← Back to all threat actors

ShinyHunters

Also known as UNC6240, Bling Libra
Tracked as G1057

ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. ShinyHunters has been associated with the broader collective called The Community, also known as The Com whose members have also included Scattered Spider and LAPSUS$. Public reporting has mentioned a variety of names for operations ShinyHunters members have reportedly conducted with members of other groups, including “Scattered Lapsus Hunters,” “Scattered Lapsus Shiny Hunters,” and “SLSH.”

How we source and review actor profiles
Sectors
agriculture-and-food-production, business-services, consumer-services, education, energy, financial-services, healthcare, manufacturing, technology, telecommunication
Status
Active

Threat intelligence assessment

At a glance

Facts

  • ShinyHunters is an extortion gang known for targeting online web applications and cloud SaaS environments in data theft attacks

Activity timeline

Facts

  • Claimed breach of Florida DAVID (Driver and Vehicle Information Database) with over 200,000 stolen driver records beginning September 3rd
  • Linked to breaches at Google, Cisco, PornHub, and Match Group
  • Conducted massive data-theft attack on Instructure Canvas in May causing significant outages
  • Conducted attacks on Ernst & Young

Attribution assessment

Facts

  • The ShinyHunters name has been associated with numerous threat actors conducting data breaches since 2018
  • Arrests linked to the ShinyHunters name include suspects connected to Snowflake data-theft attacks, PowerSchool breaches, and operation of the Breached v2 hacking forum
  • Threat actors targeting other states' DMV platforms using social engineering attacks are suspected to be related to ShinyHunters

Initial access and identity targets

Facts

  • Compromised password-reset flaw in DAVID system to compromise multiple accounts belonging to DMV employees and an FBI agent
  • Targets third-party integration companies and uses stolen authentication tokens to access connected SaaS environments
  • Conducts voice phishing (vishing) attacks targeting Okta, Microsoft, and Google SSO accounts impersonating IT support staff
  • Adopted device code vishing attacks to obtain Microsoft account authentication tokens

Capabilities and evasion

Facts

  • Iterates through database records by IDs to download associated HTML and images
  • Hijacks SSO accounts to breach connected enterprise services including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox

Infrastructure patterns

Facts

  • Operates a data leak site to publish breached data

Communication and pressure channels

Facts

  • Communicates with media outlets and targeted organizations regarding breaches and extortion demands

Observed targeting

Facts

  • Initially focused on Salesforce and other cloud SaaS environments
  • Recently expanded to target government DMV databases
  • Targeting other states' DMV platforms using social engineering attacks

Named victims

Organizations

  • Florida Department of Motor Vehicles (FLHSMV)
  • Google
  • Cisco
  • PornHub
  • Match Group
  • Instructure Canvas
  • Ernst & Young

Reported detail

Facts

  • ShinyHunters claimed a breach of the Florida DMV's DAVID platform, stealing over 200,000 driver records through a password-reset vulnerability
  • The group exploited compromised accounts of DMV employees and an FBI agent to access and exfiltrate records
  • ShinyHunters has evolved from targeting cloud SaaS applications like Salesforce to now attacking government systems and using sophisticated vishing attacks against major SSO providers
  • The extortion gang operates a data leak site and threatens to publish stolen data unless victims negotiate with them
  • Despite multiple arrests linked to the ShinyHunters name, threat actors using this name continue to conduct widespread data theft and extortion operations

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

First listed
Victim claimMedela.com listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimState of Florida DMV listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimNote to mr. databroker1 NEXUS DL Service listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Cataloged
Indicator5 indicators cataloged

Types: domain, tool.

First listed
Victim claimNeogen Corporation listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Disclosed
Victim claimMcKesson confirmed a breach

The organisation has publicly confirmed a breach. That confirmation covers the incident, not the attribution to ShinyHunters.

Confirmed
First listed
Victim claimElekta AB listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimJack Henry & Associates listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Disclosed
Victim claimReliaQuest confirmed a breach

The organisation has publicly confirmed a breach. That confirmation covers the incident, not the attribution to ShinyHunters.

Confirmed
First listed
Victim claimReliaQuest, LLC listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimCyrusOne, LLC. listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimNovoCure Limited listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimBOK Financial listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimCyrus****** listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimBrinks Home listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimAlcon, Inc. listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimLumenis Ltd. listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimQuestel SAS listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimNOTICE OF WARNING listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimLogitech/ Streamlabs listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Cataloged
IdentityAlias: UNC6240

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Bling Libra

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G1057

Reviewed identity mapping approved on this date.

First listed
Victim claimBaxter International, Inc. listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimSharecare, Inc. listed by ShinyHunters

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed

The interactive view includes 104 dated events with category filters and paging.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

ShinyHuntersCanonical Name
Bling LibraAlias
UNC6240Alias
G1057Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...