Widely attributedUnknown

ShinyHunters

Financially motivated threat group known for large-scale data theft and extortion, responsible for numerous high-profile database breaches sold on criminal forums.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
17.1
High signal strength
Mentions33
Sources11
High conf.14
Last seenJun 2026
First observed
Last active
Origin
Aliases
2
Techniques
0
Campaigns
0
TargetsTechnologyRetailTelecommunications
RegionsGlobal

Attribution signals

33 mentions · 11 sources
#1attributed tohigh
Infrastructure
mandiant
May 2026

"The credential harvesting domains attributed to UNC6661 commonly, but not exclusively, use the format sso.com or internal.com and have often been registered with NICENIC."

#2claimed responsibilityhigh
Unspecified
checkpoint
May 2026

"ShinyHunters claimed responsibility and said it stole more than 600,000 Salesforce records containing personal and corporate information"

#3has continued to trackhigh
TTP matchVictimology
mandiant
May 2026

"GTIG has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand"

Campaign: BlackFile
#4high
Unspecified
security-affairs
May 2026
#5observedhigh
TTP match
mandiant
May 2026

"Mandiant has observed incidents where attackers impersonate support personnel from third-party vendors to gain access."

#6has been used byhigh
TTP match
eset
May 2026

"Technical controls such as detection of caller ID spoofing, and deepfake audio (which has been used by the ShinyHunters group)."

#7high
Infrastructure
krebs
May 2026
#8demonstratedhigh
Unspecified
dark-reading
May 2026

"In January 2026, the ShinyHunters threat group demonstrated a bypass technique that compromised authentication apps and tokens across more than 100 organizations"

#9assesseshigh
Victimology
mandiant
May 2026

"GTIG assesses that the group has targeted dozens of organizations across North America, Australia, and the UK."

Campaign: BlackFile
#10high
Unspecified
bleepingcomputer
May 2026
#11assesseshigh
InfrastructureTTP match
mandiant
May 2026

"GTIG assesses that the operations are independent."

Campaign: BlackFile
#12claimed responsibilityhigh
Unspecified
wired-security
May 2026

"Hackers using the name ShinyHunters claimed responsibility for the breach"

Hedge terms observed

allegedlyassessesattributed tobreachedclaimedclaimed byclaimed responsibilityclaimsconsistent withdemonstratedhas been used byhas continued to trackmay useobservedsufferedtrackingunspecifiedwill widely adopt