#shinyhunters

[ follow ]
fromSecurityWeek
17 hours ago

Hackers Leak 5.1 Million Panera Bread Records

The ShinyHunters extortion group has claimed the theft of roughly 14 million records from Panera Bread, after compromising a Microsoft Entra single-sign-on (SSO) code. The attack falls in line with recent ShinyHunters attacks that rely on voice phishing (vishing) and SSO authentication to access victim organizations' cloud-based software-as-a-service (SaaS) environments. Last week, ShinyHunters published on its Tor-based leak site a 760GB archive allegedly containing the sensitive information stolen from Panera Bread.
Information security
#vishing
#data-breach
Music
fromTechRepublic
1 month ago

SoundCloud Cyberattack Leaves 28M Users Exposed - TechRepublic

Cybercriminals breached SoundCloud's ancillary dashboard, accessing data from about 28 million accounts, exposing emails and public profile details enabling phishing risks.
Privacy professionals
fromTechzine Global
1 month ago

Data of 21,000 Nissan customers leaked via Red Hat

Nissan customer data for about 21,000 people was exposed due to a Red Hat breach, revealing names, addresses, phones, and emails; no financial data exposed.
fromDataBreaches.Net
1 week ago

ShinyHunters claim to be behind SSO-account data theft attacks - DataBreaches.Net

The ShinyHunters extortion gang claims it is behind a wave of ongoing voice phishing attacks targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google, enabling threat actors to breach corporate SaaS platforms and steal company data for extortion. In these attacks, threat actors impersonate IT support and call employees, tricking them into entering their credentials and multi-factor authentication (MFA) codes on phishing sites that impersonate company login portals.
Information security
fromTechzine Global
6 days ago

Nearly 30 million SoundCloud accounts affected by data breach

A data breach at SoundCloud that came to light in December 2025 is now becoming clearer. The data breach monitor Have I Been Pwned added the leaked dataset to its database this week, revealing the true extent of the impact. SoundCloud is a global audio platform where artists and listeners come together and where hundreds of millions of music and audio tracks are hosted.
Information security
Information security
fromTheregister
1 week ago

Canva among ~100 ShinyHunters credential-theft targets

ShinyHunters targeted about 100 Okta SSO accounts, using voice‑phishing to steal credentials, enroll attacker devices in MFA, and pivot into SaaS to exfiltrate data.
Information security
fromDataBreaches.Net
1 week ago

ShinyHunters claim to be behind SSO-account data theft attacks - DataBreaches.Net

Voice phishing targeting Okta, Microsoft, and Google SSO lets attackers bypass MFA, access corporate SaaS platforms, and steal company data for extortion.
fromDataBreaches.Net
1 week ago

France's Waltio faces ransom threat from notorious hacker collective - DataBreaches.Net

Waltio, a French crypto tax platform, is under siege from ShinyHunters, a notorious ransomware group claiming to hold the personal data of nearly 50,000 users.
Information security
#okta
fromDataBreaches.Net
1 week ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

fromwww.theguardian.com
1 month ago

The Com: the growing cybercrime network behind recent Pornhub hack

Ransomware hacks, data theft, crypto scams and sextortion cover a broad range of cybercrimes carried out by an equally varied list of assailants. But there is also an English-speaking criminal ecosystem carrying out these activities that defies conventional categorisation. Nonetheless, it does have a name: the Com. Short for community, the Com is a loose affiliation of cyber-criminals, largely native English language speakers typically aged from 16 to 25.
Information security
#gainsight
fromThe Hacker News
2 months ago
Information security

Gainsight Expands Impacted Customer List Following Salesforce Security Alert

Gainsight reports more customers affected by suspicious activity; Salesforce revoked tokens and multiple vendors disabled integrations while investigations and IoC disclosures proceed.
fromTheregister
2 months ago
Information security

Gainsight CEO: only a 'handful' of customers' data stolen

Gainsight reports only a handful of customers affected by a Salesforce-related breach, while external analysts believe over 200 Salesforce instances were potentially impacted.
Information security
fromTheregister
2 months ago

