ShinyHunters
Active3 briefings · first covered 4/29/2026 · last covered 6/28/2026
Exploitable Vulnerabilities, Prioritized
Sorted by CISA KEV status and EPSS exploit probability, same signals as the dashboard.
Indicators of Compromise
Subscribe to unlock this actor's full IOC list
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Attribution & Known Techniques
Matched to shinyhunters in MISP's open threat-intelligence galaxy (ransomware cluster).
No technique-level data in the matched source for this actor.
Coverage Timeline
6/28/2026 · KNOW YOUR ENEMY
ShinyHunters Breaches 100 Organizations Using Oracle PeopleSoft Zero-Day
ShinyHunters exploited a CVSS 9.8 Oracle PeopleSoft zero-day to compromise 100+ organizations before Oracle knew the flaw existed.
5/27/2026 · ACTIVE CAMPAIGN
ShinyHunters Vishing: 40 Million Records Stolen From Charter and 400 Organizations
ShinyHunters vishing SaaS extortion campaign confirmed Charter breach: 40M records stolen. Get TTPs, IOCs, and defensive steps now.
4/29/2026 · ACTIVE CAMPAIGN
ShinyHunters Hit Medtronic and ADT: 14.5M Records Stolen via AI Vishing and Salesforce
ShinyHunters stole 14.5M records from Medtronic and ADT this week using AI vishing to bypass MFA then pivoting through Salesforce. Here's how to protect your org now.
Not yet tracked for this actor
- CrowdStrike Falcon / SentinelOne Deep Visibility-specific query syntax — hunting queries above (if any) are Microsoft Defender/Sentinel KQL
- File transfer and exfiltration services used
- Hunting queries — no FalconFriday rule matched this actor's known techniques