ShinyHunters

ShinyHunters — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

ShinyHuntersConfidence: High

Data theft / extortion

Motivation: Financial

71Attributed Breaches Circulating
HighAttribution Confidence
Data theft / extortionActor Type
Part of the Scattered Lapsus$ Hunters coalition (41 combined breaches). Coalition breaches are tracked once on the coalition profile and cross-referenced here.

Overview

Began as a database theft and resale actor and evolved toward SaaS-focused extortion, using vishing, credential harvesting, and SSO compromise to steal customer data from cloud and SaaS environments. Prolific and currently active.

Tactics, Targeting & TTPs

Targeting: SaaS, Salesforce, customer databases. Related clusters include UNC6040, UNC6240, and UNC6661 in some reporting. Monetization: extortion and sale/resale of stolen data.

Related Clusters & Actors

UNC6040UNC6240UNC6661Scattered Lapsus$ Hunters

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation