Report Traces ShinyHunters’ Six-Year Evolution and Changing Attack Tactics

Summary
Sekoia and Beazley trace ShinyHunters’ activity from 2020 to 2026, detailing its shifting access methods, decentralized identity, breach claims, law-enforcement actions and recent campaigns, including exploitation of a PeopleSoft zero-day.
Key points
- The report describes ShinyHunters as a shifting cybercrime brand used by multiple clusters, rather than a single stable group; it cautions that breach claims and attribution often need independent verification.
- Access tactics evolved from exposed credentials, GitHub tokens and misconfigured S3 buckets to MFA-less Snowflake accounts, vishing, OAuth abuse and SaaS supply-chain token theft.
- The report links the 2026 PeopleSoft campaign to CVE-2026-35273, a critical remote-code-execution flaw exploited before Oracle’s June 10 advisory; Google identified more than 100 exposed organizations, about 68% in higher education.
- Incident-response findings from a PeopleSoft compromise describe JSP backdoors, MeshAgent, Chisel, Rclone, scheduled PowerShell tasks and attempts to disable CrowdStrike protections.
- The report highlights recurring MFA and cloud-configuration weaknesses, while noting that attackers’ claimed breach figures can exceed victims’ confirmed impact.
- It includes Sekoia detection queries and incident-response indicators for the PeopleSoft campaign, including suspicious files, a domain and an IP address.
Article Details
- Publisher
- Sekoia and Beazley Security
- Report Period
- 2020–2026; activity covered through early September 2026
- Scope
- ShinyHunters' organizational evolution, access methods, breaches, extortion, and a 2026 Oracle PeopleSoft compromise investigated by Beazley Security.
- Key Statistics
- Mandiant reported that up to 165 Snowflake customer organizations were potentially exposed in the 2024 campaign; the report says Snowflake's platform itself was not breached.
- In the 2025 Salesloft Drift campaign, stolen OAuth tokens were used to export Salesforce data from more than 700 organizations. ShinyHunters claimed the figure was closer to 760.
- Google identified more than 100 exposed organizations in the 2026 Oracle PeopleSoft campaign; roughly 68% of affected organizations were in higher education.
- For the 2023 Pizza Hut Australia incident, ShinyHunters claimed more than one million customers and 30 million order records, while the company scoped the impact to roughly 193,000 customers.
- Recommendations
- Hunt for connections to azurenetfiles.net and 142.11.200.186 using the report's detection queries.
- Hunt for creation of the MeshFwFix scheduled task and execution of cs_disable.cmd.
- Hunt for the modified MeshAgent binary at C:\Windows\Temp\ma.exe and creation of the JSP backdoors orau.jsp and webpack.jsp.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | azurenetfiles[.]net | Malicious domain in a detection query for the Oracle PeopleSoft incident; the report describes a C2 domain mimicking Azure infrastructure. |
| DOMAIN | breachforums[.]hn | Newly registered domain hosting a purported SLSH goodbye letter that Resecurity flagged as likely disinformation. |
| DOMAIN | breachforums[.]st | BreachForums domain ShinyHunters reportedly regained and used to redirect users after a forum seizure. |
| DOMAIN | raid[.]lol | Seized domain of RaidForums, the illicit marketplace used for ShinyHunters' stolen-data sales and leaks. |
| DOMAIN | raidforums[.]com | Seized domain of RaidForums, the illicit marketplace used for ShinyHunters' stolen-data sales and leaks. |
| DOMAIN | rf[.]ws | Seized domain of RaidForums, the illicit marketplace used for ShinyHunters' stolen-data sales and leaks. |
| IPV4 | 142[.]11[.]200[.]186 | Malicious remote IP identified in a detection query for the Oracle PeopleSoft incident. |
| SHA256 | a4e525d8825c1bac6dd934ef2c008b5fb9988289190b5b98d854799e07e207e4 | SHA-256 of webpack.js, listed among indicators collected during Beazley Security's Oracle PeopleSoft incident response. |
MITRE ATT&CK
T1021.001 · Remote Desktop ProtocolBeazley Security observed lateral movement through RDP using compromised credentials.T1053.005 · Scheduled TaskThe report provides a detection query for malicious scheduled-task creation.T1059.001 · PowerShellMalicious scheduled tasks executed obfuscated PowerShell scripts.T1078 · Valid AccountsIntrusions used stolen or compromised credentials to access cloud and enterprise environments.T1190 · Exploit Public-Facing ApplicationThe 2026 Oracle PeopleSoft campaign exploited CVE-2026-35273 in an exposed endpoint.T1505.003 · Web ShellAttackers deployed JSP backdoors on compromised PeopleSoft servers for persistence.T1550.002 · Pass the HashBeazley Security also observed Pass-the-Hash during lateral movement.T1562.001 · Disable or Modify ToolsThe incident response observed disabled PowerShell monitoring and a script that disables CrowdStrike EDR.T1566.002 · Spearphishing LinkEarlier intrusions used phishing emails leading victims to fake login pages.T1566.004 · Spearphishing VoiceThe 2025–2026 intrusions used voice phishing and IT-helpdesk impersonation.
