ShinyHunters is a financially motivated cybercriminal collective and data-theft extortion brand active since at least 2020. It has persisted through changes in membership, arrests and disruption of its infrastructure. Name variants include ShinyHunter and Shiny Hunters; associated tracking names include Bling Libra, UNC6040 and UNC6240, although these labels should not necessarily be treated as interchangeable descriptions of every operation. The collective targets corporate cloud and software-as-a-service accounts, as well as government systems. Its targets span information technology, healthcare, telecommunications, professional services, retail and food distribution. Initial-access methods include phishing, voice phishing, impersonation of IT support personnel, use of stolen credentials and exploitation of unpatched enterprise applications. Its social-engineering operations target enterprise identity services, including Okta, while its cloud attacks abuse legitimate OAuth mechanisms to obtain data through activity that can resemble ordinary application traffic. ShinyHunters compromised numerous Snowflake customer environments lacking multifactor authentication and used stolen data for extortion. ShinyHunters primarily monetizes stolen information through demands for payment backed by threats of public disclosure, rather than file encryption. It operates a leak site, publishes victim listings and negotiation deadlines, and releases stolen information to increase pressure. Its activity has included the compromise of the FBI's recruitment platform, exposing employee personal information, sensitive assignment details and medical information. The intrusion was attributed to a failure to apply an issued security patch on a third-party-managed platform. International law-enforcement investigations have resulted in multiple arrests of suspected participants, but the brand and its data-publication infrastructure have continued to operate.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
67 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Google’s Mandiant separately reported that the group had exploited CVE-2026-35273, a critical flaw in Oracle PeopleSoft’s Environment Management component, and used URL encoding to get around WAF rules blocking the vulnerable endpoint.
The origins of the hostility trace to autumn 2025 during an extortion campaign centered on an Oracle E-Business Suite (EBS) zero-day vulnerability designated as CVE-2025-61882. Threat intelligence tracking revealed that unpatched enterprise Oracle EBS instances were systematically targeted to exfiltrate critical corporate databases from over one hundred corporations.
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
Параллельный вектор — эксплуатация CVE-2021-35587 в Oracle Access Manager... неаутентифицированный атакующий с сетевым доступом по HTTP получает полный контроль над Oracle Access Manager. Уязвимость включена в каталог CISA KEV; по данным AlienVault OTX имеет более 50 пульсов с тегом «actively exploited».
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
2 more CVEs tied to this actor tracked in Mallory.
209 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with an FBI breach exposing employees’ personal information and previous attacks against cloud platforms, healthcare organizations, universities, technology companies, retailers, and education service providers. Authorities have arrested several suspected affiliates or co-conspirators. The article suggests, but does not confirm, that Edward Dubrovsky’s extortion charges are connected to the group’s FBI attack.
Named hacking group associated with an attack on FBI Jobs. The report states that the FBI arrested the co-founder of a Canadian cybersecurity firm for allegedly assisting the group; the excerpt provides no technical details about the attack.
A data-theft and extortion group under an international FBI investigation involving multiple arrests. ShinyHunters claimed to have stolen personal and health-related information about current, former and prospective FBI personnel, but the FBI confirmed only unauthorized portal activity, not the full data-theft claims. The group said it would not leak the FBI data and characterized the breach as marketing. Its download infrastructure reportedly remains online, hosting terabytes of stolen corporate data. Edward Dubrovsky’s alleged connection to the group and the precise basis for his arrest remain publicly unresolved.
Conducts data theft and extortion against software-as-a-service companies and other organizations. The article reports that the group stole sensitive information from the FBI's recruitment portal, including personnel details and medical and psychiatric records. According to the FBI, it has extorted more than $70 million from victims this year. The article centers on the arrest of a Canadian ransomware-negotiation specialist suspected of assisting the group, alongside arrests involving alleged members.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.