Ransomware Group intelligence
Shinyhunters
ActiveTrack Shinyhunters with 181 published victims and 4 known leak locations in a single intelligence view.
Overview
Shinyhunters is tracked by Breach House as a ransomware group with 181 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Up checked 20m ago | shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onion |
| Leak location 2 | Web location | Up checked 21m ago | breachforums.hn |
| Leak location 3 | Onion service | Down checked 20m ago | toolatedhs5dtr2pv6h5kdraneak5gs3sxrecqhoufc5e45edior7mqd.onion |
| Leak location 1 | Onion service | Down checked 20m ago | shinypogk4jjniry5qi7247tznop6mxdrdte2k6pdu5cyo43vdzmrwid.onion |
Top Activity Sectors (17)
- Communication / Marketing 23
- Retail / E-commerce 18
- IT 16
- Not identified 15
- Education 14
- Finance / Legal / Insurance 13
- Services 11
- Healthcare / Pharma 10
- Transportation / Travel / Logistics 8
- Manufacturing / Engineering 5
- Hospitality / Food & Beverage / Tourism 5
- Telecommunications 4
- Construction / Real Estate 4
- Energy 3
- Public Sector 2
- Agriculture / Food 1
- NGOs / Associations 1
Typical Attacks (46)
▼How Shinyhunters typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via ShinyHunters.
-
T1589.001 Credentials Reconnaissance
What they do: ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.
What that means: Adversaries may gather credentials that can be used during targeting.
-
T1593.003 Code Repositories Reconnaissance
What they do: ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.
What that means: Adversaries may search public code repositories for information about victims that can be used during targeting.
-
T1595.002 Vulnerability Scanning Reconnaissance
What they do: ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.
What that means: Adversaries may scan victims for vulnerabilities that can be used during targeting.
-
T1598 Phishing for Information Reconnaissance
What they do: ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.
What that means: Adversaries may send phishing messages to elicit sensitive information that can be used during targeting.
-
T1598.003 Spearphishing Link Reconnaissance
What they do: ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials.
What that means: Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
-
T1583.001 Domains Resource Development
What they do: ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data.
What that means: Adversaries may acquire domains that can be used during targeting.
-
T1583.004 Server Resource Development
What they do: ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.
What that means: Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting.
-
T1585.002 Email Accounts Resource Development
What they do: ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.
What that means: Adversaries may create email accounts that can be used during targeting.
-
T1587.004 Exploits Resource Development
What they do: ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.
What that means: Adversaries may develop exploits that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1588.007 Artificial Intelligence Resource Development
What they do: ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.
What that means: Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting.
-
What they do: ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments.
What that means: Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1195.001 Compromise Software Dependencies and Development Tools Initial Access
What they do: ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.
What that means: Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
-
T1059.007 JavaScript Execution
What they do: ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems.
What that means: Adversaries may abuse various implementations of JavaScript for execution.
-
T1059.009 Cloud API Execution
What they do: ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.
What that means: Adversaries may abuse cloud APIs to execute malicious commands.
-
What they do: ShinyHunters has abused software deployment tools for lateral movement.
What that means: Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
-
T1203 Exploitation for Client Execution Execution
What they do: ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks.
What that means: Adversaries may exploit software vulnerabilities in client applications to execute code.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1684 Social Engineering Stealth
What they do: ShinyHunters has used social engineering to demand payment from victims.
What that means: Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instructions (i.e., introduction of malicious payloads or software), while minimizing technical indicators.
-
T1110 Brute Force Credential Access
What they do: ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1528 Steal Application Access Token Credential Access
What they do: ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository.
What that means: Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
-
T1552.001 Credentials In Files Credential Access
What they do: ShinyHunters has gathered PII from database infrastructure.
What that means: Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
-
T1016 System Network Configuration Discovery Discovery
What they do: ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1069.003 Cloud Groups Discovery
What they do: ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.
What that means: Adversaries may attempt to find cloud groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1580 Cloud Infrastructure Discovery Discovery
What they do: ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.
What that means: An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.
