ShinyHunters is a financially motivated cybercriminal extortion collective best known for large-scale data theft, leak-site extortion, and identity-centric intrusions against cloud and SaaS environments. The group is widely tracked as ShinyHunters and has also been associated with aliases including SLSH, UNC6240, and in some reporting UNC6040 for related initial-access activity. Additional aliases seen in vendor tracking include BLING_LIBRA. Public reporting consistently characterizes the actor as a criminal rather than a state-sponsored threat group. ShinyHunters has evolved from breach-and-leak operations into aggressive social-engineering-led extortion. Its operations commonly rely on voice phishing against employees, impersonation of IT support or internal staff, credential harvesting against enterprise single sign-on platforms, MFA manipulation, and abuse of valid accounts. In multiple campaigns, the actor has targeted identity providers and downstream SaaS applications rather than on-premises infrastructure, enabling access to platforms such as CRM, collaboration, ticketing, analytics, and data platforms. The group has also abused OAuth consent flows, trusted connected applications, guest-access misconfigurations, and legitimate vendor integrations to obtain persistent API-level access and exfiltrate data while blending into normal cloud activity. A major tradecraft theme is post-compromise collection from enterprise SaaS ecosystems. Reported activity includes theft of data from Salesforce environments, SharePoint and Microsoft 365-related services, and other connected business applications after compromise of a corporate SSO account or trusted third-party integration. The actor has also been linked to supply-chain-style access paths in which compromised vendor credentials or tokens were used to reach customer environments. This emphasis on trusted identities and sanctioned application behavior reduces traditional detection opportunities based on malware or anomalous sign-ins alone. ShinyHunters has also been tied to opportunistic exploitation of exposed enterprise applications for extortion. In 2026, Google Threat Intelligence Group and Mandiant attributed an active compromise and extortion campaign against Oracle PeopleSoft infrastructure to UNC6240, identified as ShinyHunters, involving CVE-2026-35273. Reporting on that campaign indicated broad exposure across organizations worldwide, with academic institutions disproportionately represented among exposed targets. The group has also been associated with attacks affecting education-sector platforms and customers, reinforcing a demonstrated interest in universities, educational software ecosystems, and institutions holding large volumes of personal and financial data. Victimology spans healthcare, education, manufacturing, retail, and technology, with campaigns affecting both direct enterprise targets and downstream customers through third-party relationships. Reported incidents and claims have involved organizations such as Abbott, Vimeo, Fluke, the University of Nottingham, and customers of Salesforce- and PeopleSoft-related ecosystems. The group’s extortion model is primarily pay-or-leak rather than encryption-centric ransomware, although some reporting and victim notices loosely describe incidents as ransomware. Its core business model is data exfiltration followed by coercive negotiation and threatened public release on a leak site. Operationally, ShinyHunters overlaps with a broader ecosystem of socially engineered extortion actors. Some reporting distinguishes related clusters, with UNC6040 used for initial access activity and UNC6240 for follow-on extortion that claimed the ShinyHunters brand. Researchers have also noted tradecraft and infrastructure similarities with BlackFile and Helix, but firm attribution between these entities remains unproven. The actor’s repeated use of employee-focused deception, cloud application abuse, and rapid monetization through public shaming and data publication places it among the more prominent modern data-extortion groups specializing in identity and SaaS compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
CVE-2026-35273 (Oracle PeopleSoft PeopleTools) : accès HTTP non authentifié, lié à ShinyHunters
Oracle E-Business Suite was the target of a large scale Cl0p ransomware campaign just months ago via CVE-2025-61882... A critical zero day in Oracle EBS Concurrent Processing, exploited by the Cl0p ransomware gang...
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation.
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
According to data obtained from a public Telegram channel operated by the ShinyHunters team, the threat actor persona ‘Yukari’ exploited an Oracle Access Manager vulnerability (CVE-2021-35587). The attack targeted financial institutions and manufacturers.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for one of the reported Abbott breach incidents.
Referenced as a possibly linked data extortion group with similar infrastructure and tactics to Helix, including impersonation, Microsoft 365 targeting, SharePoint data theft, and social engineering.
Group discussed as an example campaign spanning vishing through Salesforce data exfiltration; also noted as using deepfake audio to impersonate IT support.
Extortion activity tied to unauthorized access to Abbott's Cancer Diagnostics/legacy Exact Sciences systems, with claims of data exfiltration and threats to publish stolen information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.