Skip to content

ShinyHunters

Ransomware Group2 claimsLast activity:

Overview

ShinyHunters is a financially motivated data-theft, data-brokerage and extortion brand active since at least 2020. Palo Alto Networks Unit 42 tracks related activity as Bling Libra and describes global theft and extortion across financial services, technology, hospitality, media, real estate, telecommunications and retail. The FBI separately describes ShinyHunters as a cybercriminal group specializing in large-scale breaches and extortion. Public reporting does not establish state sponsorship, and the brand does not necessarily identify one stable set of operators.

Activity and targeting

ShinyHunters-branded activity has targeted organizations across multiple industries and regions rather than a single sector. Unit 42 reports worldwide operations and publication of stolen data after failed extortion. A 2026 FBI public-service announcement highlights technology, finance and retail targeting and warns about education-sector exposure. These are documented patterns, not proof that every claimed victim or leak-site entry reflects a verified intrusion.

Google Threat Intelligence Group reported that 2026 activity expanded across cloud software and identity platforms. Its January analysis tracks several clusters associated with ShinyHunters-branded extortion, including UNC6661, UNC6671 and UNC6240, to account for evolving partnerships and possible impersonation. That structure cautions against treating every vendor cluster as a confirmed alias or every campaign as the work of identical operators.

Methods and operational characteristics

Observed access methods include stolen credentials, phishing, weak cloud configurations and social engineering. GTIG documented voice phishing in which callers impersonated IT staff, used victim-branded credential-harvesting pages, captured single-sign-on credentials and MFA codes, enrolled attacker devices and then exfiltrated data from SaaS applications. Extortion activity used payment demands, deadlines, proof samples, leak-site publication, employee harassment and, in some cases, reported DDoS pressure. The FBI also warns of threatening calls and texts, harassment, swatting and publication through Tor leak sites.

The brand has also been linked to direct vulnerability exploitation. In June 2026, Mandiant and GTIG attributed an Oracle PeopleSoft campaign to UNC6240/ShinyHunters. The activity exploited CVE-2026-35273 as a zero-day, used customized MeshCentral agents, mapped and moved through PeopleSoft infrastructure, staged data and correlated with publication on a ShinyHunters leak site. These operations centered on data theft and extortion; ShinyHunters branding does not by itself establish ransomware encryption.

What type of group is it?

ShinyHunters is best characterized as a financially motivated cybercrime and extortion brand. The reviewed sources support profit-driven data theft, public leaking and coercion rather than political or state-directed objectives. Attribution should remain campaign-specific: vendor labels such as Bling Libra and UNC designations organize observed activity, but current reporting also describes multiple clusters, partnerships and possible impersonation. They should not be treated as definitive proof of a single enduring organization behind every ShinyHunters claim.

Incident claims

NAIC PeopleSoft incident disrupts insurer designations

Incident date: Source: ransomware.livePublished: Discovered:

Claim details

ShinyHunters claimed on its leak site that it obtained and published more than 3.1 TB of NAIC.org data. NAIC confirmed publication by the responsible party but did not publicly name the group or validate the claimed volume.

Impacted organizations

Impacted locations

Sources