-
T1619 Cloud Storage Object Discovery Discovery
What they do: ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.
What that means: Adversaries may enumerate objects in cloud storage infrastructure.
-
T1210 Exploitation of Remote Services Lateral Movement
What they do: ShinyHunters has exploited vulnerabilities in remote services for lateral movement.
What that means: Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
-
T1550.001 Application Access Token Lateral Movement
What they do: ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.
What that means: Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems.
-
T1213.003 Code Repositories Collection
What they do: ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.
What that means: Adversaries may leverage code repositories to collect valuable information.
-
T1213.006 Databases Collection
What they do: ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.
What that means: Adversaries may leverage databases to mine valuable information.
-
T1530 Data from Cloud Storage Collection
What they do: ShinyHunters has collected data from insecure cloud buckets.
What that means: Adversaries may access data from cloud storage.
-
T1560.002 Archive via Library Collection
What they do: ShinyHunters has used the following command to compress collected data: ` pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst `.
What that means: An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: ShinyHunters has used Tor to host their DLS.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: ShinyHunters has established a connection between the staging host and the C2 using SSH.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1567 Exfiltration Over Web Service Exfiltration
What they do: ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data.
What that means: Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.
-
T1485 Data Destruction Impact
What they do: ShinyHunters has executed the `DeleteBucket` API call to delete buckets.
What that means: Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
-
T1491.001 Internal Defacement Impact
What they do: ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1657 Financial Theft Impact
What they do: ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Victims (181)
Search, filter and paginate the victim timeline for Shinyhunters. Showing 1–100 of 181.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Neogen Corporation id32272 View details | United States | Healthcare / Pharma | — | |
|
Neogen Corporation is a United States-based company operating within the Healthcare and Medicine sector, providing laboratory diagnostics, genomic sequencing, and related clinical testing services to healthcare systems and research institutions. As a prominent healthcare entity, its operational continuity and data integrity are critical to patient care and industry trust. Neogen Corporation was listed as a ransomware victim associated with the ShinyHunters threat actor, reflecting a cybersecurity incident within its digital infrastructure. This listing underscores the vulnerability of healthcare organizations to sophisticated cyber threats and highlights the importance of robust defense strategies across sensitive sectors. The entry serves as a reference point for threat-intelligence analysis concerning healthcare entities targeted by advanced persistent threats. |
|||||
| Ransomware | Neogen Corporation id32272 View details | United States | Healthcare / Pharma | — | |
|
This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 30 Aug 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | McKesson Corporation id32248 View details | United States | Healthcare / Pharma | — | |
|
McKesson Corporation is a major United States-based healthcare and pharmaceutical distribution company providing medical products, pharmaceuticals, and healthcare services globally. Operating within the critical healthcare and pharma sector, McKesson serves hospitals, clinics, government entities, and healthcare professionals through supply chain solutions and digital health initiatives. This entity is cataloged in the threat-intelligence index as a ransomware victim associated with the ShinyHunters threat actor group. The listing reflects its inclusion in cybersecurity threat monitoring for entities impacted by this specific adversary, underscoring vulnerabilities within healthcare infrastructure. No further incident details, such as confirmed breach specifics or disclosure timelines, are elaborated here to maintain factual neutrality and avoid speculation. |
|||||
| Ransomware | McKesson Corporation id32248 View details | United States | Healthcare / Pharma | — | |
|
Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Elekta AB id32245 View details | Sweden | Manufacturing / Engineering | — | |
|
Elekta AB is a Sweden-based corporation operating within the manufacturing and engineering sectors, providing technology, digital solutions, and engineering services to global clients. The entity was formally cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor identified as ShinyHunters. This listing reflects documented cyber-threat intelligence concerning the organization and its exposure to ransomware activity linked to ShinyHunters. The record emphasizes the entity's sector profile and geographic origin alongside the security incident classification without disclosing unverified incident details. Elekta AB remains referenced in this context as a representative case tied to ShinyHunters-associated ransomware activity. |
