ShinyHunters is a financially motivated data-theft and extortion brand that steals data from cloud and SaaS platforms and demands payment to keep it unpublished. The 2024 thefts from Snowflake customer accounts were claimed under the name; Mandiant found the attackers used infostealer-harvested credentials on accounts without MFA. Since 2025 Google and the FBI have described callers posing as IT support who talk staff into approving a malicious Salesforce connected app, followed by extortion emails signed ShinyHunters. Google tracks the extortion side as UNC6240. KrebsOnSecurity describes the crew as part of Scattered LAPSUS$ Hunters, an amalgam of Scattered Spider, LAPSUS$ and ShinyHunters.
LatestDutch police confirmed on 28 September 2026 the arrest of a 24-year-old man in their investigation into ShinyHunters; KrebsOnSecurity, citing sources, reported he was detained around 16 September. In September AdaptHealth confirmed that 4,115,802 people were affected by a June 2026 breach attributed to ShinyHunters.
Timeline
Mandiant reported a data-theft campaign against Snowflake customer accounts that used infostealer-stolen credentials on accounts without MFA; about 165 organisations were notified.
French police reportedly arrested four suspects in June 2025, including one using the ShinyHunters alias, over breaches of French firms (reported).
The Record — French police reportedly arrest suspected BreachForums administrators (25 Jun 2025)
Google described UNC6040 voice-phishing staff into approving a modified Salesforce Data Loader app, with later extortion by actors claiming the ShinyHunters brand.
The FBI issued a FLASH alert on Salesforce data theft, noting some victims then received extortion emails allegedly from ShinyHunters.
FBI FLASH-20250912-001 — UNC6040 and UNC6395 compromising Salesforce instances (12 Sep 2025)
Google reported ShinyHunters-branded vishing for SSO credentials and MFA codes in January 2026 and a new SHINYHUNTERS leak site.
Google Threat Intelligence — Expansion of ShinyHunters-branded SaaS data theft (31 Jan 2026)
Instructure said it reached an agreement with the actor behind its Canvas breach, detected on 29 April; ShinyHunters had claimed the attack.
Help Net Security — Instructure took a risky approach to recover stolen Canvas data (12 May 2026)
AdaptHealth disclosed a breach in an SEC filing; it later reported 4,115,802 people affected, and the attack was attributed to ShinyHunters.
BleepingComputer — AdaptHealth confirms 4.1 million people exposed in July cyberattack (9 Sep 2026)
Dutch police confirmed the arrest of a 24-year-old man in their ShinyHunters investigation.
Reformatorisch Dagblad — Man aangehouden in onderzoek naar hackersgroep ShinyHunters (28 Sep 2026)
Who is exposed, and what holds
Who is exposed
- Salesforce and other SaaS tenants where employees can authorise new connected apps
- Organisations whose staff or contractors can be talked into sharing SSO credentials and MFA codes
- Cloud data platforms with accounts protected only by passwords
Recommended controls
- Move to phishing-resistant MFA such as FIDO2 security keys or passkeys
- Restrict who can install connected apps and hold the API Enabled permission; allowlist approved apps
- Alert on new MFA device registrations, bulk SaaS exports and logins from VPN or Tor
Desk coverage
Sources
- FBI FLASH-20250912-001 — UNC6040 and UNC6395 compromising Salesforce instances (12 Sep 2025)
- Google Threat Intelligence — The cost of a call: from voice phishing to data extortion (5 Jun 2025, updated Aug 2025)
- Google Threat Intelligence — Expansion of ShinyHunters-branded SaaS data theft (31 Jan 2026)
- Mandiant/Google — UNC5537 targets Snowflake customer instances for data theft and extortion (10 Jun 2024)
- BleepingComputer — Stolen Ticketmaster data from Snowflake attacks briefly for sale again (9 Jun 2025)
- Instructure — Security incident update & FAQs (May 2026)
- Help Net Security — Instructure took a risky approach to recover stolen Canvas data (12 May 2026)
- BleepingComputer — AdaptHealth confirms 4.1 million people exposed in July cyberattack (9 Sep 2026)
- KrebsOnSecurity — Dutch police arrest reformed hacker in ShinyHunters investigation (28 Sep 2026)
- Reformatorisch Dagblad — Man aangehouden in onderzoek naar hackersgroep ShinyHunters (28 Sep 2026)
- The Record — French police reportedly arrest suspected BreachForums administrators (25 Jun 2025)