#shinyhunters

[ follow ]
#cybersecurity
Privacy professionals
fromTheregister
1 week ago

Burglar alarm biz gets burgled, ShinyHunters pursues ransom

ADT confirmed a cyber intrusion by ShinyHunters, claiming over 10 million records were stolen, while ADT reported a limited data breach.
Information security
fromTNW | Eu
1 month ago

European Commission breached after hackers poisoned open-source security tool Trivy

A major data breach at the European Commission was caused by TeamPCP exploiting a supply chain attack on the Trivy security tool.
Information security
fromTechRepublic
2 days ago

Canvas Breach May Put 275M Users, 9,000 Schools at Risk

Instructure confirmed a Canvas breach affecting user information and messages, with hackers claiming 275 million users and nearly 9,000 schools impacted.
Privacy professionals
fromTheregister
1 week ago

Burglar alarm biz gets burgled, ShinyHunters pursues ransom

ADT confirmed a cyber intrusion by ShinyHunters, claiming over 10 million records were stolen, while ADT reported a limited data breach.
Information security
fromTNW | Eu
1 month ago

European Commission breached after hackers poisoned open-source security tool Trivy

A major data breach at the European Commission was caused by TeamPCP exploiting a supply chain attack on the Trivy security tool.
#data-breach
fromTechCrunch
1 day ago
Privacy professionals

Hackers steal students' data during breach at education tech giant Instructure | TechCrunch

Privacy professionals
fromTechCrunch
1 day ago

Hackers steal students' data during breach at education tech giant Instructure | TechCrunch

Instructure confirmed a data breach involving students' private information, claimed by the hacking group ShinyHunters.
Information security
fromTheregister
1 day ago

Cushman & Wakefield confirms vishing cyberattack

Cushman & Wakefield confirmed a data breach caused by vishing, with two cybercrime groups claiming responsibility for separate attacks.
Privacy professionals
fromTechzine Global
2 days ago

ShinyHunters claims Instructure breach, data from 275M users stolen

Instructure confirmed a data breach affecting personal data of users, with claims of 275 million individuals' data stolen by the ShinyHunters group.
#cyberattack
Information security
fromSecurityWeek
2 days ago

Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats

Instructure faced a cyberattack leading to a data breach, affecting personal information of millions in the education sector.
Information security
fromSecurityWeek
1 week ago

Vimeo Confirms User and Customer Data Breach

Vimeo confirmed a data breach involving user data theft through a third-party vendor, but no video content or payment information was compromised.
Privacy professionals
fromSecurityWeek
1 week ago

Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak

Medtronic confirmed a hack by ShinyHunters, claiming millions of records were stolen, but asserts no impact on patient safety or operations.
Privacy professionals
fromTheregister
1 week ago

ShinyHunters claim they have cruise giant Carnival's booty

Carnival Corporation faces a significant data breach involving 7.5 million email addresses linked to its Mariner Society loyalty program.
#vercel
Information security
fromTechRepublic
2 weeks ago

Vercel Confirms Major Security Incident as Hacker Claims $2M Ransom Demand

Vercel confirmed a security incident involving unauthorized access to internal systems, with a threat actor claiming to sell stolen company data.
fromTechCrunch
2 weeks ago
Information security

App host Vercel confirms security incident, says customer data was stolen via breach at Context AI | TechCrunch

fromInfoWorld
2 weeks ago
Information security

Hackers exploit Vercel's trust in AI integration

Sensitive secrets should be treated as potentially exposed and rotated as a priority.
fromThe Verge
2 weeks ago
Information security

Cloud development platform Vercel was hacked

Vercel experienced a security breach due to a compromised third-party AI tool, leading to the exposure of customer data.
Information security
fromTechRepublic
2 weeks ago

Vercel Confirms Major Security Incident as Hacker Claims $2M Ransom Demand

Vercel confirmed a security incident involving unauthorized access to internal systems, with a threat actor claiming to sell stolen company data.
Information security
fromTechCrunch
2 weeks ago

App host Vercel confirms security incident, says customer data was stolen via breach at Context AI | TechCrunch

Vercel experienced a data breach due to a compromised employee account linked to Context AI, exposing customer credentials.
Information security
fromTechRepublic
2 weeks ago