|||||
| Ransomware | Elekta AB id32245 View details | Sweden | Manufacturing / Engineering | — | |
|
This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Jack Henry & Associates id32246 View details | United States | Services | — | |
|
Jack Henry & Associates operates within the Services sector and serves clients primarily within the United States, providing professional consulting and related service offerings. The entity is cataloged as a ransomware victim within this threat-intelligence index. Its listing is directly associated with the ShinyHunters threat actor group, indicating an incident where ShinyHunters was identified in connection with this organization. No specific technical details regarding data exfiltration, ransom demands, or breach confirmation are included in this description, adhering to strict factual boundaries. This entry supports cybersecurity teams in assessing organizational exposure and tracking threat actor activity across affected service-sector entities. |
|||||
| Ransomware | Jack Henry & Associates id32246 View details | United States | Services | — | |
|
This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | CyrusOne, LLC. id32059 View details | United States | Manufacturing / Engineering | — | |
|
CyrusOne, LLC is a United States-based company operating within the Manufacturing and Engineering sector, providing advanced process control, automation, and digital solutions for industrial operations. As a prominent industrial enterprise, it was cataloged in the threat-intelligence index under the listing type ransomware victim. The entity is associated with the threat actor ShinyHunters, a group known for targeting organizations across multiple sectors. This entry documents the relationship between CyrusOne, LLC and ShinyHunters within the ransomware victim classification. The description remains neutral regarding specific incident details, as confirmed specifics were not publicly disclosed by the company. |
|||||
| Ransomware | CyrusOne, LLC. id32059 View details | United States | Manufacturing / Engineering | — | |
|
Update 23 Aug : We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along with: Sharepoint: (369.6 GB Compressed / 645 GB Uncompressed) 288,729 Files, 60,513 Folders - More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object. - Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.) - Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs - Extensive physical key inventory logs, verification photos, and contractor Green Badge audits - Large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics - Full CERM (Critical Environment Reliability Management) process library - Physical and information security policy suite plus governance materials - Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages - Credential and access-control artifacts (including PasswordList.xlsx, Okta SSC Access lists, active badge reports, and multiple Data Center Access Control forms) This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | ReliaQuest, LLC id32012 View details | United States | IT | — | |
|
ReliaQuest, LLC is a United States-based company operating within the information technology sector, providing services and solutions aligned with IT infrastructure and managed technology offerings. Within the threat-intelligence index, ReliaQuest, LLC is cataloged as a ransomware victim linked to the ShinyHunters threat actor. This listing type indicates observed or reported association with ShinyHunters activity affecting the entity, without disclosing confirmed breach specifics such as data exfiltration details, financial impact, or precise incident timelines. The entry supports cyber threat analysis by documenting the entity's sector, geographic origin, and its relationship to a specific ransomware-associated actor group. ReliaQuest, LLC remains referenced neutrally as part of the ransomware victim index for threat-intelligence purposes. |
|||||
| Ransomware | ReliaQuest, LLC id32012 View details | United States | IT | — | |
|
This time the post is about you , not us. Let Mandiant report and advise on us accurately, go away. DISCLAIMER: This information is being provided "as is" for informational purposes only. We do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this post. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favour by us. | Updated: 23 Aug 2026 |
|||||
| Ransomware | NovoCure Limited id31936 View details | Israel | — | — | |
|
This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 22 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | BOK Financial id31937 View details | United States | — | — | |
|
This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 22 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Cyrus****** id31923 View details | — | — | ||
|
This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 20 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Cyrus****** id31923 View details | United States | — | — | |
|
This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 20 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Logitech/ Streamlabs id31828 View details | Switzerland | — | ||
|
