ShinyHunters is a financially motivated cybercriminal extortion group known primarily for large-scale data theft, supply-chain compromise, and identity-centric intrusions against cloud and SaaS environments. The group is also tracked as Bling Libra, and reporting has associated it with aliases including UNC6040 and UNC6240; some activity using similar tradecraft has also been discussed alongside other clusters, but not all such clusters are confirmed to be the same actor. ShinyHunters has been active since at least 2020 and has evolved from earlier ransomware-associated activity into a predominantly pay-or-leak extortion model focused on exfiltrating data rather than relying on file encryption. The group has repeatedly targeted organizations in healthcare, medical technology, financial and professional services, education, and physical security, with a strong concentration of victims in the United States and additional activity affecting the United Kingdom, Canada, Australia, and other countries. Reported victims and campaigns include attacks against healthcare-related organizations, security providers, enterprise software users, and large professional-services firms. ShinyHunters has also been linked to attacks affecting universities and schools through compromises of widely used platforms. Operationally, ShinyHunters is associated with supply-chain and identity attacks used to gain access to enterprise cloud estates and storage platforms. Reported tradecraft includes abuse of third-party integration partners, theft and misuse of OAuth tokens, compromise of SaaS tenants, and exfiltration of large volumes of sensitive data from platforms such as Salesforce and Snowflake. The group has also been tied to voice-phishing and social-engineering-driven intrusions in which employees are tricked into approving authentication requests or entering credentials into adversary-controlled portals, enabling session hijacking and access to identity providers and downstream SaaS applications. In addition, ShinyHunters has been linked to exploitation of Oracle PeopleSoft zero-day CVE-2026-35273. ShinyHunters operates extortion infrastructure including a leak site and has repeatedly threatened victims with public release of stolen data unless payment is made. Multiple 2026 incidents were explicitly described as pay-or-leak campaigns, and the group has been characterized as conducting pure data-theft extortion rather than traditional encryption-led ransomware. At the same time, reporting has linked the group to ShinySp1d3r, a ransomware family apparently under development, indicating at least some continued interest in encryption-capable tooling. Overall, ShinyHunters is best characterized as a prolific data-extortion actor specializing in cloud-focused intrusions, credential and token abuse, and monetization through public shaming and sale or release of stolen information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
ShinyHunters was responsible for several major breaches, including attacks against Canvas (impacting ~9,000 educational institutions globally) and the exploitation of the Oracle PeopleSoft zero-day (CVE-2026–35273). According to Mandiant and the Google Threat Intelligence Group (GTIG), the zero-day was used to attack over 100 organisations worldwide, including the University of Nottingham and other institutions.
Oracle E-Business Suite was the target of a large scale Cl0p ransomware campaign just months ago via CVE-2025-61882... A critical zero day in Oracle EBS Concurrent Processing, exploited by the Cl0p ransomware gang...
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
According to data obtained from a public Telegram channel operated by the ShinyHunters team, the threat actor persona ‘Yukari’ exploited an Oracle Access Manager vulnerability (CVE-2021-35587). The attack targeted financial institutions and manufacturers.
82 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a financially motivated group whose tradecraft overlaps with UNC6671, though the article says the operations are assessed to be acting independently.
Conducting a "pay or leak" extortion campaign and publicly releasing stolen data from Exact Sciences' cancer diagnostics business.
Conducting a 'pay or leak' extortion campaign against Inter-Con Security and allegedly publishing stolen company data including email addresses and personal/contact information.
Conducting a 'pay or leak' extortion campaign and publishing allegedly stolen company data, including email addresses and personal/contact information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.