Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: extortion (25 articles)Clear

ShinyHunters claims FBI breach through Oracle PeopleSoft zero-day as agency stays silent

The extortion group ShinyHunters claimed on its dark web site that it breached the FBI and stole data on current and former employees and job applicants, naming Criminal Justice, HR, and Medlink services. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero-day to gain remote code execution and deface the FBI jobs site. The claim, first reported by 404 Media, is unverified, and the FBI has not confirmed any compromise. ShinyHunters framed it as retaliation for a May FBI advisory about its Canvas targeting, disputing those allegations and rejecting reported ties to the wider criminal collective. Treat the specifics as an attacker claim pending independent confirmation.

Check
Track independent confirmation before acting, and separately prioritize Oracle PeopleSoft patching and exposure review given repeated zero-day claims against that platform.
Affected
Internet-facing Oracle PeopleSoft deployments are the claimed entry point, so unpatched or exposed HR and applicant systems on that platform warrant urgent review.
Fix
Apply current PeopleSoft security fixes, restrict and monitor internet-facing instances, and wait for verified reporting before drawing conclusions about the FBI claim.

ShinyHunters leaks Carhartt data, but half the records were synthetic test data

The extortion group ShinyHunters published data stolen from workwear maker Carhartt after the company refused a 3.3 million dollar ransom, but analysis showed the leak was smaller than it first appeared. The raw dump held nearly 25 million email addresses, yet breach-tracking service Have I Been Pwned found millions were synthetic records that matched no real people, leaving about 12.9 million genuine addresses along with names, phone numbers, and physical addresses. A researcher traced the data to Carhartt's customer analytics warehouse, contaminated with a standard retail benchmarking dataset used for testing. The detailed contact and identity profiles still create real risk of targeted phishing for those affected.

Check
Affected Carhartt customers should be alert to targeted phishing and scam calls using their real name, address, and phone number, and treat unexpected messages referencing recent orders with suspicion.
Affected
About 12.9 million Carhartt customers whose emails, names, phone numbers, and physical addresses were leaked; the detailed profiles support convincing phishing, even though millions of the leaked records were synthetic.
Fix
For defenders, verify breach claims before reacting since raw dumps can be inflated with synthetic data, and keep test and benchmark datasets out of production stores that hold real records.

Exact Sciences breach exposes data of nearly 11 million in extortion campaign

Data from a breach at cancer-screening company Exact Sciences, now part of Abbott, was indexed by Have I Been Pwned with about 10.9 million unique email addresses. The extortion group ShinyHunters claimed the intrusion, saying it reached internal legacy systems and then pivoted from a corporate single-sign-on account into connected cloud services such as Microsoft 365, Salesforce, and others to steal data. It is part of a wider ShinyHunters wave hitting medical-technology companies. Abbott is investigating and disputed the attacker's characterization of some data. The pattern, one stolen sign-on unlocking many linked services, is now a recurring route to large healthcare breaches.

Check
People who used Exact Sciences services should watch for breach notices and health-themed phishing, and organizations should map which cloud services a single corporate sign-on can unlock.
Affected
Roughly 11 million people whose data sat in Exact Sciences systems and connected cloud services; attackers used one corporate sign-on to reach linked platforms, a pattern behind repeated large medical breaches.
Fix
Enforce phishing-resistant MFA on single-sign-on, scope what each connected cloud app can access, monitor for bulk exports across integrated services, and prepare for extortion-driven leaks of healthcare data.

Chipmaker Analog Devices confirms a breach and stolen files, says operations are fine

Analog Devices, a major US semiconductor maker, confirmed in a securities filing that an unauthorized party accessed some internal systems and exfiltrated files in a June intrusion, while saying operations were not affected. The company has not named who was responsible. Days before the filing, an extortion group calling itself ExfilSquad listed Analog Devices on its leak site and claimed to hold about 570,000 customer records with personal information and home addresses, but Analog Devices has not linked the June breach to that group, and the claim is unverified. The filing also noted a second, separate security issue unrelated to the June intrusion.

Check
Organizations that share data with Analog Devices should watch for a notification and monitor for phishing, while treating the extortion group's specific claims as unverified until the company confirms details.
Affected
Analog Devices and parties whose data sat in its systems; the company confirms files were stolen in June, while an extortion group's claim of 570,000 customer records with home addresses remains unverified.
Fix
Affected parties should watch for official notice and be alert to targeted phishing. Organizations should segment sensitive data, limit what vendors can reach, and prepare for extortion-driven leaks and unverified claims.

DentaQuest notifies more than 23 million people after a data theft attack

Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.

Check
People with DentaQuest or associated Medicaid or Medicare dental coverage should watch for a notification, enroll in the offered monitoring, consider a credit freeze, and be alert to health-themed phishing.
Affected
More than 23 million DentaQuest members whose names, Social Security numbers, government program identifiers, and dental and vision health records were exposed and leaked, supporting identity theft and targeted fraud.
Fix
Affected people should freeze credit and monitor benefits statements. Organizations holding health data should segment it, enforce phishing-resistant MFA, monitor for bulk data access, and prepare for extortion-driven leaks.

Mount Royal University confirms attackers stole and then deleted its files

Mount Royal University in Calgary has confirmed that attackers breached its network in June, stole data from its file storage systems, and then deleted the files to hinder recovery, as the hackers now publicly claim the attack. The intrusion, detected around June 18, disrupted phones, the university website, and other systems. The affected storage held academic material such as assignments and research, but the university acknowledges some students and staff may have kept personal information there, and a separate departmental drive was also wiped. Mount Royal is notifying affected individuals and offering credit monitoring to current and recent employees, though not to students.

