ShinyHunters

ShinyHunters — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

ShinyHuntersConfidence: High

Data theft / extortion group

Motivation: Financial extortion, data sale

53Attributed Breaches
HighAttribution Confidence
Data theft / extortion groupActor Type

Overview

A prolific data theft and extortion group that began as a database theft and resale actor and evolved toward SaaS-focused extortion. Recent activity involves vishing, credential harvesting, SSO compromise, and theft of customer data from cloud and SaaS environments.

Tactics, Targeting & Attribution

Actor class: data theft/extortion. Targeting: SaaS, Salesforce, customer databases. Related clusters include UNC6040, UNC6240, and UNC6661 in some reporting.

ObscureIQ Classification

Confirmed data theft/extortion actor.

Source

Attribution and profile draw on public threat-intelligence reporting. Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or get a tailored exposure audit.

Request Consultation