This is a final warning to reach out by 21 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Metabase id31694 View details | United States | IT | — | |
|
Metabase.com is an IT company based in the US, offering open-source business intelligence and data analytics solutions. The company provides tools for data visualization, reporting, and analytics to various organizations. Metabase.com was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Metabase id31694 View details | United States | IT | — | |
|
:P | Updated: 12 August 2026 | SHA256: 84daf8f33954a0b03238a1e0da3ee109d5bc32acc134cfdddfac36b4b75d2480 |
|||||
| Ransomware | Sharecare, Inc. id31695 View details | United States | Healthcare / Pharma | — | |
|
Sharecare.com is a US-based healthcare and medicine company that provides health and wellness services. The company offers various resources and tools to help individuals manage their health. Sharecare.com was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Sharecare, Inc. id31695 View details | United States | Healthcare / Pharma | — | |
|
This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to negotiate for you, that is on you. We will be publishing companies data who are negotiating with us, without a warning if negotiators continue to take us as misinformed individuals and BS us. Over 3.4 million Salesforce records containing some PII and 28GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 25GB+ (compressed) | Updated: 13 August 2026 | SHA256: 195842b8a53e8d7fe63238dbed753c1c28a86034ca98f99527ef743528b6cc45 |
|||||
| Ransomware | Carhartt, Inc. id31674 View details | United States | — | — | |
|
Our demand for this Company was $3.3 million. The Company reached out. However, The Company did not try to negotiate. If The Company attempted to negotiate with us The Company would've ended up saving a good chunk of money. Instead they decided to do (see blow); this is also because The Company hired a very unskilled and incompetent negotiator. If The Company hired competency to negotiate for them, this post would've never been published. [21:24:22] carhartt: After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process. There is millions of customers of data involved here. As we always say, these companies don't care. Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 50GB+ (compressed) | Updated: 13 August 2026 | SHA256: 6b37f770382ce82bfa4677466cc51d9269e5a70436eecf101fae6fa9d5d8e8ac |
|||||
| Ransomware | Cook Medical LLC id31676 View details | United States | — | — | |
|
Customer data, employee data, and other internal corporate data was compromised. The Company engaged with us but made several paltry offers, did not want to pay what we asked for and decided they are okay with the data leak to happen instead of increasing their offer by a little, then we'd likely have accepted and this post would not have gone up. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 182GB+ (compressed) | Updated: 14 August 2026 | SHA256: 8a87ba511f25f20a193f05a6578a620b02302c2075a6f2dff428d1f1a826ba63 |
|||||
| Ransomware | Baxter International, Inc. id31678 View details | United States | — | — | |
|
Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 14 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Ali** ********** id31487 View details | China | Retail / E-commerce | ||
|
Ali** ********** is a retail and e-commerce company based in China, offering various products and services to customers. As a key player in the retail sector, the company operates in a highly competitive market. Ali** ********** was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Ali** ********** id31487 View details | China | Retail / E-commerce | ||
|
August 7, 2026 3:00 PM ET: Over 11.5 million records across Salesforce, ServiceNow, and Entra containing some PII of customers and employees and 3.1TB+ of internal corporate data was compromised. This is a final warning to reach out by 10 August 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 08 August 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Lumenis Ltd. id31160 View details | Israel | Healthcare / Pharma | — | |
|
Lumenis.com is a global leader in the field of minimally invasive clinical solutions, offering a range of medical devices and technologies for various healthcare applications. Based in Israel, the company operates in the healthcare and pharmaceutical sector, providing innovative solutions for medical professionals. Lumenis.com was listed as a ransomware victim associated with ShinyHunters |
|||||
| Ransomware | Questel SAS id31161 View details | France | IT | — | |
|
Questel.com is a French company operating in the IT sector, providing intellectual property solutions and services. The company offers a range of products and tools for patent and trademark searching, analysis, and management. Questel.com was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Lumenis Ltd. id31160 View details | Israel | Healthcare / Pharma | — | |
|
Over 1.1 million records containing some Pil of customers/employees and 176GB+ of internal corporate data was compromised. This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
|||||
| Ransomware | Questel SAS id31161 View details | France | IT | — | |
|
Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
|||||
| Ransomware | Alcon Inc. id31163 View details | Switzerland | Healthcare / Pharma | — | |
|