CVE
Threat Actors
Dark StormGroup whose DDoS attack was suggested as one possible explanation for a BreachForums outage; the cause remains unsettled.GnosticPlayersEarlier hacking collective linked to ShinyHunters through researcher-attributed personnel overlap; individuals involved disputed ShinyHunters membership.HellcatActor whom ShinyHunters alleged, in an interview cited by the report, was behind SLSH; this is a disputed third-party claim.LAPSUS$Group described as part of the broader ecosystem and the reported Scattered Lapsus$ Hunters merger.QilinRansomware group whose possible retaliation was suggested as an explanation for a BreachForums outage; the cause remains unsettled.Scattered Lapsus$ HuntersName the report also uses for the purported Scattered Lapsus$ Hunters collective.Scattered SpiderGroup described as part of the broader ecosystem; the report says it is separately tracked as UNC3944.ShinyHuntersData-theft and extortion brand active since 2020; the report cautions that distinct clusters have operated under its name.SLSHAbbreviation explicitly used for Scattered Lapsus$ Hunters; the report notes disputed accounts of its membership.Sp1d3rPersona associated in reporting with extortion during the Snowflake campaign.Sp1d3rHuntersPersona the report describes as overlapping with the Snowflake campaign's ShinyHunters branding.SpidermanDataPersona that advertised alleged Ticketmaster records during the Snowflake campaign.The ComBroader cybercrime community to which the report assesses a high-confidence ShinyHunters link.TheDarkOverlordEarlier extortion collective that researchers connect to ShinyHunters' lineage through reported personnel continuity.UNC5537Mandiant's designation for the 2024 Snowflake intrusions; the report distinguishes their operators from ShinyHunters' historic core.UNC6040Google-tracked cluster associated with the 2025 Salesforce vishing intrusions.UNC6240Google-tracked extortion arm that the report says consistently claims to be ShinyHunters.UNC6395Google-tracked Salesloft Drift campaign cluster; Google did not attribute it to ShinyHunters.UNC6661Google-tracked cluster associated with 2026 SSO and vishing intrusions.UNC6671Google-tracked vishing and SaaS data-theft cluster with overlapping tactics.whitewarlockPersona that originally posted the Santander breach claim later mirrored by ShinyHunters.
Malware
Vendors
AnodotCloud (Aura) deployments and SaaS supply-chain token theft, running from Drift through Gainsight to Anodot. There were also two escalations that year worth tracking separately from breaches. A turn toward violentBeazley SecurityCo-authored by Sekoia and Beazley Security, this report traces six years of ShinyHunters' activity with first-hand incident response from a 2026 Oracle PeopleSoft compromise.GoogleIt's worth holding onto the same attribution caution that applied to 2024, because it only sharpened further that year. Google's threat intelligence tracks the individual pieces of this campaign as distinct clusters. Instructurethreat covering roughly 5.5 million records. And around April 25, the initial compromise of Instructure's Canvas platform occurred, exploiting the "Free-For-Teacher" account creation mechanism. An intrusionMicrosoftWishbone (~40M), and Chronicle[.]com (~3M). The group also claimed to have stolen roughly 500GB from Microsoft's private GitHub repositories, releasing about 1GB as a proof. Microsoft investigated but neverOracleCo-authored by Sekoia and Beazley Security, this report traces six years of ShinyHunters' activity with first-hand incident response from a 2026 Oracle PeopleSoft compromise.SalesforceEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.Salesloftwith OAuth abuse before pivoting again toward SaaS supply-chain token theft, exemplified by the Salesloft Drift campaign. The second is a brand merger: ShinyHunters, Scattered Spider (tracked separately asSnowflakeEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.