McGraw-Hill Confirms Data Exposure, Hackers Claim 45M Salesforce Records Leaked

Unauthorized access to limited internal data at McGraw-Hill was linked to a Salesforce misconfiguration, raising concerns about potential identity fraud and harassment.
Privacy professionals
fromKotaku
3 weeks ago

GTA 6 Hackers Say They Will Release The Breached Data After Ransom Demands Not Met - Kotaku

ShinyHunters plans to publish stolen data from Rockstar after ransom demands were not met.
#rockstar-games
Information security
fromKotaku
3 weeks ago

GTA 6 Developer Rockstar Reportedly Hacked, Data Being Ransomed

ShinyHunters claims to have breached Rockstar Games' cloud servers, demanding ransom by April 14 or threatening to leak corporate data.
Information security
fromSecurityWeek
1 month ago

Hundreds of Salesforce Customers Allegedly Targeted in New Data Theft Campaign

ShinyHunters targets Salesforce instances through social engineering and misconfiguration exploitation, not platform vulnerabilities, prompting Salesforce warnings about overly permissive guest user settings.
Canada news
fromTheregister
2 months ago

Canada Goose says ShinyHunters only breached old data

A historical dataset of over 600,000 Canada Goose customer records was published online, but there is no current evidence of a breach of company systems.
Information security
fromTechRepublic
8 months ago

Workday Hit by Social Engineering Attack, Third-Party Data Exposed

A social engineering attack gave attackers access to a third-party CRM, exposing business contact details while Workday's customer tenants and stored data remained uncompromised.
fromTheregister
2 months ago

Betterment breach scope pegged at 1.4M users

Betterment, which offers automated investment and financial planning services, first disclosed the breach in January after detecting unauthorized access to certain internal systems on January 9. Betterment said the hacker gained entry through a social engineering scheme that relied on impersonation to infiltrate third-party marketing and operations tools, then used that access to send customers a fraudulent cryptocurrency promotion disguised as an official company message.
Information security
fromSecurityWeek
3 months ago

Hackers Leak 5.1 Million Panera Bread Records

The ShinyHunters extortion group has claimed the theft of roughly 14 million records from Panera Bread, after compromising a Microsoft Entra single-sign-on (SSO) code. The attack falls in line with recent ShinyHunters attacks that rely on voice phishing (vishing) and SSO authentication to access victim organizations' cloud-based software-as-a-service (SaaS) environments. Last week, ShinyHunters published on its Tor-based leak site a 760GB archive allegedly containing the sensitive information stolen from Panera Bread.
Information security
#vishing
fromDataBreaches.Net
3 months ago

ShinyHunters claim to be behind SSO-account data theft attacks - DataBreaches.Net

The ShinyHunters extortion gang claims it is behind a wave of ongoing voice phishing attacks targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google, enabling threat actors to breach corporate SaaS platforms and steal company data for extortion. In these attacks, threat actors impersonate IT support and call employees, tricking them into entering their credentials and multi-factor authentication (MFA) codes on phishing sites that impersonate company login portals.
Information security
fromTechzine Global
3 months ago

Nearly 30 million SoundCloud accounts affected by data breach

A data breach at SoundCloud that came to light in December 2025 is now becoming clearer. The data breach monitor Have I Been Pwned added the leaked dataset to its database this week, revealing the true extent of the impact. SoundCloud is a global audio platform where artists and listeners come together and where hundreds of millions of music and audio tracks are hosted.
Information security
Information security
fromTheregister
3 months ago

Canva among ~100 ShinyHunters credential-theft targets

ShinyHunters targeted about 100 Okta SSO accounts, using voice‑phishing to steal credentials, enroll attacker devices in MFA, and pivot into SaaS to exfiltrate data.
Information security
fromDataBreaches.Net
3 months ago

ShinyHunters claim to be behind SSO-account data theft attacks - DataBreaches.Net

Voice phishing targeting Okta, Microsoft, and Google SSO lets attackers bypass MFA, access corporate SaaS platforms, and steal company data for extortion.
fromDataBreaches.Net
3 months ago

France's Waltio faces ransom threat from notorious hacker collective - DataBreaches.Net

