Report Traces ShinyHunters’ Six-Year Evolution and Changing Attack Tactics

· Original article ↗

Summary

Sekoia and Beazley trace ShinyHunters’ activity from 2020 to 2026, detailing its shifting access methods, decentralized identity, breach claims, law-enforcement actions and recent campaigns, including exploitation of a PeopleSoft zero-day.

Key points

  • The report describes ShinyHunters as a shifting cybercrime brand used by multiple clusters, rather than a single stable group; it cautions that breach claims and attribution often need independent verification.
  • Access tactics evolved from exposed credentials, GitHub tokens and misconfigured S3 buckets to MFA-less Snowflake accounts, vishing, OAuth abuse and SaaS supply-chain token theft.
  • The report links the 2026 PeopleSoft campaign to CVE-2026-35273, a critical remote-code-execution flaw exploited before Oracle’s June 10 advisory; Google identified more than 100 exposed organizations, about 68% in higher education.
  • Incident-response findings from a PeopleSoft compromise describe JSP backdoors, MeshAgent, Chisel, Rclone, scheduled PowerShell tasks and attempts to disable CrowdStrike protections.
  • The report highlights recurring MFA and cloud-configuration weaknesses, while noting that attackers’ claimed breach figures can exceed victims’ confirmed impact.
  • It includes Sekoia detection queries and incident-response indicators for the PeopleSoft campaign, including suspicious files, a domain and an IP address.

Article Details

Publisher
Sekoia and Beazley Security
Report Period
2020–2026; activity covered through early September 2026
Scope
ShinyHunters' organizational evolution, access methods, breaches, extortion, and a 2026 Oracle PeopleSoft compromise investigated by Beazley Security.
Key Statistics
  • Mandiant reported that up to 165 Snowflake customer organizations were potentially exposed in the 2024 campaign; the report says Snowflake's platform itself was not breached.
  • In the 2025 Salesloft Drift campaign, stolen OAuth tokens were used to export Salesforce data from more than 700 organizations. ShinyHunters claimed the figure was closer to 760.
  • Google identified more than 100 exposed organizations in the 2026 Oracle PeopleSoft campaign; roughly 68% of affected organizations were in higher education.
  • For the 2023 Pizza Hut Australia incident, ShinyHunters claimed more than one million customers and 30 million order records, while the company scoped the impact to roughly 193,000 customers.
Recommendations
  • Hunt for connections to azurenetfiles.net and 142.11.200.186 using the report's detection queries.
  • Hunt for creation of the MeshFwFix scheduled task and execution of cs_disable.cmd.
  • Hunt for the modified MeshAgent binary at C:\Windows\Temp\ma.exe and creation of the JSP backdoors orau.jsp and webpack.jsp.

Indicators of compromise

TypeIndicatorContext
DOMAINazurenetfiles[.]netMalicious domain in a detection query for the Oracle PeopleSoft incident; the report describes a C2 domain mimicking Azure infrastructure.
DOMAINbreachforums[.]hnNewly registered domain hosting a purported SLSH goodbye letter that Resecurity flagged as likely disinformation.
DOMAINbreachforums[.]stBreachForums domain ShinyHunters reportedly regained and used to redirect users after a forum seizure.
DOMAINraid[.]lolSeized domain of RaidForums, the illicit marketplace used for ShinyHunters' stolen-data sales and leaks.
DOMAINraidforums[.]comSeized domain of RaidForums, the illicit marketplace used for ShinyHunters' stolen-data sales and leaks.
DOMAINrf[.]wsSeized domain of RaidForums, the illicit marketplace used for ShinyHunters' stolen-data sales and leaks.
IPV4142[.]11[.]200[.]186Malicious remote IP identified in a detection query for the Oracle PeopleSoft incident.
SHA256a4e525d8825c1bac6dd934ef2c008b5fb9988289190b5b98d854799e07e207e4SHA-256 of webpack.js, listed among indicators collected during Beazley Security's Oracle PeopleSoft incident response.

MITRE ATT&CK

CVE

Threat Actors

Dark StormGroup whose DDoS attack was suggested as one possible explanation for a BreachForums outage; the cause remains unsettled.GnosticPlayersEarlier hacking collective linked to ShinyHunters through researcher-attributed personnel overlap; individuals involved disputed ShinyHunters membership.HellcatActor whom ShinyHunters alleged, in an interview cited by the report, was behind SLSH; this is a disputed third-party claim.LAPSUS$Group described as part of the broader ecosystem and the reported Scattered Lapsus$ Hunters merger.QilinRansomware group whose possible retaliation was suggested as an explanation for a BreachForums outage; the cause remains unsettled.Scattered Lapsus$ HuntersName the report also uses for the purported Scattered Lapsus$ Hunters collective.Scattered SpiderGroup described as part of the broader ecosystem; the report says it is separately tracked as UNC3944.ShinyHuntersData-theft and extortion brand active since 2020; the report cautions that distinct clusters have operated under its name.SLSHAbbreviation explicitly used for Scattered Lapsus$ Hunters; the report notes disputed accounts of its membership.Sp1d3rPersona associated in reporting with extortion during the Snowflake campaign.Sp1d3rHuntersPersona the report describes as overlapping with the Snowflake campaign's ShinyHunters branding.SpidermanDataPersona that advertised alleged Ticketmaster records during the Snowflake campaign.The ComBroader cybercrime community to which the report assesses a high-confidence ShinyHunters link.TheDarkOverlordEarlier extortion collective that researchers connect to ShinyHunters' lineage through reported personnel continuity.UNC5537Mandiant's designation for the 2024 Snowflake intrusions; the report distinguishes their operators from ShinyHunters' historic core.UNC6040Google-tracked cluster associated with the 2025 Salesforce vishing intrusions.UNC6240Google-tracked extortion arm that the report says consistently claims to be ShinyHunters.UNC6395Google-tracked Salesloft Drift campaign cluster; Google did not attribute it to ShinyHunters.UNC6661Google-tracked cluster associated with 2026 SSO and vishing intrusions.UNC6671Google-tracked vishing and SaaS data-theft cluster with overlapping tactics.whitewarlockPersona that originally posted the Santander breach claim later mirrored by ShinyHunters.