Alcon.com is a leading healthcare and pharma company based in Switzerland, offering a range of products and services in the eye care industry. The company operates globally, providing innovative solutions for vision care. Alcon.com was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Alcon Inc. id31163 View details | Switzerland | Healthcare / Pharma | — | |
|
Over 25 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
|||||
| Ransomware | BH Security, LLC. (brinkshome.com) id30972 View details | United States | Retail / E-commerce | — | |
|
Brinkshome.com is an e-commerce company based in the United States, operating in the retail sector. The company offers various products and services to its customers. Brinkshome.com was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | BH Security, LLC. (brinkshome.com) id30972 View details | United States | Retail / E-commerce | — | |
|
Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | RingCentral, Inc. id30973 View details | United States | Telecommunications | — | |
|
RingCentral is a telecommunications company based in the United States, offering cloud-based communication and collaboration solutions. The company provides services such as video conferencing, phone systems, and contact centers to businesses. RingCentral was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | RingCentral, Inc. id30973 View details | United States | Telecommunications | — | |
|
Over XX of data was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Ernst & Young id30974 View details | United States | Finance / Legal / Insurance | — | |
|
Ernst & Young is a multinational professional services firm based in the US, operating in the finance, legal, and insurance sectors, providing audit, tax, and advisory services. The company has a global presence, serving a wide range of clients. Ernst & Young was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Ernst & Young id30974 View details | United States | Finance / Legal / Insurance | — | |
|
Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files. This is a final warning to reach out by 31 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Abbott owned Exact Sciences Corporation id30568 View details | United States | Healthcare / Pharma | — | |
|
Exact Sciences Corporation is a US-based company operating in the healthcare and pharmaceutical sector, offering various medical solutions. As a leading provider of cancer screening and diagnostic tests, the company plays a significant role in the healthcare industry. Abbott owned Exact Sciences Corporation was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Abbott owned Exact Sciences Corporation id30568 View details | United States | Healthcare / Pharma | — | |
|
You wouldn't want us to describe what was exfiltrated from you publicly. This is a final warning to reach out by 18 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 15 July 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Fluke Corporation id30139 View details | United States | Manufacturing / Engineering | — | |
|
Fluke Corporation is a leading American company specializing in the manufacture, distribution, and service of electronic test tools and software. Based in the United States, the company operates within the manufacturing and engineering sector, providing a wide range of products and solutions. Fluke Corporation is known for its high-quality offerings, catering to various industries. It was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Fluke Corporation id30139 View details | United States | Manufacturing / Engineering | — | |
|
Over 21 million Salesforce records containing some PII were compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 100GB+ | Updated: 02 July 2026 | SHA256: 6ee9bd06756efceb56e5c56fd4e8ab3a8006b9cb80e7c0b4405ed15b996c05fe |
|||||
| Ransomware | Ingram Content Group, Inc. id30140 View details | United States | Retail / E-commerce | — | |
|
Ingram Content Group, Inc. is a leading US-based company operating in the retail and e-commerce sector, providing a wide range of services and offerings. The company is involved in book distribution, print-on-demand, and other related services. Ingram Content Group, Inc. was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Ingram Content Group, Inc. id30140 View details | United States | Retail / E-commerce | — | |
|
The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Updated: 02 July 2026 | SHA256: f3c961b709bcff8f70dbb8361116831d2c86361754a09658115b9efed39308e5 |
|||||
| Ransomware | Adapt****** id30014 View details | United Kingdom | IT | — | |
|
Adapt****** is an IT company based in the United Kingdom, providing various IT services. The company operates in the IT sector, offering its services to clients in GB. Adapt****** was listed as a ransomware victim associated with shinyhunters |
|||||
| Ransomware | Adapt****** id30014 View details | United Kingdom | IT | — | |
|
Data being leaked by today 12:00 AM New York time. | Updated: 25 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | icsecurity.com id29976 View details | United States | IT | — | |
|
Over 2.7 million records and other internal corporate data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 19 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Amazon owned OneMedical.com id29971 View details | United States | Healthcare / Pharma | — | |
|
