many figures come from the group itself, and victims often do not confirm them. Where it matters, the group’s claims are kept apart from what companies and law enforcement have confirmed.
Which companies has ShinyHunters attacked
In 2026 ShinyHunters claimed attacks on the FBI, Florida’s driver database, McKesson, Carhartt, RingCentral, the Council of Europe and Madison Square Garden Sports. The main cases:
| Victim | What leaked | Scale | Date and status |
|---|---|---|---|
| FBI job applicant portal breach | employee and applicant data: Social Security numbers, emergency contacts, home addresses | group claims 2-3 TB; FBI assumes data on all employees was stolen | September 2026, FBI notifying those affected |
| Florida DMV driver database leak | DAVID driving records, passports, permanent resident cards, visas | 594,701 files (475,207 images, 119,494 HTML records); group claims over 200,000 records | access from September 3, leaked September 14 |
| McKesson confirms breach | patient records | group claims 284 million records; company has not confirmed | discovered August 25, 2026 |
| Carhartt: 12.9M accounts reportedly affected | names, emails, phone numbers, addresses of customers and employees | group claims over 50 GB; reports say 12.9M accounts; not confirmed | about August 13, 2026 |
| RingCentral loses 1.6M records | names, emails, addresses, phone numbers, no passwords | 1.6 million records, 623 GB claimed | disclosed July 28, leaked August 3 |
| Council of Europe: 297 GB of employee data | payslips, CVs, personnel files, bank and medical records over 15 years | 297 GB, 10,000 employees | intrusion May 27-June 9, leaked after June 16 deadline |
| Madison Square Garden Sports leak after missed deadline | customer emails, internal “Talent” files on famous people | 45 GB published; group claims over 26 million records | ransom deadline June 15, 2026 |
The group’s leak site also listed Ernst & Young, Abbott-owned Exact Sciences and Brinks Home in August. It is unclear whether the EY entry refers to the breach of that firm’s support ticketing system disclosed earlier. Reports also tie the group to earlier attacks on Ticketmaster and Rockstar Games, and it has claimed breaches at PornHub and Vimeo.
The consequences are concrete. In the FBI case, public home addresses could endanger agents’ families. The Council of Europe has not announced a plan to notify affected people or offer credit monitoring. The MSG files include home addresses and internal risk ratings of public figures, and MSG uses facial recognition at its venues.
How does ShinyHunters hack companies
ShinyHunters mainly gets in through flaws in enterprise software, phished logins and stolen credentials rather than by encrypting systems. Four patterns appear in the reports.
Oracle PeopleSoft flaws. Mass attacks on Oracle PeopleSoft servers reached 300 instances at over 100 organizations, mostly in education; the University of Nottingham confirmed an incident. The attackers chain old flaws with zero-day exploits, meaning flaws unknown to the vendor that have no patch when the attack starts. The Council of Europe intrusion used CVE-2026-35273 (CVSS 9.8), which needs no authentication and affects PeopleTools 8.61 or 8.62 with an externally reachable Environment Management Hub. CISA added it to its known exploited vulnerabilities catalog on June 12.
Passkey-themed phishing. Microsoft warned about passkey phishing and Microsoft 365 data theft: since May 2026 attackers have called or messaged staff posing as IT help desks and urged them to update a passkey, MFA or SSO setup. The victim lands on a fake login page or is tricked into approving access with a device code. Attackers do not register a passkey. They capture the sign-in and session tokens, then copy files from SharePoint, OneDrive and mail slowly, over hours or days. Microsoft links part of this activity to Storm-3121, tied to ShinyHunters. The technique is covered in the phishing topic.
A phone call to an employee. A ShinyHunters spokesperson said it broke into RingCentral by voice-phishing a member of staff, with no exploit and no unpatched flaw. RingCentral called it a sophisticated social engineering campaign.
Stolen credentials. Florida confirms DMV breach via stolen police credentials: the department says the attacker used one Plant City police user’s credentials stored on a personal device. The group claims a password reset flaw gave it access to many DAVID accounts, including an FBI agent’s. Neither version has been independently verified. More context in driver’s license data leaks and government data breaches.
Have ShinyHunters members been arrested
Yes: two suspected members have been detained, but the group keeps announcing attacks. Dutch police arrested a suspected leader on September 15, a 24-year-old from Amsterdam. Krebs on Security and Reuters identified him as Pepijn van der Stap, convicted in 2023 of data theft and extortion. FBI Cyber Division Assistant Director Brett Leatherman called the suspect one of the group’s alleged leaders. ShinyHunters told Reuters he has no association with it.
The second case is Saif al-Din Khader, alias Rey, detained in Jordan. Three people familiar with the matter said he was taken into custody, two of them on Tuesday, and that he is cooperating with the FBI to identify fellow hackers. The circumstances of the detention are unknown. The FBI does not comment on specific arrests abroad but says it has already worked with partners to arrest multiple subjects. More such cases are in the cybercrime arrests topic.
Why did ShinyHunters attack the FBI and Cl0p
ShinyHunters says its FBI attack was retaliation for a May 2026 FBI FLASH report on its tactics, and in September it also took over the leak site of the Cl0p group. The group’s account of the FBI breach, as reported by BleepingComputer: entry through an unpatched Oracle PeopleSoft zero-day, then lateral movement into FBI-managed AWS GovCloud. The FBI confirmed only that it is investigating unauthorized activity affecting FBIjobs.gov. 404 Media received roughly 5,000 purported employee records and verified some details. A week later the FBI was still assessing damage and assuming data on all employees was stolen, while the group demanded the FBI amend its advisory about the group’s extortion tactics, which many read as a threat to leak.