Malware

Vendors

AnodotCloud (Aura) deployments and SaaS supply-chain token theft, running from Drift through Gainsight to Anodot. There were also two escalations that year worth tracking separately from breaches. A turn toward violentBeazley SecurityCo-authored by Sekoia and Beazley Security, this report traces six years of ShinyHunters' activity with first-hand incident response from a 2026 Oracle PeopleSoft compromise.GoogleIt's worth holding onto the same attribution caution that applied to 2024, because it only sharpened further that year. Google's threat intelligence tracks the individual pieces of this campaign as distinct clusters. Instructurethreat covering roughly 5.5 million records. And around April 25, the initial compromise of Instructure's Canvas platform occurred, exploiting the "Free-For-Teacher" account creation mechanism. An intrusionMicrosoftWishbone (~40M), and Chronicle[.]com (~3M). The group also claimed to have stolen roughly 500GB from Microsoft's private GitHub repositories, releasing about 1GB as a proof. Microsoft investigated but neverOracleCo-authored by Sekoia and Beazley Security, this report traces six years of ShinyHunters' activity with first-hand incident response from a 2026 Oracle PeopleSoft compromise.SalesforceEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.Salesloftwith OAuth abuse before pivoting again toward SaaS supply-chain token theft, exemplified by the Salesloft Drift campaign. The second is a brand merger: ShinyHunters, Scattered Spider (tracked separately asSnowflakeEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.

Products

BreachForumsRaidForums user known as "Pompompurin" (later identified as Conor Brian Fitzpatrick) launched BreachForums as an almost identical clone of its predecessor, preserving the same audience and the sameCanvasthreat covering roughly 5.5 million records. And around April 25, the initial compromise of Instructure's Canvas platform occurred, exploiting the "Free-For-Teacher" account creation mechanism. An intrusion that wouldMicrosoft Entraenrollment alerts and cover their tracks. Panera Bread (roughly 5 million records, via a compromised Microsoft Entra SSO) and Grubhub both surfaced as extortion targets that month. The group's Salesforce ExperienceOktafor the resulting data. The group is still using vishing to pivots through enterprise SSO providers (Okta, Entra, Google) into SaaS platforms like SharePoint, OneDrive, Salesforce and Slack. They areOracle PeopleSoftCo-authored by Sekoia and Beazley Security, this report traces six years of ShinyHunters' activity with first-hand incident response from a 2026 Oracle PeopleSoft compromise.RaidForumssell it privately on darkweb markets and RaidForums, SalesforceEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.Salesforce Experience CloudSharePoint, OneDrive, Salesforce and Slack. They are systematically scanning for misconfigured Salesforce Experience Cloud (Aura) deployments and SaaS supply-chain token theft, running from Drift through Gainsight toSalesloft Driftwith OAuth abuse before pivoting again toward SaaS supply-chain token theft, exemplified by the Salesloft Drift campaign. The second is a brand merger: ShinyHunters, Scattered Spider (tracked separately asSnowflakeEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.

Tools

Countries

Australiato have stolen more than 30 million order records and over a million customers' data from Pizza Hut Australia, gained via multiple misconfigured AWS S3 buckets with initial access dating back to around July orChileoriginally posted by "whitewarlock," covering staff data and roughly 30 million customers across Spain, Chile, and Uruguay, listed for about $2 million. The actor also claimed the intrusion had come through the angleFrancebut a byproduct of which platforms or flaws it was exploiting at the time. The one exception being France, where 2025 arrests exposed victims tied directly to the operators' own nationality.IndiaThe group's apparent shift from APAC/India toward the US and Western Europe isn't a strategic choice, but a byproduct of which platforms or flaws it was exploiting at the time. The one exception being France, where 2025IndonesiaIn the group's earliest period, 2020-2021, there was a notable weighting toward APAC, India, and Indonesia. Such targeting includes victims like Tokopedia, Unacademy, BigBasket, Juspay, Upstox, and RedDoorz asNetherlandsSingaporeSeptember was comparatively quiet, with the main event being a breach of a Singapore hotel booking platform RedDoorz around September 4, affecting roughly 5.8 million records and later attributed to ShinyHunters.Spainbreach originally posted by "whitewarlock," covering staff data and roughly 30 million customers across Spain, Chile, and Uruguay, listed for about $2 million. The actor also claimed the intrusion had come throughUnited KingdomUnited Stateswas already winding down, even as the law enforcement story around them was just beginning. When the United States Department of Justice (DOJ) eventually indicted the group's alleged members later that year, and whenUruguayposted by "whitewarlock," covering staff data and roughly 30 million customers across Spain, Chile, and Uruguay, listed for about $2 million. The actor also claimed the intrusion had come through the angle of a

Industries

Related Articles