Over 8.8TB of data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | NAIC.org id29972 View details | United States | Finance / Legal / Insurance | — | |
|
Over 3.1 terabytes of National Association of Insurance Commissioners data (105,000+ files) was compromised across the INSData statistical platform, Vision credit rating feeds, SERFF, OPTINS, UCAA, EDP, RDC, and state insurance department reporting systems (NAIC, all fifty state insurance departments, and thousands of licensed insurers), including 2.1 million insurer regulatory filing PDFs, 40,000 quarterly statistical CSVs with federal EINs and company data, 45,000+ licensed rating agency files from Moody's, Fitch, S&P, Kroll, DBRS, and AM Best with CUSIP and ISIN identifiers, statutory annual and quarterly financial statements, premium and loss statistics, and HR Ratings master data. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Service Notice: Scheduled Maintenance and Infrastructure Upgrades id29951 View details | — | — | ||
|
* The primary server hosting all leaked data is currently undergoing scheduled maintenance and will be unavailable for approximately 24 hours. * To improve your downloading experience, we are currently deploying multiple data mirrors to ensure faster, more reliable download speeds. Additionally, we will soon offer torrent links for all hosted files to provide a more robust distribution network. * No data has been lost as we keep several backups of everything that has been leaked on here since Day 1. These files will remain publicly accessible with ease till the end of time. We appreciate your patience as we upgrade our infrastructure. | Updated: 17 June 2026 |
|||||
| Ransomware | Ralph Lauren id29940 View details | United States | Retail / E-commerce | — | |
|
Over 220GB of data containing customer PII, purchase/trasnaction info, future unreleased releases from 2027 and onward, and more was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 163GB+ (compressed) | Updated: 16 June 2026 | SHA256: 17a7af9c00ea38ce822e2f022c0ceb5149535610a15f009b866d616e70cbf7e2 |
|||||
| Ransomware | icc.edu id29896 View details | United States | Education | — | |
|
Over 28 gigabytes of Illinois Central College data (122,000+ files) was compromised across PeopleSoft Campus Solutions and Human Resources (ICC, SURS pension reporting, Workday costing, and ICCB curriculum systems), including 9,200+ employee payslip PDFs, 500+ SURS payroll files with Social Security numbers, direct deposit records with bank account and routing numbers, student financial aid and grade roster exports, enrollment CSVs with @icc.edu accounts, and Workday salary allocation data spanning 2021 through June 2026. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | moody.edu id29897 View details | United States | Education | — | |
|
Over 23 gigabytes of Moody Bible Institute data (1,300+ files, tens of millions of records) was compromised across enrollment, donor relations, payroll, and communications systems (MBI, EDC/Salesforce leads, PeopleSoft PS_COMMUNICATION, Horizon SIS, WHPD donor database, and Cadence admissions), including 46 million communication records, 2.2 million enrollment lead records, 108,000 biodemographic master files with addresses and birthdates, 3.3 gigabytes of donor gift data, employee payroll XML with home addresses and earnings, 1,100+ admissions outreach files, and student housing assignment records. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | glendale.edu id29898 View details | United States | Education | — | |
|
Over 62 gigabytes of Glendale Community College data (304,000+ files) was compromised across PeopleSoft Campus Solutions (GCC, integrations, financial aid, and admission processing), including 150,000+ student records with names, dates of birth, and @student.glendale.edu emails, login and enrollment mapping files, new student enrollment CSVs, immunization compliance logs, admission checklist reports, financial aid batch exports, and transcript PDFs spanning September 2020 through June 2026. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | hccs.edu id29866 View details | United States | Education | — | |
|
Hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses. Daily and full student roster exports library credentials, PINs, and @student[.hccs[.edu accounts. Over 12,000 financial aid and bursar reports including FAFSA/ISIR suspense data with names, birthdates, emails, phones, and home addresses. Class rosters with birthdates, grades, academic programs, and contact information for tens of thousands of enrolled students per term. Over 344,000 international student documents including SEVIS I-20 forms, visa applications, passports, bank statements, tax returns, immigration affidavits, and acceptance letters. Over 14,000 student immunization and vaccination records including meningitis compliance documentation. Over 15,000 additional health and immunization documents across report archives and A LOT more was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | kodak.com id29867 View details | United States | Manufacturing / Engineering | — | |
|
Over 2.2 million records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Deep Well Services id29868 View details | Energy | — | ||
|
Over 7k records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Sysco Corporation id29869 View details | United States | Agriculture / Food | — | |
|
