#shinyhunters

18 posts · Last used 9d

Exclusive, breaking: Dutch Police Arrest "Reformed" Hacker in ShinyHunters investigation Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/ #shinyhunters #cybercrime
75
8
86
2
In today's Breach Please, @malwarejake@infosec.exchange and I talk about how Shiny Hunters got into the FBI through an unpatched Oracle PeopleSoft O-day, walking out with employee, applicant, and family data from AWS GovCloud. Plus: technical debt, the case for just patching, and a PR moment involving two dogs. Ep 39 of Breach Please: YouTube: https://www.youtube.com/watch?v=GKhVFA3Ji88 #Cybersecurity #InfoSec #DataBreach #Oracle #shinyhunters #fbi

Sept 23, 2026 - S0:E39: FBI Breach, Shiny Hunters' Oracle O-Day, and a PR Fail With Dogs

1
0
1
0
Replying to
@InternationalCyberDigest@infosec.exchange @BleepingComputer@infosec.exchange @404mediaco@mastodon.social The official statement from ShinyHunters leak site Source: vxdb #cybersecurity #infosec #fbi #databreach #shinyhunters #defaced
1
0
0
0
NEW by me: ShinyHunters escalates dispute with FBI; claims to have seized job applicants' site and acquired data First, they threatened Clop this week, and now the FBI. Some will disagree with me strongly, but I actually agree with ShinyHunters on some of their objections to a May 2026 FBI bulletin about them. That still doesn't excuse them hacking and extorting them, of course. https://databreaches.net/2026/09/22/shinyhunters-escalates-dispute-with-fbi-claims-to-have-seized-job-applicants-site-and-acquired-data/ #databreach #govsec #cybersecurity #extortion #ShinyHunters #FBI #Cl0p
5
0
4
0
Replying to
If you're among the 23 million, review your breach notification, check HaveIBeenPwned, and enroll in identity protection services immediately. Reward: You've received a complimentary Cavity Search — performed remotely, without anesthesia. #DataBreach #CyberSecurity #DentaQuest #ShinyHunters #HealthcareHack #AchievementUnlocked (3/3)
0
0
0
0
⚠️ ShinyHunters claims it hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day 「 A spokesperson for the cybercrime crew on Thursday told The Register that they exploited CVE-2026-35273 to break into the university’s PeopleSoft system and steal 40 GB of personal data and billing records belonging to hundreds of thousands of current and former students 」 https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-claims-oracle-peoplesoft-0-day-hit-100-orgs/5254443 #ShinyHunters #PeopleSoft #oracle #CVE202635273
0
0
1
0
Chicago Sun-Times - All | U. of I. reschedules finals after learning platform Canvas reaches deal with hackers by AP AI generated summary, Read the full article for complete information. The University of Illinois Urbana‑Champaign postponed its final exams from Friday to Sunday (Mother’s Day) after the Canvas learning platform’s owner, Instructure, announced it had reached an agreement with the hackers who breached the system. Instructure temporarily shut down Canvas for investigation, locking out students and faculty, and later claimed the attackers deleted the stolen data and “shred logs” confirmed the erasure, though no guarantee was given that all copies were eliminated. The breach exposed student IDs, names, emails and messages, but not passwords or financial information. The university warned of heightened phishing risks and said the rescheduling, though imperfect, was the best of several problematic options. Read more: https://chicago.suntimes.com/education/2026/05/12/u-of-i-reschedules-finals-canvas-hack-deal #JohnColeman #UniversityIllinois #Instructure #Canvas #ShinyHunters #Urbana_Champaign #
0
0
6
0
BBC News | Canvas hack: Company pays criminals to delete students' stolen data AI generated summary, Read the full article for complete information. The makers of Canvas, the learning‑management platform used by thousands of universities, confirmed that after a massive hack—affecting roughly 9,000 institutions in the US, Canada, Australia and the UK and disrupting exams—they reached an agreement with the extortion group Shiny Hunters, who claimed to have stolen 3.5 TB of student and university data. Instructure says the hackers deleted the data, provided digital confirmation of its destruction, and promised no further extortion of its customers, although the exact terms and any payment remain undisclosed. While paying cyber‑criminals is generally discouraged because it can encourage more attacks and offers no guarantee the data is truly gone, Instructure emphasized protecting students and staff as its primary motive and highlighted its transparency in updating the public throughout the incident, which also saw ransom notes appear on students’ screens during exams and caused significant disruption to coursework. Read more: https://www.bbc.com/news/articles/cdepzg83x87o?at_medium=RSS&at_campaign=rss #Instructure #ShinyHunters #Canvas #AubreyPalmer
0
0
4
0
Instructure has confirmed a data breach, exposing sensitive user data including student IDs and private messages. This marks the second time in under a year that the notorious ShinyHunters group has claimed an attack on the EdTech giant. While Instructure's confirmed scope is smaller, ShinyHunters alleges a staggering 275 million individuals and billions of private messages were… https://www.tpp.blog/1x31kbg #cybersecurity #instructure #shinyhunters 🤖 This post was AI-generated.
0
0
1
0
ADT has confirmed yet another data breach, with the ShinyHunters group claiming to have exposed millions of customer records including PII. This incident isn't just a one-off; it points to a systemic problem, potentially stemming from social engineering tactics like vishing and compromised SSO accounts into SaaS platforms like Salesforce. The real concern? Data entrusted to a security provider can… https://www.tpp.blog/vwuqge5 #cybersecurity #adt #shinyhunters 🤖 This post was AI-generated.
0
0
1
0
You've seen all posts