Salesforce flags another third-party security incident

Gainsight-published applications' compromised external connections allowed unauthorized access to some customers' Salesforce data; Salesforce revoked tokens and removed apps from AppExchange.
#salesforce
fromTechCrunch
2 months ago
Information security

Salesforce says some of its customers' data was accessed after Gainsight breach | TechCrunch

fromTechCrunch
2 months ago
Information security

Salesforce says some of its customers' data was accessed after Gainsight breach | TechCrunch

Information security
fromDataBreaches.Net
3 months ago

Legal Aid Agency chief admits difficulties understanding impact of cyberattack - DataBreaches.Net

The Legal Aid Agency continues to assess a widespread cyberattack detected in spring; analysts are reconstructing compromised applicant data and work may take weeks.
fromDataBreaches.Net
3 months ago

An arrested man's lawyer claims his client can't be ShinyHunters' leader. His argument wasn't persuasive. - DataBreaches.Net

During the conference, Branco: argued that those arrested were young autistic people who were very technically talented and could be of great benefit to their country, but instead they had been arrested and could be going away for 20 years. claimed that Kering and LVMH, two victims of attacks, had pressured the French government to make arrests. claimed that French law enforcement was taking orders/direction from the FBI.
France news
Information security
fromDataBreaches.Net
3 months ago

Oracle silently fixes zero-day exploit leaked by ShinyHunters - DataBreaches.Net

Oracle patched a remotely exploitable E-Business Suite vulnerability (CVE-2025-61884) that was actively exploited and had a leaked proof-of-concept.
Information security
fromSFGATE
4 months ago

SF tech giant hit with 14 lawsuits in rapid succession

Hackers used social-engineering to authorize malicious connected apps in Salesforce accounts, exfiltrating customer data and triggering multiple lawsuits alleging inadequate platform security.
Information security
fromEntrepreneur
4 months ago

Stellantis Data Breach Affects Millions of Car Buyers: Report | Entrepreneur

Stellantis experienced unauthorized access to a third-party North America customer service platform exposing contact information of potentially over 18 million customers; financial data not compromised.
#scattered-spider
Information security
fromDataBreaches.Net
4 months ago

When "Goodbye" isn't the end: Scattered LAPSUS$ Hunters hack on - DataBreaches.Net

Some cybercriminals claimed retirement while others continue exploiting vulnerabilities, indicating ongoing attacks despite farewell messages.
#kering
fromDataBreaches.Net
4 months ago
Information security

Update: Kering confirms Gucci and other brands hacked; claims no conversations with hackers? - DataBreaches.Net

fromDataBreaches.Net
4 months ago
Information security

Exclusive: High-end fashion retailers Gucci, Balenciaga, Brioni, and Alexander McQueen hit by Salesforce attacks - DataBreaches.Net

fromDataBreaches.Net
4 months ago
Information security

Update: Kering confirms Gucci and other brands hacked; claims no conversations with hackers? - DataBreaches.Net

fromDataBreaches.Net
4 months ago
Information security

Exclusive: High-end fashion retailers Gucci, Balenciaga, Brioni, and Alexander McQueen hit by Salesforce attacks - DataBreaches.Net

Information security
fromMail Online
5 months ago

Major data breach at credit giant exposes 4.4 million Americans' data

TransUnion suffered a data breach exposing personal information, including Social Security numbers, of over 4.4 million U.S. consumers.
Information security
fromApp Developer Magazine
1 year ago

Salesforce breach let hackers steal Google customer data

A Google corporate Salesforce instance was breached by UNC6040, exposing basic business contact data, prompting impact analysis and mitigation while extortion campaigns (UNC6240/ShinyHunters) emerged.
Information security
fromMail Online
5 months ago

Mother of all Google breaches puts all 2.5b Gmail users at risk

A breach of a Google Salesforce-managed database exposed contact data for 2.5 billion Gmail users, enabling scammers to attempt account hijacking through vishing and phishing.
#google
fromTechCrunch
5 months ago
Privacy professionals

Google says hackers stole its customers' data in a breach of its Salesforce database | TechCrunch

fromTechCrunch
5 months ago
Privacy professionals

Google says hackers stole its customers' data in a breach of its Salesforce database | TechCrunch

[ Load more ]