Over 61 million Salesforce records across several tables, some containing customer data/PII, employee data, and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | coe.int id29855 View details | France | NGOs / Associations | — | |
|
Over 297 GB of Council of Europe HR and payroll data (429,000+ files) was compromised across the Secretariat, Directorate of Human Resources, Parliamentary Assembly, EDQM, permanent and temporary staff, interpreters, conference services, language booth units, and payroll administration, including 409,000+ payslips for 10,000+ staff from 2011 to 2026, 14,000+ CVs and 3,700+ in-house personnel files, 10,700+ per-employee document stores, contract and purchase order records, mission travel overpayments, interpreter scheduling and 2026 salary scales, Blue List rosters, absence and illness reports, bank account and URSSAF payroll data, performance evaluations, and payroll exports, covering full names, employee IDs, home addresses, phone numbers, dates of birth, salaries, bank details, tax and social security information, medical and absence records, mission references, and other internal institutional data. This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 14 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Madison Square Garden Sports Corp. id29816 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Over 26 million records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group id29817 View details | United States | Retail / E-commerce | — | |
|
Hundreds of thousands of records containing PII (SSN, DOB, etc.), W-2 tax records, pay data, physical scans of government identity documents, drive licenses, and a lot more was compromised. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | American Tower Corporation id29818 View details | United States | Telecommunications | — | |
|
Over 5.2 million records consiting of a significant amount of customer and landowner PII, other records tied to other companies such as T-Mobile, Verizon, and the US DHS, several tower asset records containing GPS data and plaintext physical access/gate codes for cell tower compunds across the United States, thousands of internal corporate data, and a lot more were compromised. We urge you to reach out. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Zayo.com & Allstream.com id29819 View details | United States | Telecommunications | — | |
|
You wouldn't want us to describe what data was taken from you publicly here. A fair assessment of this breach in terms of criticality is a 9/10. We urge you to reach out. Read our emails. Failure to do so will result in the full publication and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Nexstar.tv id29782 View details | United States | Telecommunications | — | |
|
Over 1 million Salesforce records and other internal corporate data containing PII was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 June 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Ralph Lauren Corporation id29783 View details | United States | Retail / E-commerce | — | |
|
Over 220GB of data containing customer PII, purchase/trasnaction info, future unreleased releases from 2027 and onward, and more was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 June 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Notice id29753 View details | Other | — | ||
|
Notice is a French company operating in the **Other** sector; public search results do not provide enough reliable detail to confirm its exact offerings or location beyond that classification. In threat-intelligence listings, it appears as an entity identified by name rather than through a detailed corporate profile. The available record indicates it was listed as a ransomware victim associated with **ShinyHunters**. |
|||||
| Ransomware | nottingham.ac.uk id29708 View details | United Kingdom | Education | — | |
|
Over 40 GB of billing and payment records, credit card and payment details, student finance data, and campus portal exports from the University of Nottingham and its Malaysia and China campuses was compromised, including payer contact information, transaction amounts, IP addresses, full names, home addresses, postcodes, email addresses, phone numbers, dates of birth, and other internal campus data. | Size: 19GB+ (compressed) | Updated: 10 June 2026 | SHA256: d3aaaf06dd857deec3866072cc2876780623d880992e8d735094db4779535873 |
|||||
| Ransomware | DentaQuest, LLC. id29386 View details | United States | Other | — | |
|
The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 234GB+ (compressed) | Updated: 30 May 2026 | SHA256: db3088225c36be26ce2b458fa7a190176d071441e2e0830c0d82143e6323a3e1 |
|||||
| Ransomware | BCD Travel id29401 View details | Netherlands | Other | — | |
|
Over 700k Salesforce records and various Sharepoint sites corporate data has been compromised. This is a final warning to reach out by 1 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 29 May 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | DentaQuest, LLC id29452 View details | United States | Other | — | |
|
You wouldn't want us to describe what data and how much data was compromised. It is in your best interests to reply to us or we are leaking it all by the deadline. This is a final warning to reach out by 29 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 28 May 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Baker Distributing Company id29324 View details | United States | Other | — | |
