The extortion group ShinyHunters claimed on its dark web site that it breached the FBI and stole data on current and former employees and job applicants, naming Criminal Justice, HR, and Medlink services. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero-day to gain remote code execution and deface the FBI jobs site. The claim, first reported by 404 Media, is unverified, and the FBI has not confirmed any compromise. ShinyHunters framed it as retaliation for a May FBI advisory about its Canvas targeting, disputing those allegations and rejecting reported ties to the wider criminal collective. Treat the specifics as an attacker claim pending independent confirmation.
Researchers describe attackers using voice phishing calls to talk employees into granting access from their personal devices, then reaching Microsoft 365 and corporate data through the trust the user extends. The attackers do not hack the device; they convince the person, then use Microsoft's Graph API to identify valuable targets and pass access to extortion groups like ShinyHunters. Because the weakness is the user's decision rather than the hardware, banning personal devices would not stop it. The stronger defense is tightening identity and authentication and limiting what a compromised account can actually do, so that tricking one person yields far less to the attacker.
AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.
The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.
The extortion group ShinyHunters published data stolen from Questel, a French intellectual-property software and services firm, after a voice phishing call gave attackers access to a Sales SharePoint site in its Microsoft 365 environment. The group claimed more than 21 million records, but the published corpus verified out to about 1.2 million real email addresses, along with names, employers, job titles, physical addresses, and phone numbers, mostly corporate contacts from sales and marketing. Questel confirmed the unauthorized access but has not endorsed the larger figure. It is the same voice-phishing-into-connected-cloud pattern, and the same inflated-claim behavior, seen in other recent ShinyHunters cases.
Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, which the extortion group ShinyHunters claims exposed 284 million patient records. The group told reporters it broke in by voice-phishing two employees, then extracted data from the company's Salesforce and Snowflake environments, the same connected-app looting pattern it has used elsewhere. It claims deeply sensitive medical data was taken and says a roughly 55 million dollar ransom went unanswered. McKesson confirmed the incident in a regulatory filing but has not verified what was stolen, and the record count, like past ShinyHunters claims, may be inflated.
The extortion group ShinyHunters published data stolen from workwear maker Carhartt after the company refused a 3.3 million dollar ransom, but analysis showed the leak was smaller than it first appeared. The raw dump held nearly 25 million email addresses, yet breach-tracking service Have I Been Pwned found millions were synthetic records that matched no real people, leaving about 12.9 million genuine addresses along with names, phone numbers, and physical addresses. A researcher traced the data to Carhartt's customer analytics warehouse, contaminated with a standard retail benchmarking dataset used for testing. The detailed contact and identity profiles still create real risk of targeted phishing for those affected.
Data from a breach at cancer-screening company Exact Sciences, now part of Abbott, was indexed by Have I Been Pwned with about 10.9 million unique email addresses. The extortion group ShinyHunters claimed the intrusion, saying it reached internal legacy systems and then pivoted from a corporate single-sign-on account into connected cloud services such as Microsoft 365, Salesforce, and others to steal data. It is part of a wider ShinyHunters wave hitting medical-technology companies. Abbott is investigating and disputed the attacker's characterization of some data. The pattern, one stolen sign-on unlocking many linked services, is now a recurring route to large healthcare breaches.
Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.
Glendale Community College has had data on roughly 793,000 people exposed after the extortion group ShinyHunters stole files from its student information systems. Have I Been Pwned indexed 793,925 accounts, and the attackers claim to have taken more than 62GB across roughly 304,000 files, including student records with personal identifiers, financial aid exports, immunization logs, admission checklists, and transcripts dating back to 2020. The theft came from the college's PeopleSoft Campus Solutions environment, tying it to the wider ShinyHunters campaign against Oracle PeopleSoft that has hit numerous universities and companies. The breadth of academic and personal data raises the risk of identity theft and targeted phishing against students, applicants, and staff.