ShinyHunters, a financially motivated data-theft and extortion group active since 2020, has continued targeting organizations across entertainment, healthcare, education, and criminal infrastructure. Rockstar Games confirmed that attackers accessed a limited amount of non-material company information through a third-party cloud provider, while maintaining that players and operations were unaffected. In a separate September campaign, data allegedly stolen from Swiss medical-device maker Medela was publicly released after a “pay or leak” extortion attempt; the dataset reportedly included roughly 424,000 unique email addresses, corporate contact details, and some support tickets.
The group has also claimed attacks against other cybercriminals: it allegedly exploited CVE-2026-42608, an unauthenticated path-traversal flaw in Grav CMS, to compromise and deface Clop’s former Tor leak-site server and demand payment. Grav released version 1.7.53.4 after the issue, which had previously been fixed only in the 2.0 branch. Reporting also links ShinyHunters to the theft of more than one billion Salesforce-customer records in 2025 and disruption of the Canvas learning platform in 2026, underscoring how repeated data exposures can be combined into identity profiles that enable account takeover, fraud, and targeted scams.

See which actors are running it and whether you're in range.
12 events from the most recent confirmed update back to the earliest known activity.
Swiss medical-device company Medela was reportedly targeted in a ShinyHunters “pay or leak” extortion campaign.
ShinyHunters reportedly disrupted the Canvas digital-learning platform, affecting more than 8,800 schools nationwide, while pressuring affected organizations to negotiate or risk public release of data.
ShinyHunters reportedly exfiltrated more than one billion records from Salesforce customers and threatened dozens of Fortune 500 victims with publication unless they paid.
ShinyHunters advertised an alleged AT&T database of more than 70 million records, including Social Security numbers and dates of birth, with a $200,000 opening bid and $1 million buyout price. The listing was subsequently removed by forum moderators; ReliaQuest could not verify that the data originated from AT&T.
ShinyHunters publicly revealed an extortion-focused model, claiming it demanded payment from infiltrated victims and threatened data exposure in tactics resembling data-extortion ransomware operations.
ShinyHunters emerged as a financially motivated threat group and posted 91 million allegedly stolen Tokopedia user records for sale on the Empire Market dark-web marketplace.
ShinyHunters defaced the HackForums website and replaced forum material with Pokémon references.
Grav released version 1.7.53.4 to remediate CVE-2026-42608 for users of its 1.7 branch after noting the issue had been fixed in Grav 2.0 but not initially backported to the branch used by Clop.
Clop moved its data-leak site to a new Tor address after the alleged breach and defacement. The group denied any relationship with ShinyHunters and said the compromised server held only site content, not sensitive operational or financial information.
ShinyHunters claimed responsibility for compromising Clop's prior data-leak-site server through CVE-2026-42608, an unauthenticated Grav CMS path-traversal flaw. The group claimed it stole source code, server logs, and private keys before demanding a ransom.
Rockstar Games confirmed that a breach involving a third-party cloud provider exposed a limited amount of non-material company information. ShinyHunters claimed it accessed Rockstar servers managed by that provider and threatened to publish allegedly stolen material unless paid a ransom; Rockstar said the incident did not affect its organization or players.
Data allegedly obtained from Medela was publicly published, exposing approximately 424,000 unique email addresses and primarily corporate contact details; some records included support tickets. The breach was classified as sensitive and not publicly searchable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcehaveibeenpwned.com
Open sourcescworld.com
Open sourcebbc.co.uk
Open sourcereliaquest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.