ShinyHunters has published a broad trove of allegedly stolen data affecting more than 40 organizations across retail, healthcare, hospitality, insurance, and consumer services, with reporting tying the leak campaign to victims including Bumble, Match Group, Mytheresa, Zara, Carnival, and 7-Eleven. Researchers said the exposed material includes personally identifiable information, customer and transaction records, internal corporate files, and multi-terabyte datasets; one of the largest alleged exposures involved Medtronic, where roughly 9 million records were reportedly listed before that entry was later removed from the leak site.
The campaign reflects ShinyHunters' continued shift from ransomware-style encryption to data theft and extortion, with the group allegedly threatening to keep victim data available indefinitely on criminal platforms. Separate reports said the actors claimed to have stolen about 10 million records from dating-app companies, while researchers also linked leaked Bumble data to the same operation after an earlier claim that roughly 30GB had been taken from the company. The disclosures echo a wider criminal pattern in which stolen sensitive data is leaked to pressure victims after exfiltration, including in healthcare breaches such as the Change Healthcare incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
27 events from the most recent confirmed update back to the earliest known activity.
In May 2026, Baker Distributing was listed on the ShinyHunters pay-or-leak site, and in early June 2026 the group publicly released data it claimed to have taken from the company's SharePoint and Salesforce environments. The leaked dataset reportedly contained 103,000 unique email addresses plus names, physical addresses, phone numbers, and support tickets tied to Baker's HVAC contractor customer base.
In May 2026, BCD Travel was claimed as a victim of the ShinyHunters pay-or-leak extortion campaign, and the allegedly stolen data was published publicly in early June 2026. The exposed data reportedly included 396,000 unique email addresses as well as names, addresses, phone numbers, job titles, employer names, and records from leads, staff, and support-ticket datasets.
A Troy Hunt weekly update cited DentaQuest as an example in the ongoing ShinyHunters campaign, stating that an alleged 233GB dataset from the organization was dropped shortly after it was mentioned. This adds DentaQuest as a newly disclosed victim in the group's 2026 data-theft and extortion activity.
Daily Dark Web reported that ShinyHunters claimed to have stolen 14 million records from Panera Bread. This adds Panera Bread as a newly disclosed victim in the broader ShinyHunters data-theft and extortion campaign.
By late April 2026, reporting described ShinyHunters as shifting from file encryption to pure data theft and extortion, with threats to keep victim data available indefinitely on underground platforms. The campaign was said to expose millions of records and terabytes of stolen information.
Later reporting said Medtronic, initially highlighted as a major victim with about nine million allegedly compromised records, was subsequently removed from the leak site. The removal suggested a possible ransom payment or ongoing negotiation, though this was not confirmed.
Inditex said unauthorized access affected group databases in an incident tied to a former technology provider after Zara was named in ShinyHunters leak threats. The company said passwords, payment cards, and other payment methods were not exposed.
In April 2026, Mytheresa was identified as a victim of the ShinyHunters extortion group in a pay-or-leak incident. After the ransom deadline passed, the group publicly released stolen data reportedly including 84,000 unique email addresses, customer contact and purchase details, and partial payment card information.
Cybernews reported that ShinyHunters threatened Ameriprise Financial and claimed to hold about 200GB of stolen data. The report adds Ameriprise as a newly disclosed victim in the group’s 2026 data-theft and extortion campaign.
Aura confirmed it was breached in an incident linked to ShinyHunters and said at least 900,000 individuals were impacted. The disclosure adds Aura as a newly identified victim in the group’s 2026 data-theft and extortion campaign.
The Register reported that Dutch telecom provider Odido was affected as ShinyHunters leak activity continued, adding Odido as a newly disclosed victim in the broader 2026 publication wave. The report also indicated Dutch police were supporting the company in response to the incident.
The Register reported that ShinyHunters demanded $1.5 million from Wynn Resorts to prevent the leak of allegedly stolen data. The report adds Wynn Resorts as a newly disclosed victim in the group’s 2026 data-theft and extortion campaign.
Canada Goose said a Valentine's Day dataset attributed to ShinyHunters, reportedly containing more than 600,000 records, did not result from a new security incident at the company. The retailer said the leaked data appeared to stem from an older breach and that it was reviewing the dataset to verify its accuracy and scope.
The Register reported that ShinyHunters claimed it had stolen 10 million records from dating apps. This marked a public escalation in the group’s claims around consumer-platform data exposure.
Cybernews reported that Bumble-related data associated with the Hives group was found in ShinyHunters leak postings, warning that the company was among the exposed organizations. The reporting connected Bumble to the broader January 2026 publication wave.
A Daily Dark Web report said ShinyHunters allegedly breached Bumble Inc. and claimed to possess about 30GB of stolen data. This appears to be the earliest referenced event tied to the later Bumble-related reporting.
Further leak-site postings continued during the same week after the first January 23 listing, expanding the scope of the campaign. Reported victims included major brands such as Mytheresa, Zara, Carnival, 7-Eleven, and Medtronic.
According to later reporting, the earliest listing in a large ShinyHunters leak campaign appeared on January 23, 2026. The trove reportedly involved around 40 organizations across sectors including retail, insurance, and hospitality.
BleepingComputer reported that ShinyHunters claimed to have breached Santander and was selling data allegedly tied to 30 million customers. This adds Santander as a newly disclosed victim in the group’s activity prior to the later 2025–2026 campaign entries.
BleepingComputer reported that clothing retailer Bonobos suffered a data breach and that a 70GB database was leaked by a hacker. The report adds Bonobos as another disclosed victim in the broader ShinyHunters-linked retail data exposure campaign.
SiliconANGLE reported that ShinyHunters published 1.9 million stolen user credentials from photo editing site Pixlr. The report adds Pixlr as another disclosed victim in the group’s early multi-company data theft and exposure campaign.
Hackread reported that ShinyHunters leaked a 5.22GB database allegedly belonging to Mashable.com. The report identifies Mashable as another victim in the group’s 2020 multi-company data exposure campaign.
Security Affairs reported that ShinyHunters leaked more than 386 million user records stolen from 18 companies. The report documents an earlier large-scale multi-victim data exposure campaign attributed to the group, predating the later 2025–2026 incidents in the existing timeline.
Minted confirmed a data breach after ShinyHunters offered the company's database for sale. The incident identifies Minted as an additional victim in the group's 2020 data-theft campaign.
Graham Cluley reported that millions of Zoosk dating profiles were put up for sale by the hacking group ShinyHunters. The report identifies Zoosk as another victim in the group's early 2020 multi-company data theft and exposure campaign.
TechRadar reported that ShinyHunters was leaking millions of user details, documenting an early phase of the group's 2020 multi-victim data exposure activity. The report indicates the campaign was already affecting multiple organizations before later victim-specific disclosures such as Minted and Mashable.
ZDNet reported that the hacker group ShinyHunters was selling more than 73 million user records on the dark web. The report marks an early public disclosure of the group’s 2020 multi-victim data theft and sale activity before later victim-specific reports such as Zoosk and Minted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
30 references tracked. Mallory keeps watching after this page renders.
haveibeenpwned.com
Open sourcehaveibeenpwned.com
Open sourcetroyhunt.com
Open sourcehaveibeenpwned.com
Open sourcegrahamcluley.com
Open sourcetechradar.com
Open sourcezdnet.com
Open sourcescmagazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.