Extortionists sent ASOS app users an apparently genuine ASOS push alert on October 6 claiming they had fully compromised the retailer's Snowflake instance. The alert is the only access anyone outside ASOS has seen; the entry route and any data taken are unknown.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+45
- Incentives70
- Confidence35
ShinyHunters says a second PeopleSoft zero-day let it steal data on every FBI employee, a claim neither the FBI nor Oracle has confirmed. Two suspects have since been arrested, and PeopleSoft customers are still judging their own exposure from analysts' advice.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+40
- Incentives60
- Confidence35
Alleged ShinyHunters member Saif al-Din Khader, detained in Jordan on Tuesday, is helping the FBI find other members, two sources told Reuters. A new ShinyHunters leak site went up two days later, suggesting other members still run the extortion.
Perspective Coverage
11 publishers
- Builder
- Builder 14%
- Operator
- Operator 72%
- Investor
- Investor 14%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence62
Daniel Rhyne, a former infrastructure engineer, got 32 months in prison for using domain controller tasks to lock out 254 servers and 3,284 workstations. He staged it over 17 days of unauthorized access, and administrators learned of it from password-reset notifications after the tasks ran.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
ShinyHunters claims it holds fitness-for-work medical records, including blood and urine results, on about 60,000 current and former FBI staff. Test results and home addresses cannot be reset like a password, so containment now depends on the files staying unpublished.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence50
ShinyHunters claims data on almost every FBI agent, and samples reviewed by researchers show contact information, family details and duty assignments. The FBI has not confirmed what was taken or who took it, and says it is investigating.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence40
ShinyHunters told 404 Media it will never publish its FBI haul, which it claims is 2 to 3 terabytes covering all employees and applicants. Keeping the files unpublished limits public exposure, but agents' home addresses, spouses' names and medical records are still with the group.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives75
- Confidence45
ShinyHunters says it will never publish or sell the 2TB to 3TB of FBI data it claims to hold and calls its one-week ultimatum a marketing campaign. The pledge leaves standing its unverified claim that an Oracle PeopleSoft zero-day got it in.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+45
- Incentives70
- Confidence40
Army soldier Cameron Wagenius got 70 months in prison for extorting AT&T with call records taken from Snowflake accounts that lacked MFA. His group got in with exposed credentials alone, and AT&T's $370,000 ransom did not stop the leaks that followed.
Perspective Coverage
7 publishers
- Builder
- Builder 22%
- Operator
- Operator 59%
- Investor
- Investor 19%
Reality
- Evidence82
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence78
ShinyHunters is again exploiting Oracle PeopleSoft flaw CVE-2026-35273, getting past WAF rules by URL-encoding one letter of the path, Mandiant reported. The servers now in reach are the ones whose operators filtered the endpoint and never applied Oracle's patch.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence55
ShinyHunters has shown journalists FBI medical exams that name agents and their addresses, from a set it says covers about 60,000 current and former staff. The FBI has so far confirmed only an incident in FBIJobs-related systems, and the group is threatening to publish within five days.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence45
ShinyHunters says the two to three terabytes it took from the FBI include psychiatric and medical evaluations of bureau staff. Beside a Reuters sample tying named staff to counterintelligence jobs, those files are exposure no password reset can fix.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence40
Cameron Curry got two years for extorting Brightly Software with stolen payroll data. The demand started one day after his contract ended, which is where the control gap sits.
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+15
- Incentives25
- Confidence72
ShinyHunters claims 623GB from a July social-engineering campaign and leaked part of it. Have I Been Pwned confirmed 1.6 million account records. Both the vendor and the crew can be telling the truth.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 62%
- Investor
- Investor 16%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
BleepingComputer confirmed the attacker's text file and the defaced page on Clop's existing onion address. The full server access, the stolen source code and the Tor private key are still ShinyHunters' own account of it.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives75
- Confidence55
Latvian police say one man with an automated scanner and an anonymous mailbox turned two mid-sized company websites into an extortion business. Investigators linked the two cases on similarities in the methods used.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 65%
- Investor
- Investor 12%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+8
- Incentives45
- Confidence72
The group told 404 Media it reached apply.fbijobs.gov through Oracle's PeopleSoft, and the FBI says the point of breach is still undetermined. Three of the bureau's recruiting pages have been serving error screens.
Reality
- Evidence52
- Adoption40
- Hype gap+32
- Incentives72
- Confidence55
A hacker used a government employee's infostealer-compromised mailbox to send fraudulent requests to Revolut's Lithuanian subsidiary for about five months, and roughly 680 customers' passports and financial data went out.
Reality
- Evidence45
- Adoption55
- Hype gap+20
- Incentives65
- Confidence50
Revolut says its core systems were never touched, and that staff approved fraudulent information requests because the sender's domain was genuine and the email authentication valid. It is applying for a deposit-taking licence in Israel.
Reality
- Evidence38
- Adoption45
- Hype gap+15
- Incentives75
- Confidence40