Earlier, on the night of September 18, ShinyHunters defaced Cl0p’s leak site on Tor with Pokemon artwork and a message that the site had been pwned. The group says it entered through an unauthenticated file-upload flaw in Grav, the CMS behind the site, and took Cl0p’s source code, plugins and logs. It also claims Cl0p’s onion service keys, which analysts call unproven, and set a 72-hour ultimatum. Cl0p has not commented. The report says the feud appears to date to October 2025.
What it means for you
- A call, text or message from an “IT help desk” urging an urgent passkey, MFA or SSO update matches the scenario Microsoft described in campaigns by groups linked to ShinyHunters. Do not follow the link; open your company’s sign-in portal yourself.
- For Microsoft 365 admins, Microsoft recommends phishing-resistant MFA, restricting sensitive cloud resources to managed devices and disabling device-code authentication when it is not needed.
- Organizations with Oracle PeopleSoft reachable from the internet should check logs for the indicators of compromise published with the June campaign (IP addresses, a script that drops ransom notes).
- If you receive a breach notice, monitor bank statements and credit reports, keep the incident paperwork and consider a fraud alert.
Still open: whether McKesson and Carhartt will confirm the figures the group claims (284 million records and 12.9 million accounts), how far the FBI data theft reached, and whether the arrests in the Netherlands and Jordan will slow a group that keeps announcing attacks.
Key facts
- Saif al-Din Khader, alias Rey, a suspected key ShinyHunters member, was detained in Jordan. Two sources say he is cooperating with the FBI to identify other members. (source)
- Dutch police arrested a 24-year-old Amsterdam man on September 15. The FBI called him one of the group's alleged leaders; ShinyHunters says he has no association with it. (source)
- The group claims it stole 2TB to 3TB from FBI systems via an Oracle PeopleSoft zero-day. The FBI confirmed it is investigating unauthorized activity affecting FBIjobs.gov. (source)
- ShinyHunters defaced the Tor leak site of the Cl0p group and issued a 72-hour ultimatum. It claims Cl0p's source code and onion keys; analysts call the keys unproven. (source)
- After a failed ransom negotiation, the group leaked 594,701 files from Florida's DAVID driver database: 475,207 images and 119,494 HTML driving records. (source)
- McKesson confirmed a breach discovered on August 25. ShinyHunters claims 284 million patient records; the company has not confirmed that figure. (source)
- The group published 297 GB of Council of Europe data, including payslips of 10,000 employees, after a June 16 ransom deadline passed. Entry came via Oracle PeopleSoft flaw CVE-2026-35273. (source)
- ShinyHunters is attacking Oracle PeopleSoft servers: 300 instances at over 100 organizations, mostly in education. The University of Nottingham confirmed an incident. (source)
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- Alleged ShinyHunters Member Detained in Jordan, Cooperating With FBI Privacy
- Dutch police arrest 24-year-old suspected ShinyHunters leader Security
- FBI still assessing ShinyHunters breach of job applicant portal Security
- ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day Security
- ShinyHunters defaces Cl0p ransomware leak site Security
- ShinyHunters Leaks 594,701 Files After Florida DMV Hack Security
- Florida Confirms DMV Database Breach via Stolen Police Credentials Privacy
- Passkey-themed phishing campaign hits Microsoft 365 and steals corporate data Security
- Carhartt Data Breach: ShinyHunters Claims 50GB Stolen, 12.9M Accounts Affected Privacy
- McKesson Confirms Breach After ShinyHunters Claims 284M Patient Records Stolen Security
Show older (5 stories)
- RingCentral Loses 1.6 Million Records in Social Engineering Attack Security
- Council of Europe Data Breach: ShinyHunters Publishes 297 GB of Employee Records Privacy
- ShinyHunters Publishes 297GB of Council of Europe Data After Ransom Deadline Missed Security
- ShinyHunters Publishes 45 GB of Data from MSG Sports After Ransom Deadline Missed Security
- ShinyHunters Targets Oracle PeopleSoft Servers, Steals Data from Over 100 Organizations Security
FAQ
What is ShinyHunters?
ShinyHunters is a cybercriminal extortion group known for stealing large databases and leaking them when victims do not pay. It runs a pay-or-leak model without encrypting systems, unlike classic ransomware. In 2026 it claimed attacks on the FBI, McKesson, the Council of Europe and the Florida DMV.
Who are ShinyHunters?
Experts describe ShinyHunters as mainly young, English-speaking hackers focused on data theft and extortion. TechTimes describes it as a brand that has survived arrests and infrastructure seizures, with more than 40 breaches claimed in 2026 alone. Two suspected members have been detained: one in the Netherlands on September 15 and one in Jordan, reported in October.
Who is ShinyHunters hackers?
No single person is ShinyHunters: it is a group, and most members are unnamed. Press reports name two suspects, Pepijn van der Stap in the Netherlands (the group denies he is a member) and Saif al-Din Khader, alias Rey, in Jordan. Both are suspects, not convicted members.
How does ShinyHunters hack companies?
Mostly through enterprise software flaws and stolen logins. In 2026 it hit Oracle PeopleSoft servers (CVE-2026-35273, CVSS 9.8), and Microsoft described passkey-themed phishing by groups linked to it, in which attackers pose as IT help desks. A ShinyHunters spokesperson said it broke into RingCentral by voice-phishing an employee, and Florida blamed credentials of one police user.
Which companies has ShinyHunters attacked?
In 2026 the group claimed attacks on the FBI, McKesson, Carhartt, RingCentral, the Council of Europe, Madison Square Garden Sports and the Florida DMV. Reports also tie it to earlier attacks on Ticketmaster and Rockstar Games. Many figures come from the group itself and are not confirmed by victims.