Skip to content

other

ShinyHunters

Financially motivated hacking group, also tracked as GnosticPlayers and UNC6240, that breaches firms and SaaS platforms to steal data and extort victims.

Known aliases

  • GnosticPlayers
  • GTG-50014
  • @odysseusgroup
  • shinygroup
  • Shiny Hunters
  • ShinyHunters extortion gang
  • ShinyHunters gang
  • UNC6240

Relationships

No evidence-backed relationships are recorded.

Current stories

security8 publishers

Alleged ShinyHunters member detained in Jordan is reportedly helping the FBI find other members

Alleged ShinyHunters member Saif al-Din Khader, detained in Jordan on Tuesday, is helping the FBI find other members, two sources told Reuters. A new ShinyHunters leak site went up two days later, suggesting other members still run the extortion.

Perspective Coverage

8 publishers
Builder
Builder 16%
Operator
Operator 71%
Investor
Investor 13%

Reality

Evidence58
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence62
security9 publishers

Pentagon personnel agency discovered the file-server flaw nine months after intruders began using it

Defense Manpower Data Center is notifying people after intruders read unencrypted files on its server for nine months, exposing 2.76 million living people. Nine months of access means every file that server held over the period should be treated as copied.

Perspective Coverage

9 publishers
Builder
Builder 13%
Operator
Operator 81%
Investor
Investor 6%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence68
product2 publishers

Pentagon breach exposes the job specialties of 2.8 million current and former personnel

Pentagon officials are telling 2.8 million living people that hackers took their personnel records, occupational specialty included. At least 1.5 million of them are not on active duty, so the exposure reaches well beyond the active force a month after a similar FBI breach.

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence64
security9 publishers

FBI presses ShinyHunters members to surrender after Dutch police hold an alleged leader

FBI's Brett Leatherman urged ShinyHunters members to surrender after the Dutch arrest of an alleged leader of a group tied to $70 million in extortion. Dutch police have not ruled out more arrests, though the public record so far shows one suspect in custody.

Perspective Coverage

9 publishers
Builder
Builder 17%
Operator
Operator 68%
Investor
Investor 15%

Reality

Evidence68
Adoption
Insufficient
Hype gap+30
Incentives60
Confidence64
invest1 publisher

FBI memo tells every employee to treat their personal data as stolen after the FBIjobs.gov breach

FBI told staff in an internal memo to assume hacking group ShinyHunters stole data on every employee after a claimed 2 to 3 terabyte breach of FBIjobs.gov. Until the bureau confirms the scale, staff and the job applicants the hackers say are also in the files have reason to treat their home addresses as exposed.

Publishers:decrypt.co

Reality

Evidence35
Adoption
Insufficient
Hype gap+15
Incentives70
Confidence40
product3 publishers

ShinyHunters defaced the FBI's jobs site a week after Dutch police held an alleged leader

Dutch police detained an alleged ShinyHunters leader on September 15, seven days before the group defaced the FBI's jobs website. The FBI says it is still chasing the rest of the group, so the vendor services and web portals it has used to get in remain the exposure to manage.

Perspective Coverage

3 publishers
Builder
Builder 13%
Operator
Operator 69%
Investor
Investor 18%

Reality

Evidence60
Adoption
Insufficient
Hype gap+25
Incentives60
Confidence58
security8 publishers

ShinyHunters slips past PeopleSoft firewall rules by encoding one character

ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 58%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+8
Incentives58
Confidence74
security1 publisher

ShinyHunters calls its FBI ultimatum a marketing campaign

ShinyHunters says it will never publish or sell the 2TB to 3TB of FBI data it claims to hold and calls its one-week ultimatum a marketing campaign. The pledge leaves standing its unverified claim that an Oracle PeopleSoft zero-day got it in.

Publishers:hackread.com

Reality

Evidence30
Adoption
Insufficient
Hype gap+45
Incentives70
Confidence40
security1 publisher

ShinyHunters' leak samples expose named FBI agents' medical exams

ShinyHunters has shown journalists FBI medical exams that name agents and their addresses, from a set it says covers about 60,000 current and former staff. The FBI has so far confirmed only an incident in FBIJobs-related systems, and the group is threatening to publish within five days.

Publishers:malwarebytes.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence45
security3 publishers

RingCentral's platform held. Its customer records are on the internet anyway.

