ShinyHunters is a financially motivated cybercriminal data-extortion group, also tracked as Bling Libra, UNC6040, and UNC6240. The group conducts large-scale theft-and-extortion operations against organizations, prominently including U.S. healthcare and medical-technology entities and French technology-services companies. It has also conducted vishing campaigns targeting enterprise cloud-account users at major consumer brands. ShinyHunters uses social engineering, including voice phishing and impersonation, to obtain employee access or credentials. Reported operations have involved compromising single sign-on accounts and using valid access to reach cloud-hosted SaaS environments, including Salesforce and Snowflake, followed by data exfiltration. The group uses leak sites and pay-or-leak demands to pressure victims, threatening publication of stolen data when negotiations fail or deadlines expire. Its publicly claimed victim activity includes McKesson, Baxter International, Questel, Ernst & Young, and Neogen. Claims concerning individual incidents, record volumes, and specific stolen data categories are not always independently verified by affected organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
On June 10th, 2026, Oracle disclosed a critical unauthenticated Remote Code Execution (RCE) vulnerability impacting its Oracle PeopleSoft PeopleTools application, tracked as CVE-2026-35273 (CVSS: 9.8). Successful exploitation of the flaw can result in full takeover of PeopleSoft Enterprise PeopleTools.
Oracle E-Business Suite was the target of a large scale Cl0p ransomware campaign just months ago via CVE-2025-61882... A critical zero day in Oracle EBS Concurrent Processing, exploited by the Cl0p ransomware gang...
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
According to data obtained from a public Telegram channel operated by the ShinyHunters team, the threat actor persona ‘Yukari’ exploited an Oracle Access Manager vulnerability (CVE-2021-35587). The attack targeted financial institutions and manufacturers.
99 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed a separate breach of healthcare distributor McKesson and alleged theft of hundreds of millions of records.
An extortion group claimed responsibility for stealing patient records from pharmaceutical distributor McKesson.
Data-extortion operation alleged to have breached McKesson, exfiltrated customer data from third-party applications, and demanded a $55 million ransom. The article says initial access is believed to have been obtained through social engineering targeting employees.
Conducted an alleged data-extortion intrusion against McKesson, claiming theft of approximately 284 million patient and employee records from Snowflake and Salesforce cloud environments and demanding a $55 million ransom.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.