Tag: shinyhunters
92 articles

ADT Confirms Cyber Intrusion After ShinyHunters Extortion Attempt
ADT confirmed a cyber intrusion on April 20, swiftly isolating the breach and collaborating with incident responders and law enforcement to contain the damage. The compromised data included sensitive information like names, phone numbers, and addresses, as well as dates of birth and partial Social Security numbers for a smaller subset of individuals.

ADT Confirms Data Breach After ShinyHunters Extortion Threat
ADT confirmed a data breach after a threat from hackers known as ShinyHunters, who demanded an extortion payment. The breach exposed sensitive customer info, including names, phone numbers, addresses, and in some cases, dates of birth and Social Security numbers.

Carnival Breach Exposes 7.5M Emails in Alleged ShinyHunters Hack
A massive data breach at Carnival Corporation has exposed a whopping 7.5 million emails, allegedly at the hands of the notorious ShinyHunters hack group, after failed negotiations between the two parties left customers' sensitive information vulnerable. The breach is said to have yielded terabytes of internal corporate data, sparking concerns for customers and the company behind Holland America Line.

McGraw Hill Breach Exposes 13.5 Million User Accounts
A massive data breach at McGraw Hill has exposed the personal and academic records of 13.5 million students and educators, leaving them vulnerable to exploitation by the ShinyHunters extortion group. The breach, which targeted McGraw Hill's Salesforce environment, has raised urgent concerns about digital security and data protection in the education sector.

Rockstar Games Data Breach Exposes Sensitive Analytics Information
Rockstar Games has suffered a data breach, with sensitive analytics information - including insights into the behavior of millions of players - leaked by the ShinyHunters extortion gang on a criminal site. The breach is linked to a recent security incident at Anodot, a company used by Rockstar Games.

Rockstar Games Data Breached as ShinyHunters Exploits Third-Party Vulnerability
Rockstar Games has been hit by a data breach, with a notorious hacking group called ShinyHunters claiming it accessed sensitive information through a vulnerability in a third-party tool, rather than a complex hack. The group says it simply walked through an open door, exploiting access to Snowflake metrics to get to the data.

Critical Threat: Alarming Rise of Scattered Lapsus ShinyHunters Extortion Tactics
Scattered Lapsus ShinyHunters, a notorious data ransom gang, is taking extortion to a disturbing new level, using aggressive tactics that threaten not just companies, but also the safety and well-being of executives and their families. Their playbook of harassment, intimidation, and manipulation has raised the alarm among experts, who warn that it's only a matter of time before someone gets hurt.

Europa EU Data Breach Reveals Alarming Cybersecurity Gaps
The recent data breach on Europa.eu, claimed by the notorious ShinyHunters gang, exposes a harsh truth: even the most secure systems can be vulnerable, putting sensitive user data at risk. With personal info like names, emails, and phone numbers potentially compromised, the European Commission's swift response and investigation are crucial to mitigating the damage.

KrebsOnSecurity.com Exclusive: Best Security Insights at 16
For its 16th year, KrebsOnSecurity pulls back the curtain on how organized extortion rings, DDoS‑for‑hire botnets and scaled social‑engineering tradecraft turned lone hackers into multimillion‑dollar criminal businesses.

Scattered Spider Exclusive: Dangerous Unified Collective
Imagine low‑tech social engineering and SIM swaps teaming up with mass data brokers — that’s Scattered Spider, ShinyHunters and LAPSUS$ fusing tactics to turn bulk theft into pinpoint extortion. Security teams and cloud customers now face a hybrid, high‑leverage threat targeting SaaS platforms like Salesforce.

ShinyHunters Exclusive: Damaging Corporate Extortion Wave
The ShinyHunters campaign has escalated from quiet database dumps to brazen public extortion—naming victims, posting timetables, and using voice‑phishing plus massive file thefts that could turn single breaches into a supply‑chain crisis. Corporations now face a stark choice: pay ransoms or risk a public dump of sensitive customer and corporate data.

ShinyHunters Orchestrate Widespread Corporate Extortion
ShinyHunters have kicked off a sweeping campaign of corporate extortion—leaking stolen data and demanding ransoms—so read on to see how companies are fighting back and what it means for you.

ShinyHunters extortion: Stunning Risky Corporate Threat
Imagine waking up to find your company’s secrets posted online unless you pay up — that’s the stark reality dozens of firms now face after ShinyHunters launched a brazen public extortion site. This escalation — tied to prior Salesforce, Discord, and Red Hat breaches — raises the stakes for stronger security, faster incident response, and clearer vendor transparency.

ShinyHunters Exclusive: Dangerous Corporate Extortion
ShinyHunters has escalated from voice‑phishing to a public extortion site threatening to dump data from dozens of Fortune 500 companies. That shift puts customers and companies at risk and makes strengthening human‑centric defenses and zero‑trust controls urgently necessary.

Gucci and Alexander McQueen: Exclusive Risky Data Breach
Luxury shoppers were jolted this week after a reported breach tied to ShinyHunters exposed millions of email addresses linked to Gucci and Alexander McQueen. Change your passwords, enable MFA, and watch for phishing while the brands investigate and disclose what was taken.

Allianz Life data breach: Stunning Risky Fallout
About 1.1 million Allianz Life customers may have had personal data exposed in a breach tied to the ShinyHunters group — here’s what to watch for and the quick steps you can take now to protect your identity and finances.

Workday CRM breach: Stunning Critical Risk Revealed
Workday says attackers accessed vendor-run CRM tools that support its customers, potentially exposing contact and support data — a stark reminder that even trusted platforms can be vulnerable through third-party integrations. If you use Workday, assume elevated risk, tighten vendor controls, and watch for suspicious communications while the investigation continues.

data extortion: Stunning, Dangerous Cloud Threat
ShinyHunters and Scattered Spider have shifted from stealing and selling data to brazenly extorting Salesforce customers, combining mass-data access with hands-on intrusion to squeeze ransoms out of enterprises. If this hybrid tactic spreads to financial and tech-service providers, it could seriously amplify risk across industries—time to lock down identities, APIs, and incident playbooks.

cybercrime collectives: Stunning Risky Alliance Revealed
If Scattered Spider, ShinyHunters and Lapsus$ are really trading tips and trophies in a shared Telegram channel, defenders could face faster, smarter attacks. Now’s the time to harden defenses—MFA, rapid patching, and better intel-sharing—before their bragging turns into your breach.

ShinyHunters cybercrime group: Critical Exclusive Threat
When your bank calls about a transaction you didn’t make, it’s a stark reminder that the ShinyHunters cybercrime group is now homing in on banks, fintechs and their vendors to harvest credentials and personal data for large-scale fraud. Institutions must act fast—tightening credential defenses, shoring up vendor security, and boosting detection—to protect customers, reputation and regulatory standing.