ShinyHunters claims 623GB from a July social-engineering campaign and leaked part of it. Have I Been Pwned confirmed 1.6 million account records. Both the vendor and the crew can be telling the truth.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 62%
Investor
Investor 16%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence70

Earlier coverage

  1. ShinyHunters routes around PeopleSoft firewall rules to hit systems still missing Oracle's patch

    Invest · September 26, 2026 · 1 publisher

  2. ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered

    Security · August 25, 2026 · 5 publishers

  3. ShinyHunters breached Clop's leak site through an unpatched Grav path traversal flaw

    Security · September 26, 2026 · 1 publisher

  4. McKesson's 8-K locates the stolen data inside third-party applications

    Security · August 28, 2026 · 9 publishers

  5. North Korea's WaterPlum fake-recruiter campaign has stolen $10.7 million from IT workers

    Security · September 25, 2026 · 1 publisher

  6. Trezor says ShipMonk kept 67,000 customer records it had certified as deleted

    Security · September 6, 2026 · 3 publishers

  7. Intruders reached Mathspace's unpatched Metabase four days after the fix shipped

    Security · September 7, 2026 · 4 publishers

  8. Attackers phished Trezor, BitBox and CoinTracking customers through one shared newsletter provider

    Security · September 10, 2026 · 4 publishers

  9. Florida traces the DAVID driver database breach to one Plant City police account

    Security · September 11, 2026 · 2 publishers

  10. Anthropic widened its dual-use biology block on lost certainty about the old threshold

    Build · September 10, 2026 · 5 publishers

  11. Storm-3121 callers demand an urgent passkey update to harvest Microsoft 365 session tokens

    Security · September 11, 2026 · 6 publishers

  12. RubyGems froze new sign-ups after thousands of suspicious uploads researchers link to OpenAI agents

    Security · September 11, 2026 · 12 publishers

  13. ShinyHunters threatens to name companies that paid Clop after defacing its leak site

    Security · September 25, 2026 · 1 publisher

  14. Google's undercover analyst watched TeamPCP poison packages from inside its core chat

    Product · September 18, 2026 · 1 publisher

  15. ShinyHunters says a Grav upload path let it deface Clop's leak site

    Build · September 19, 2026 · 2 publishers

  16. ShinyHunters reportedly pivoted from a recruiting server to FBI agent records

    Product · September 22, 2026 · 4 publishers

  17. ShinyHunters pins its claimed FBI breach on an unpatched PeopleSoft RCE

    Security · September 23, 2026 · 14 publishers

  18. ShinyHunters demands an FBI advisory retraction as the price of not leaking staff data

    Product · September 24, 2026 · 1 publisher

  19. ShinyHunters claims an Oracle PeopleSoft exploit opened the FBI's job application portal

    Product · September 23, 2026 · 1 publisher

  20. ShinyHunters claims 2 to 3 terabytes of FBI personnel data from an Oracle PeopleSoft flaw

    Leadership · September 23, 2026 · 3 publishers

  21. ShinyHunters claims a PeopleSoft zero-day gave it code execution on FBI servers

    Product · September 23, 2026 · 1 publisher

  22. ShinyHunters claims the private keys to Clop's onion address after defacing the leak site

    Security · September 19, 2026 · 6 publishers

  23. Clop asks ShinyHunters to come online from the leak site ShinyHunters defaced

    Security · September 22, 2026 · 1 publisher

  24. ShinyHunters says it controls the private keys to Cl0p's onion address

    Product · September 21, 2026 · 1 publisher

  25. ShinyHunters says a Grav upload flaw got it inside Cl0p's leak site

    Product · September 21, 2026 · 1 publisher

  26. Telus says stolen credentials gave an attacker 16 months inside consumer telecom accounts

    Security · September 14, 2026 · 1 publisher

  27. IBM prices the AI-assisted breach at a million dollars more than the rest

    Invest · September 14, 2026 · 1 publisher

  28. AdaptHealth traces a 4.1 million-record breach to one compromised contractor session

    Security · September 12, 2026 · 2 publishers

  29. San Francisco's city attorney orders Meta to stop allowing AI child abuse ads its review missed

    Product · September 12, 2026 · 1 publisher

  30. Anthropic documents five possible bioweapons cases it cannot confirm were meant to cause harm

    Product · September 11, 2026 · 7 publishers

  31. ShinyHunters affiliates escalated one stolen token to full cloud admin in about three hours

    Product · September 10, 2026 · 1 publisher

  32. Fake IT callers register their own MFA method under the Microsoft 365 identities they phish

    Security · September 10, 2026 · 1 publisher

  33. ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal

    Security · September 8, 2026 · 1 publisher

  34. TeamPCP poisoned more than 1,000 packages with tactics anyone can copy

    Security · August 28, 2026 · 1 publisher

  35. Jack Henry stakes a public refusal on an exposure it counts in institutions

    Invest · September 2, 2026 · 1 publisher

  36. Log4j maintainers call this week's critical RCE reports a known security non-finding

    Security · August 28, 2026 · 1 publisher

  37. ShinyHunters dumps 12.9 million Carhartt records after a refused $3.3 million ransom

    Security · August 27, 2026 · 1 publisher

  38. Take-Two's GTA 6 leak subpoena turns Discord and Microsoft logs into a device-level ID list

    Security · August 25, 2026 · 1 publisher

  39. A DMCA notice over one GitHub repo now asks Microsoft for MachineGuids from three Discord servers

    Build · August 22, 2026 · 1 publisher

  40. The extortion call now comes from your help desk, and the fix is a procedure you own

    Leadership · August 19, 2026 · 1 publisher