Products
BreachForumsRaidForums user known as "Pompompurin" (later identified as Conor Brian Fitzpatrick) launched BreachForums as an almost identical clone of its predecessor, preserving the same audience and the sameCanvasthreat covering roughly 5.5 million records. And around April 25, the initial compromise of Instructure's Canvas platform occurred, exploiting the "Free-For-Teacher" account creation mechanism. An intrusion that wouldMicrosoft Entraenrollment alerts and cover their tracks. Panera Bread (roughly 5 million records, via a compromised Microsoft Entra SSO) and Grubhub both surfaced as extortion targets that month. The group's Salesforce ExperienceOktafor the resulting data. The group is still using vishing to pivots through enterprise SSO providers (Okta, Entra, Google) into SaaS platforms like SharePoint, OneDrive, Salesforce and Slack. They areOracle PeopleSoftCo-authored by Sekoia and Beazley Security, this report traces six years of ShinyHunters' activity with first-hand incident response from a 2026 Oracle PeopleSoft compromise.RaidForumssell it privately on darkweb markets and RaidForums, SalesforceEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.Salesforce Experience CloudSharePoint, OneDrive, Salesforce and Slack. They are systematically scanning for misconfigured Salesforce Experience Cloud (Aura) deployments and SaaS supply-chain token theft, running from Drift through Gainsight toSalesloft Driftwith OAuth abuse before pivoting again toward SaaS supply-chain token theft, exemplified by the Salesloft Drift campaign. The second is a brand merger: ShinyHunters, Scattered Spider (tracked separately asSnowflakeEach year's targeting has tracked whatever access method was cheapest to exploit at scale. S3 buckets and GitHub tokens, Snowflake accounts lacking MFA, OAuth-abused Salesforce integrations and PeopleSoft zero-day.
Tools
AuraInspectorSalesforce Experience Cloud tooling, built around a modified version of the open-source auditing tool AuraInspector, released that same January and immediately got weaponized.Chiselthough other attacks like Pass-the-Hash were also observed. Open source network tunnel utility Chisel was used to facilitate remote RDP sessions. Many hosts had malicious scheduled tasks executing obfuscatedMeshAgentAttacks against security tools also included a small windows script that disables CrowdStrike EDR. MeshAgent was observed being used as C2, matching Google’s reporting. The popular open source file transferMeshCentralthe operation in detail. The attackers had built their staging infrastructure around the open-source MeshCentral remote management platform, deploying Windows agent binaries disguised as Microsoft Azure services andRapeFlakeon the customer side. The attackers used a custom reconnaissance and exfiltration tooling nicknamed "RapeFlake" to move through compromised environments. RClonewas observed being used as C2, matching Google’s reporting. The popular open source file transfer utility Rclone was used when exfiltration was attempted.
Countries
Australiato have stolen more than 30 million order records and over a million customers' data from Pizza Hut Australia, gained via multiple misconfigured AWS S3 buckets with initial access dating back to around July orChileoriginally posted by "whitewarlock," covering staff data and roughly 30 million customers across Spain, Chile, and Uruguay, listed for about $2 million. The actor also claimed the intrusion had come through the angleFrancebut a byproduct of which platforms or flaws it was exploiting at the time. The one exception being France, where 2025 arrests exposed victims tied directly to the operators' own nationality.IndiaThe group's apparent shift from APAC/India toward the US and Western Europe isn't a strategic choice, but a byproduct of which platforms or flaws it was exploiting at the time. The one exception being France, where 2025IndonesiaIn the group's earliest period, 2020-2021, there was a notable weighting toward APAC, India, and Indonesia. Such targeting includes victims like Tokopedia, Unacademy, BigBasket, Juspay, Upstox, and RedDoorz asNetherlandsSingaporeSeptember was comparatively quiet, with the main event being a breach of a Singapore hotel booking platform RedDoorz around September 4, affecting roughly 5.8 million records and later attributed to ShinyHunters.Spainbreach originally posted by "whitewarlock," covering staff data and roughly 30 million customers across Spain, Chile, and Uruguay, listed for about $2 million. The actor also claimed the intrusion had come throughUnited KingdomUnited Stateswas already winding down, even as the law enforcement story around them was just beginning. When the United States Department of Justice (DOJ) eventually indicted the group's alleged members later that year, and whenUruguayposted by "whitewarlock," covering staff data and roughly 30 million customers across Spain, Chile, and Uruguay, listed for about $2 million. The actor also claimed the intrusion had come through the angle of a
Industries
AviationSalesforce instance had been hit, exposing SMB advertising contact data. Through June and into July, an aviation sector wave unfolded, targeting Qantas, Air France-KLM, Hawaiian Airlines, WestJet, and later VietnamEducationof roughly one petabyte of data alongside a reported $65 million ransom demand. Infinite Campus, an education platform, was hit through Salesforce, and extortion against Rockstar Games began that month via whatFinancial Servicessevere enough to make paying look cheaper than not paying. This is why healthcare, education, and financial services victims recur so often. The compliance exposure does much of the group's negotiating for it.Healthcareone identity. Finally, McKesson between the 25th and 28th, the month's headline incident, in which the healthcare distributor confirmed unauthorized access to third-party applications affecting its Oncology andTelecommunications