Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: shinyhunters (53 articles)Clear

ShinyHunters claims FBI breach through Oracle PeopleSoft zero-day as agency stays silent

The extortion group ShinyHunters claimed on its dark web site that it breached the FBI and stole data on current and former employees and job applicants, naming Criminal Justice, HR, and Medlink services. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero-day to gain remote code execution and deface the FBI jobs site. The claim, first reported by 404 Media, is unverified, and the FBI has not confirmed any compromise. ShinyHunters framed it as retaliation for a May FBI advisory about its Canvas targeting, disputing those allegations and rejecting reported ties to the wider criminal collective. Treat the specifics as an attacker claim pending independent confirmation.

Check
Track independent confirmation before acting, and separately prioritize Oracle PeopleSoft patching and exposure review given repeated zero-day claims against that platform.
Affected
Internet-facing Oracle PeopleSoft deployments are the claimed entry point, so unpatched or exposed HR and applicant systems on that platform warrant urgent review.
Fix
Apply current PeopleSoft security fixes, restrict and monitor internet-facing instances, and wait for verified reporting before drawing conclusions about the FBI claim.

Voice phishing turns personal devices into a path to Microsoft 365 data

Researchers describe attackers using voice phishing calls to talk employees into granting access from their personal devices, then reaching Microsoft 365 and corporate data through the trust the user extends. The attackers do not hack the device; they convince the person, then use Microsoft's Graph API to identify valuable targets and pass access to extortion groups like ShinyHunters. Because the weakness is the user's decision rather than the hardware, banning personal devices would not stop it. The stronger defense is tightening identity and authentication and limiting what a compromised account can actually do, so that tricking one person yields far less to the attacker.

Check
Train staff to be suspicious of unsolicited support and IT calls that ask them to approve access or run steps, and verify such requests through a known internal channel before acting.
Affected
Organizations where employees can be socially engineered by phone into granting Microsoft 365 access from personal devices; attackers then use built-in cloud interfaces to find targets and hand access to extortion groups.
Fix
Enforce phishing-resistant authentication and conditional access, minimize standing privileges so a hijacked account does little, monitor Graph API and sign-in activity for abuse, and train users specifically against voice-based social engineering.

AdaptHealth breach tied to ShinyHunters exposes health data of 4.1 million

AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.

Check
Affected patients should watch for medical, insurance, and identity fraud and use the offered monitoring, and healthcare organizations should tighten third-party and contractor account access against social engineering.
Affected
About 4.1 million people whose names, contact details, and health and insurance information were exposed; the data supports targeted phishing and insurance fraud, and the contractor-account entry shows the third-party path.
Fix
Require phishing-resistant authentication and least privilege for contractors and third parties, monitor connected cloud apps for anomalous access, verify help-desk and account changes, and treat contractor accounts as a primary attack surface.

ShinyHunters claims theft of Florida driver records through a password-reset flaw

The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.

Check
Organizations with self-service password-reset flows should test them for account-takeover flaws, and agencies operating sensitive lookup systems should monitor for accounts enumerating records by ID and for logins from unexpected sources.
Affected
Government and law-enforcement lookup systems reachable with staff accounts; a password-reset weakness let attackers hijack employee and agent logins and mass-download driver records, exposing highly sensitive identity and vehicle data for extortion.
Fix
Harden password-reset and authentication flows, require phishing-resistant authentication for privileged lookup systems, alert on bulk record access and ID enumeration, limit how much any single account can pull, and verify breach claims.

ShinyHunters leaks Questel data taken through a vishing call into Microsoft 365

The extortion group ShinyHunters published data stolen from Questel, a French intellectual-property software and services firm, after a voice phishing call gave attackers access to a Sales SharePoint site in its Microsoft 365 environment. The group claimed more than 21 million records, but the published corpus verified out to about 1.2 million real email addresses, along with names, employers, job titles, physical addresses, and phone numbers, mostly corporate contacts from sales and marketing. Questel confirmed the unauthorized access but has not endorsed the larger figure. It is the same voice-phishing-into-connected-cloud pattern, and the same inflated-claim behavior, seen in other recent ShinyHunters cases.

Check
Harden identity and help desk processes against voice phishing, since a single tricked employee gave attackers access to a cloud collaboration site, and be skeptical of headline record counts in extortion claims.
Affected
Questel corporate contacts whose names, employers, titles, addresses, and phone numbers were leaked, about 1.2 million email addresses; the detailed business profiles support convincing targeted phishing despite the inflated original claim.
Fix
Adopt phishing-resistant authentication, train staff against vishing, tightly control access to Microsoft 365 sites like SharePoint, monitor for unusual data access, and verify breach claims before treating attacker figures as fact.

McKesson discloses breach as ShinyHunters claims 284 million patient records

Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, which the extortion group ShinyHunters claims exposed 284 million patient records. The group told reporters it broke in by voice-phishing two employees, then extracted data from the company's Salesforce and Snowflake environments, the same connected-app looting pattern it has used elsewhere. It claims deeply sensitive medical data was taken and says a roughly 55 million dollar ransom went unanswered. McKesson confirmed the incident in a regulatory filing but has not verified what was stolen, and the record count, like past ShinyHunters claims, may be inflated.