Check
Students and staff of Mount Royal University should watch for a notification, take up offered credit monitoring where eligible, and stay alert to phishing referencing the university or their information.
Affected
Mount Royal University students and staff whose academic and possibly personal data sat on the affected drives; the attackers both stole the data and deleted it, complicating recovery and raising extortion pressure.
Fix
Maintain tested, offline backups so deleted data can be restored, segment and monitor file storage, enforce phishing-resistant MFA, and prepare incident-response and communication plans for attacks that both steal and destroy data.

ShinyHunters leaks Moody Bible Institute data on 2.3 million students and donors

The extortion group ShinyHunters has published data stolen from Moody Bible Institute, a Chicago-based Christian college, after a "pay or leak" campaign. Have I Been Pwned indexed more than 2.3 million unique email addresses along with names, physical addresses, phone numbers, and dates of birth belonging to students, alumni, donors, and supporters. ShinyHunters claimed a much larger haul spanning enrollment, donor, payroll, and communications systems, and some reporting ties the intrusion to the same ShinyHunters campaign that exploited an Oracle PeopleSoft flaw. Most of the leaked email addresses had already appeared in earlier breaches, raising the risk of credential stuffing and targeted phishing.

Check
People connected to Moody Bible Institute as students, alumni, donors, or staff should watch for a notification, be alert to phishing referencing the school, and check Have I Been Pwned.
Affected
Students, alumni, donors, and supporters of Moody Bible Institute whose contact details and dates of birth were exposed (over 2.3 million emails); the data supports credential stuffing and convincing phishing.
Fix
Affected people should reset any reused passwords, enable multi-factor authentication, and treat school-themed messages with caution. Organizations should secure SaaS and HR platforms, enforce MFA, and harden against social-engineering-driven data theft.

Medtronic notifies customers after ShinyHunters breach of corporate systems

Medical device maker Medtronic has begun notifying customers that their personal data was exposed in a breach of its corporate IT systems earlier this year, an attack claimed by the extortion group ShinyHunters. Medtronic noticed unusual activity in mid-April and its investigation found that an unauthorized actor had access between April 13 and 19. ShinyHunters claimed to hold roughly nine million records containing personal and internal corporate data, and Medtronic did not pay, with its listing later removed from the group's leak site. The company says its products, patient safety, and the networks running its medical devices were not affected, crediting separation between corporate and clinical systems.

Check
People who have dealt with Medtronic as customers, patients, providers, or partners should watch for their notification and stay alert to phishing or fraud that references Medtronic or medical accounts.
Affected
Individuals whose personal data sat in Medtronic's corporate IT systems, accessed between April 13 and 19; ShinyHunters claimed about nine million records, though device networks and patient safety were not affected.
Fix
Affected people should monitor for targeted phishing and identity fraud. Organizations should segment corporate IT from operational and clinical systems, harden SaaS and identity against social engineering, and enforce phishing-resistant MFA.

ShinyHunters leaks Sysco data with 2.7 million email addresses after extortion

Food distribution giant Sysco was hit by the extortion group ShinyHunters in a "pay or leak" attack, and after the company did not pay, the stolen data was published. Have I Been Pwned has indexed 2,691,852 unique email addresses belonging to staff and customers, alongside what is described as largely corporate contact information. The breach fits ShinyHunters' sweeping 2026 campaign against large enterprises, which has typically relied on social engineering and compromised SaaS integrations rather than software exploits. Exposed business contact data is useful for convincing, targeted phishing aimed at Sysco's staff, customers, and partners.

Check
People and businesses dealing with Sysco should check Have I Been Pwned for affected emails and stay alert to phishing or invoice fraud that references Sysco accounts, orders, or deliveries.
Affected
Sysco staff, customers, and partners whose email addresses and corporate contact details were exposed (2,691,852 indexed); the data supports targeted phishing and business email compromise against the food-distribution supply chain.
Fix
Treat unexpected Sysco-themed emails with caution, verify payment or account changes through known contacts, enable phishing-resistant MFA, and brief staff and partners on the heightened phishing risk from this exposure.

ShinyHunters leaks Madison Square Garden Sports data on nearly 10 million people

The extortion group ShinyHunters has published data stolen from Madison Square Garden Sports, owner of the New York Knicks and Rangers, after the company did not pay. Have I Been Pwned indexed 9,796,738 unique email addresses spanning staff and customers, alongside extensive personal, employment, and customer-relationship records including names, addresses, phone numbers, and some dates of birth. Reporting on the leak describes an internal "Talent" file profiling former players, executives' family members, and celebrities, in some cases with so-called threat assessments. The intrusion reportedly began with voice-phishing of staff, the same social-engineering pattern behind ShinyHunters' wider 2026 campaign against large enterprises.

Check
People who interacted with Madison Square Garden venues or teams should check Have I Been Pwned for their email and watch for targeted phishing or fraud referencing tickets, accounts, or events.
Affected
Staff and customers of Madison Square Garden Sports whose contact and personal data was exposed (9,796,738 emails); high-profile individuals named in internal files face heightened targeting and impersonation risk.
Fix
Reset and avoid reusing affected account passwords, enable phishing-resistant MFA, and stay alert to convincing phishing. Organizations should harden help desks against voice-phishing with strict caller-identity verification.