FlagThis
← Threat Actors
/
Global
/
ShinyHunters
DOSSIER // SHINYHUNTERS
ShinyHunters
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
Primary Aliases:
DEV-0971
Octo Tempest
Scattered Spider
UNC3944
🔍 Adversary Rosetta Stone (26) ▾
📋 Copy All
Sponsor / State Affiliation
Independent / Not Attributed
Primary Motivation
Financial gain via the sale of stolen datasets and extortion ransoms from high-profile organizations.
Active Timeline
Unknown – Present
Confidence Rating
95% (Grounded)
Ticketmaster/Live Nation Breach, Santander Data Theft, Salesforce CRM Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(1)
CVE-2026-35273
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
📋 Copy CSV
Tenable Nessus
Qualys / Wiz
🎯 Target Sectors & Focus
Technology
Finance
Retail
Education
Telecommunications
Insurance
Luxury Goods
Aviation
🛡️ MITRE ATT&CK® Attack Lifecycle
(8 TTPs)
📥 Download Navigator JSON
All Stages
8
Initial Access
2
Persistence & Privilege Escalation
2
Credential Access & Discovery
1
Command & Control
1
Operational Techniques
2
Initial Access
2
T1566
Voice Phishing (Vishing)
↗
T1566
Third-party Supply Chain Compromise
↗
Persistence & Privilege Escalation
2
T1547
OAuth Token Theft/Abuse
↗
T1547
MFA Bypass and Session Hijacking
↗
Credential Access & Discovery
1
T1003
Credential Harvesting (Infostealers)
↗
Command & Control
1
T1071
SaaS and Cloud Misconfiguration Exploitation
↗
Operational Techniques
2
T1000
Zero-day Exploitation (e.g., Oracle PeopleSoft CVE-2026-35273)
↗
T1000
Pay-or-Leak Extortion
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
ShinyHunters Targets Salesforce Environments via Sophisticated OAuth Abuse Campaign
Attacks and Vulnerabilities
2026-09-02
[DEEP DIVE]
DentaQuest Data Breach: ShinyHunters Exfiltrates 234 GB of PHI and PII
Attacks and Vulnerabilities
2026-09-01
[DEEP DIVE]
One Medical Amazon Alleged 8.8 TB Data Exfiltration by ShinyHunters
Attacks and Vulnerabilities
2026-06-30
[DEEP DIVE]
McKesson: Massive PHI Exfiltration via Third-Party Supply Chain Compromise
Attacks and Vulnerabilities
2026-09-01
[DEEP DIVE]
DentaQuest Data Breach: 2.6 Million Dental Member Records Exfiltrated
Attacks and Vulnerabilities
2026-06-20
[DEEP DIVE]
Identity-First Extortion: Deconstructing the ShinyHunters SaaS Exfiltration Wave
Attacks and Vulnerabilities
2026-05-22
Adversary Rosetta Stone // ShinyHunters
×
🪟 Microsoft Threat Actor Naming
DEV-0971
📋
Octo Tempest
📋
🦅 CrowdStrike Monikers
Scattered Spider
📋
🔍 Mandiant / Google Threat Intel
UNC3944
📋
UNC5537
📋
UNC6040
📋
UNC6240
📋
🛡️ Other Industry Tracking Codes
0ktapus
📋
Bling Libra
📋
G1015
📋
G1057
📋
Gnostic Players
📋
LUCR-3
📋
Muddled Libra
📋
Oktapus
📋
Roasted 0ktapus
📋
Scatter Swine
📋
Scattered Lapsus Hunters
📋
Scattered LAPSUS$ Hunters
📋
Scattered Swine
📋
ShinyCorp
📋
SLH
📋
SLSH
📋
Starfraud
📋
Storm-0875
📋
Storm-0971
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD