Topic: shinyhunters group
-
McGraw Hill Data Breach Impacts 13.5 Million Users
The ShinyHunters extortion group leaked data from 13.5 million McGraw Hill user accounts, exploiting a misconfiguration in a Salesforce environment earlier this month. The exposed personally identifiable information includes names, addresses, and emails, which can be used for targeted spear-phish...
Read More » -
Infinite Campus breach alert follows ShinyHunters data theft claim
Infinite Campus, a major student information system provider, notified clients of a data breach after the ShinyHunters cybercriminal group accessed an employee's Salesforce account, but maintains no student databases were compromised. The ShinyHunters group, known for exploiting Salesforce securi...
Read More » -
ShinyHunters Breach at Rockstar Games via Anodot
The ShinyHunters group claims to have breached Rockstar Games by exploiting a third-party analytics firm (Anodot) to access data on the Snowflake cloud platform. The hackers have threatened to release the stolen data publicly on April 14, 2026, if unspecified ransom demands are not met, highlight...
Read More » -
ShinyHunters Targets Salesforce Experience Cloud in New Attack
The ShinyHunters group is attacking Salesforce Experience Cloud by weaponizing a legitimate security tool, Aura Inspector, to exploit misconfigured guest user permissions and access sensitive data without authentication. Salesforce states its platform is secure but urges customers to immediately ...
Read More » -
How ShinyHunters Hackers Exploit SSO to Steal Cloud Data
The ShinyHunters group uses sophisticated voice phishing (vishing) to steal employee credentials and bypass multi-factor authentication by impersonating IT support and using fake login pages. Once inside via a compromised single sign-on (SSO) account, attackers gain a centralized springboard to a...
Read More » -
ShinyHunters Breach Okta, Microsoft SSO in Major Data Theft
The ShinyHunters gang is conducting a sophisticated voice phishing campaign, using social engineering to steal credentials and MFA codes by impersonating IT support and using real-time, interactive phishing kits. Attackers exploit compromised SSO accounts (e.g., Okta, Microsoft Entra, Google) to ...
Read More » -
ShinyHunters hacks Canvas login portals in mass extortion campaign
The ShinyHunters extortion gang defaced Canvas login portals at approximately 330 educational institutions, displaying a ransom demand and threatening to release stolen data unless a settlement is reached by May 12, 2026. This attack follows a recent breach where ShinyHunters claimed to have stol...
Read More » -
Checkout.com donates ransom to charity after data breach
Checkout.com experienced a data breach when the ShinyHunters cybercrime group accessed a legacy cloud storage system, but the company has refused to pay the ransom. The compromised data includes internal documents and customer onboarding materials from 2020 and earlier, affecting a minority of cu...
Read More » -
FBI Shuts Down BreachForums in Salesforce Extortion Case
Federal authorities, in a joint U.S.-French operation, seized the BreachForums domain used by the ShinyHunters collective to extort businesses affected by Salesforce data theft, redirecting it to FBI-controlled infrastructure. The ShinyHunters group confirmed that law enforcement gained control o...
Read More » -
Carnival Cruise data breach hits nearly 6 million people
Carnival Corporation confirmed a data breach affecting nearly 6 million individuals, first claimed by the ShinyHunters extortion gang in April 2026, which exposed names, addresses, and some passport numbers but no financial data. The breach originated from a phishing attack targeting employee ema...
Read More » -
ShinyHunters Hackers Launch Massive Salesforce Attack
Salesforce is urging customers to immediately review security settings due to a widespread data theft campaign by the ShinyHunters group, which exploits misconfigured guest user permissions on public-facing sites. The attackers use a customized tool to scan for and extract exposed data, which is ...
Read More » -
Optimizely Data Breach Confirmed After Vishing Attack
Optimizely, a major ad-tech firm, suffered a security breach after a sophisticated voice-phishing attack on February 11th, which allowed intruders to access basic business contact information from its CRM. The company confirmed the attackers were contained and could not access sensitive customer ...
Read More » -
Grubhub Data Breach: Hackers Stole Customer Information
Grubhub has confirmed a data breach, contained the incident, and is working with experts, but has not disclosed specifics about compromised customer data or potential extortion. The attack is attributed to the ShinyHunters group, which is demanding a Bitcoin ransom to prevent the release of data ...
Read More » -
Salesforce Gainsight Compromise: Key Findings & Customer Action Steps
Salesforce detected unauthorized API calls from non-whitelisted IPs via the Gainsight Connected App, prompting immediate security actions to protect customer data. Gainsight has been temporarily removed from the Hubspot Marketplace, with only three organizations confirmed impacted and no verified...
Read More » -
Cloudflare Data Breach Linked to Salesloft Drift Supply Chain Attack
Cloudflare experienced a supply chain attack via its Salesforce customer support system, exposing API tokens and sensitive customer data, including contact details and support case information. The breach, occurring between August 12-17, is part of a broader campaign targeting multiple organizati...
Read More » -
Texas Sues PowerSchool Over Data Breach Affecting 62M Students
Texas is suing PowerSchool over a major data breach that exposed sensitive information of millions of students, alleging the company failed to protect data and misled customers about security. The breach occurred in December 2024 when an attacker used stolen credentials to access PowerSchool's po...
Read More » -
Figure Data Breach Exposes Fintech Lending Giant
Figure Technology suffered a data breach due to a social engineering attack, where hackers accessed sensitive customer files, and the company is offering credit monitoring to affected individuals. The ShinyHunters hacking group claimed responsibility, stating they released about 2.5 GB of stolen ...
Read More » -
Major Dating Apps Hacked: Hinge, Tinder, OkCupid Data Exposed
A major data breach at Match Group, parent company of Hinge, Tinder, and OkCupid, was caused by a phishing attack that compromised an employee's single sign-on account. The stolen data includes millions of user records and internal documents, but the company states passwords, financial details, a...
Read More » -
Salesforce Probes New Security Incident Similar to Salesloft Breach
Salesforce is investigating a security incident involving unauthorized access to customer data through Gainsight app integrations, leading to revoked tokens and temporary removal of the apps from AppExchange. Threat actors linked to ShinyHunters compromised Gainsight OAuth tokens to access Salesf...
Read More » -
Farmers Insurance Data Breach Exposes 1.1M After Salesforce Hack
A data breach at Farmers Insurance exposed the personal information of over 1.1 million customers due to a third-party vendor incident in May 2025. The breach involved unauthorized access to sensitive data, including names, addresses, driver's license numbers, and partial Social Security details....
Read More »