ShinyHunters is a financially motivated cybercrime and extortion group known primarily for large-scale data theft, sale of stolen records, and pay-or-leak extortion. The actor has been active since at least 2020 and has been associated with high-profile breaches involving cloud platforms, SaaS providers, logistics and fulfillment providers, and consumer-facing enterprises. Known aliases and cluster names appearing in reporting include BLING LIBRA, UNC6040, and UNC6240, though some incident-level attributions and claimed operations remain unconfirmed. The group’s operations center on unauthorized access to data stores and business platforms, followed by exfiltration and monetization through direct extortion, leak-site publication, or sale on cybercrime forums. ShinyHunters has repeatedly claimed responsibility for breaches affecting organizations such as RingCentral, Metabase, ShipMonk-linked victims, Carhartt, and Sharecare, and has also been linked in reporting to broader campaigns affecting Salesforce customers, Snowflake customers, and organizations exposed through Oracle PeopleSoft exploitation. In some cases, the group’s public claims were not independently confirmed, so individual victim attributions should be treated with appropriate caution. Observed tradecraft includes social engineering for initial access, theft of personally identifiable information from database infrastructure, and data exfiltration at scale. The actor has used extortion emails and dark-web leak-site postings to pressure victims, including publication of stolen data after alleged refusal to pay. Reporting also ties the group to abuse of exposed or compromised enterprise data platforms and to campaigns involving cloud-hosted business data. ShinyHunters is best characterized as a data-theft extortion actor rather than a traditional encryption-first ransomware operator, although some victim reporting labels incidents as ransomware. Its dominant pattern is theft of sensitive data, coercive negotiation, and public leaking or sale of records when extortion demands are not met.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The flaw, tracked as CVE-2026-35273, is a critical remote code execution bug that attackers exploited as a zero-day.
Oracle E-Business Suite was the target of a large scale Cl0p ransomware campaign just months ago via CVE-2025-61882... A critical zero day in Oracle EBS Concurrent Processing, exploited by the Cl0p ransomware gang...
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
According to data obtained from a public Telegram channel operated by the ShinyHunters team, the threat actor persona ‘Yukari’ exploited an Oracle Access Manager vulnerability (CVE-2021-35587). The attack targeted financial institutions and manufacturers.
92 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data theft and extortion operations targeting customers of major cloud and SaaS providers, including RingCentral, using social engineering and stolen corporate data for extortion rather than traditional ransomware.
Claimed responsibility for an attack on Metabase and published allegedly stolen data; its connection to the ShipMonk/Trezor-related breach is mentioned as possible but unconfirmed.
Extortion group claiming responsibility for the RingCentral data breach, stealing large volumes of data and publishing leaked data after the victim refused to pay a ransom. The content also describes the group as being involved in numerous other large-scale breaches.
Cybercriminal group linked in this report to extortion following a supply-chain data breach involving ShipMonk and affecting Trezor customer data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.