Check
Watch McKesson's official channels for confirmed details before acting on the 284 million figure, and if notified as affected, be alert to healthcare-themed phishing and identity theft using real medical details.
Affected
Patients and partners whose data McKesson handles, pending confirmation of scope; ShinyHunters claims names, Social Security numbers, and sensitive medical records were taken via phished access to Salesforce and Snowflake.
Fix
For organizations, harden connected SaaS like Salesforce and Snowflake against voice-phishing-led access with phishing-resistant authentication and tighter session controls, and verify large breach claims before treating headline numbers as confirmed.

ShinyHunters leaks Carhartt data, but half the records were synthetic test data

The extortion group ShinyHunters published data stolen from workwear maker Carhartt after the company refused a 3.3 million dollar ransom, but analysis showed the leak was smaller than it first appeared. The raw dump held nearly 25 million email addresses, yet breach-tracking service Have I Been Pwned found millions were synthetic records that matched no real people, leaving about 12.9 million genuine addresses along with names, phone numbers, and physical addresses. A researcher traced the data to Carhartt's customer analytics warehouse, contaminated with a standard retail benchmarking dataset used for testing. The detailed contact and identity profiles still create real risk of targeted phishing for those affected.

Check
Affected Carhartt customers should be alert to targeted phishing and scam calls using their real name, address, and phone number, and treat unexpected messages referencing recent orders with suspicion.
Affected
About 12.9 million Carhartt customers whose emails, names, phone numbers, and physical addresses were leaked; the detailed profiles support convincing phishing, even though millions of the leaked records were synthetic.
Fix
For defenders, verify breach claims before reacting since raw dumps can be inflated with synthetic data, and keep test and benchmark datasets out of production stores that hold real records.

Exact Sciences breach exposes data of nearly 11 million in extortion campaign

Data from a breach at cancer-screening company Exact Sciences, now part of Abbott, was indexed by Have I Been Pwned with about 10.9 million unique email addresses. The extortion group ShinyHunters claimed the intrusion, saying it reached internal legacy systems and then pivoted from a corporate single-sign-on account into connected cloud services such as Microsoft 365, Salesforce, and others to steal data. It is part of a wider ShinyHunters wave hitting medical-technology companies. Abbott is investigating and disputed the attacker's characterization of some data. The pattern, one stolen sign-on unlocking many linked services, is now a recurring route to large healthcare breaches.

Check
People who used Exact Sciences services should watch for breach notices and health-themed phishing, and organizations should map which cloud services a single corporate sign-on can unlock.
Affected
Roughly 11 million people whose data sat in Exact Sciences systems and connected cloud services; attackers used one corporate sign-on to reach linked platforms, a pattern behind repeated large medical breaches.
Fix
Enforce phishing-resistant MFA on single-sign-on, scope what each connected cloud app can access, monitor for bulk exports across integrated services, and prepare for extortion-driven leaks of healthcare data.

DentaQuest notifies more than 23 million people after a data theft attack

Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.

Check
People with DentaQuest or associated Medicaid or Medicare dental coverage should watch for a notification, enroll in the offered monitoring, consider a credit freeze, and be alert to health-themed phishing.
Affected
More than 23 million DentaQuest members whose names, Social Security numbers, government program identifiers, and dental and vision health records were exposed and leaked, supporting identity theft and targeted fraud.
Fix
Affected people should freeze credit and monitor benefits statements. Organizations holding health data should segment it, enforce phishing-resistant MFA, monitor for bulk data access, and prepare for extortion-driven leaks.

Glendale College breach exposes data on 793,000 students and applicants

Glendale Community College has had data on roughly 793,000 people exposed after the extortion group ShinyHunters stole files from its student information systems. Have I Been Pwned indexed 793,925 accounts, and the attackers claim to have taken more than 62GB across roughly 304,000 files, including student records with personal identifiers, financial aid exports, immunization logs, admission checklists, and transcripts dating back to 2020. The theft came from the college's PeopleSoft Campus Solutions environment, tying it to the wider ShinyHunters campaign against Oracle PeopleSoft that has hit numerous universities and companies. The breadth of academic and personal data raises the risk of identity theft and targeted phishing against students, applicants, and staff.

Check
People connected to Glendale Community College as students, applicants, or staff should watch for a breach notice, check Have I Been Pwned, monitor financial accounts, and be alert to college-themed phishing.
Affected
Around 793,000 Glendale Community College students, applicants, and staff whose personal, academic, financial aid, and health-related records were exposed; the depth of data supports identity theft and convincing targeted phishing.
Fix
Affected people should consider a credit freeze and monitor accounts. Organizations using Oracle PeopleSoft should apply its mitigations, review access logs, and enforce phishing-resistant MFA against this ongoing campaign.