ShinyHunters
MITRE ATT&CK: G1057 View on attack.mitre.org
Aliases: ShinyHunters, UNC6240, Bling Libra
- First seen
- 2020-05-09 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-08-15 03:00:03
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications
Context
ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. ShinyHunters has been associated with the broader collective called The Community, also known as The Com whose members have also included Scattered Spider and LAPSUS$. Public reporting has mentioned a variety of names for operations ShinyHunters members have reportedly conducted with members of other groups, including “Scattered Lapsus Hunters,” “Scattered Lapsus Shiny Hunters,” and “SLSH.”(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)(Citation: SOCRadar_ShinyHunters_Mar2024)(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)(Citation: Intel471_SH_Aug2021)(Citation: FBI_SHLMS_May2026)(Citation: Google_SHOracle_Jun2026)(Citation: Mandiant_SHDataTheft_Jan2026)(Citation: Google Salesforce JUN 2025)
Malware & tools used
- Tor (malware)
Reports & references
- cyberwarzone.com — Shinyhunters 22 Year Old Member Pleads Guilty To Cyber Extortion Causing 6 Million In Damage (report)
- bitdefender.com — Pizza Hut Australia Leaks One Million Customers Details Claims Shinyhunters Hacking Group (report)
- justice.gov — Alleged French Cybercriminal Appear Seattle Indictment Conspiracy Computer Intrusion (report)
- cloud.google.com — Voice Phishing Data Extortion (report)
- cloud.google.com — Expansion Shinyhunters Saas Data Theft (report)
- MITRE ATT&CK — G1057 (report)
- blog.eclecticiq.com — Shinyhunters Calling Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications (report)
- cloud.google.com — Shinyhunters Targets Education Sector Oracle Exploit (report)
- socradar.io — Dark Web Profile Shinyhunters (report)
- Palo Alto Unit 42 — Shinyhunters Ransomware Extortion (report)
- ic3.gov — Psa260515 (report)
- intel471.com — Shinyhunters Data Breach Mitre Attack (report)