Waltio, a French crypto tax platform, is under siege from ShinyHunters, a notorious ransomware group claiming to hold the personal data of nearly 50,000 users.
Information security
#okta
fromDataBreaches.Net
3 months ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

fromDataBreaches.Net
3 months ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

fromwww.theguardian.com
4 months ago

The Com: the growing cybercrime network behind recent Pornhub hack

Ransomware hacks, data theft, crypto scams and sextortion cover a broad range of cybercrimes carried out by an equally varied list of assailants. But there is also an English-speaking criminal ecosystem carrying out these activities that defies conventional categorisation. Nonetheless, it does have a name: the Com. Short for community, the Com is a loose affiliation of cyber-criminals, largely native English language speakers typically aged from 16 to 25.
Information security
#gainsight
Information security
fromTheregister
5 months ago

Salesforce flags another third-party security incident

Gainsight-published applications' compromised external connections allowed unauthorized access to some customers' Salesforce data; Salesforce revoked tokens and removed apps from AppExchange.
#salesforce
fromTechCrunch
5 months ago
Information security

Salesforce says some of its customers' data was accessed after Gainsight breach | TechCrunch

fromTechCrunch
5 months ago
Information security

Salesforce says some of its customers' data was accessed after Gainsight breach | TechCrunch

fromDataBreaches.Net
6 months ago

An arrested man's lawyer claims his client can't be ShinyHunters' leader. His argument wasn't persuasive. - DataBreaches.Net

During the conference, Branco: argued that those arrested were young autistic people who were very technically talented and could be of great benefit to their country, but instead they had been arrested and could be going away for 20 years. claimed that Kering and LVMH, two victims of attacks, had pressured the French government to make arrests. claimed that French law enforcement was taking orders/direction from the FBI.
France news
Information security
fromDataBreaches.Net
6 months ago

Oracle silently fixes zero-day exploit leaked by ShinyHunters - DataBreaches.Net

Oracle patched a remotely exploitable E-Business Suite vulnerability (CVE-2025-61884) that was actively exploited and had a leaked proof-of-concept.
Information security
fromSFGATE
7 months ago

SF tech giant hit with 14 lawsuits in rapid succession

Hackers used social-engineering to authorize malicious connected apps in Salesforce accounts, exfiltrating customer data and triggering multiple lawsuits alleging inadequate platform security.
Information security
fromEntrepreneur
7 months ago

Stellantis Data Breach Affects Millions of Car Buyers: Report | Entrepreneur

Stellantis experienced unauthorized access to a third-party North America customer service platform exposing contact information of potentially over 18 million customers; financial data not compromised.
#scattered-spider
Information security
fromDataBreaches.Net
7 months ago

When "Goodbye" isn't the end: Scattered LAPSUS$ Hunters hack on - DataBreaches.Net

Some cybercriminals claimed retirement while others continue exploiting vulnerabilities, indicating ongoing attacks despite farewell messages.
#kering
fromDataBreaches.Net
7 months ago
Information security

Update: Kering confirms Gucci and other brands hacked; claims no conversations with hackers? - DataBreaches.Net

fromDataBreaches.Net
7 months ago
Information security

Exclusive: High-end fashion retailers Gucci, Balenciaga, Brioni, and Alexander McQueen hit by Salesforce attacks - DataBreaches.Net

fromDataBreaches.Net
7 months ago
Information security

Update: Kering confirms Gucci and other brands hacked; claims no conversations with hackers? - DataBreaches.Net

fromDataBreaches.Net
7 months ago
Information security

Exclusive: High-end fashion retailers Gucci, Balenciaga, Brioni, and Alexander McQueen hit by Salesforce attacks - DataBreaches.Net

Information security
fromMail Online
8 months ago

Major data breach at credit giant exposes 4.4 million Americans' data

TransUnion suffered a data breach exposing personal information, including Social Security numbers, of over 4.4 million U.S. consumers.
Information security
fromApp Developer Magazine
1 year ago

Salesforce breach let hackers steal Google customer data

A Google corporate Salesforce instance was breached by UNC6040, exposing basic business contact data, prompting impact analysis and mitigation while extortion campaigns (UNC6240/ShinyHunters) emerged.
Information security
fromMail Online
8 months ago

Mother of all Google breaches puts all 2.5b Gmail users at risk

A breach of a Google Salesforce-managed database exposed contact data for 2.5 billion Gmail users, enabling scammers to attempt account hijacking through vishing and phishing.
fromTechzine Global
8 months ago

More details revealed about Salesforce leak at Google

The incident involved unauthorized access to a limited set of data from a Google business Salesforce instance including company names, phone numbers, and internal notes.
Privacy professionals
[ Load more ]