|
Over 260k Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 27 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 23 May 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Charter Communications, Inc. id29325 View details | United States | Other | — | |
|
Over 42M records containing PII have been compromised. This is a final warning to reach out by 27 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 23 May 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | DentaQuest.com id29326 View details | United States | Other | — | |
|
You wouldn't want us to describe what data and how much data was compromised publicly. It is in your best interests to reply to us or we are leaking it all by the deadline. This is a final warning to reach out by 27 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 23 May 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Notification. id29085 View details | Other | — | ||
|
Notification is listed in the threat-intelligence index as an entity in the Other sector, with country information not clearly established in the available sources. The name alone does not identify a specific industry offering, so the safest description is a neutral one that avoids adding unverified business details. Public reporting on ShinyHunters describes the group as a financially motivated data-theft and extortion actor that targets organizations through social engineering and cloud-platform access. In this catalog, Notification was listed as a ransomware victim associated with shinyhunters. |
|||||
| Ransomware | PRESS STATEMENT 13/05/2026 id29088 View details | Other | — | ||
|
PRESS STATEMENT 13/05/2026 is a threat-intelligence catalog entry for an organization in the Other sector. Publicly available indexing does not identify its country, specific products, or services, so the listing should be treated as an unattributed victim record rather than a fully profiled company. The name appears to reflect a labeled incident entry rather than a descriptive business name, and no independent corporate background is available from the supplied sources. It was listed as a ransomware victim associated with shinyhunters. |
|||||
| Ransomware | Notification id29041 View details | Other | — | ||
|
Notification is a United States-based entity categorized in the Other sector, with no reliable public profile in the available record to confirm its exact business line or offerings. In threat-intelligence listings, the name is treated as a victim entry rather than a detailed corporate profile, so the safest description is that it appears as an affected organization in an external incident index. The available source material ties the listing to ShinyHunters, a financially motivated data-extortion group active against enterprise targets. It was listed as a ransomware victim associated with shinyhunters. |
|||||
| Ransomware | Houghton Mifflin Harcourt Company id28995 View details | United States | Education | — | |
|
Your data was compromised in several of our campaigns throughout the past few months. We urge you to engage with us, it is in your best interests. This is a final warning to reach out by 12 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 9 May 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Adelante Soluciones Financieras (Addi.com) id28859 View details | Colombia | Finance / Legal / Insurance | — | |
|
Over 16M unique persons records containing significant PII, financial/transactions (credit cards), KYC and data from TransUnion and Experian (background checks) . The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 518GB+ (compressed) | Updated: 5 May 2026 | SHA256: 520d50dc384fc474e419fdd19cb3517ed6ce778a187ae7d6f44b93ccef5687db |
|||||
| Ransomware | Entire list of affected schools by Instructure breach id28861 View details | IT | — | ||
|
Entire list of affected schools by Instructure breach refers to the school list associated with Instructure, the U.S.-based educational technology company behind the Canvas learning management system used by schools and universities. Instructure provides cloud-based software that supports online coursework, class communication, and digital learning administration for education institutions. Reporting on the incident describes ShinyHunters as the extortion group behind the campaign and says the affected institutions span thousands of schools and districts. The listing is categorized as a ransomware victim and is associated with ShinyHunters. |
|||||
| Ransomware | Instructure Holdings, Inc. (Canva LMS, instructure.com) id28796 View details | United States | Education | — | |
|
Nearly 9,000 schools worldwide affected. 275 million individuals data ranging from students, teachers, and other staff containing PII. Several billions of private messages among students and teachers and students and other students involved, containing personal conversations and other PII. Your Salesforce instance was also breached and a lot more other data is involved. Pay or Leak. This is a final warning to reach out by 6 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Size: 3.65TB+ (uncompressed) | Updated: 3 May 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Cushman & Wakefield Inc. id28791 View details | United States | Construction / Real Estate | — | |
|
Over 500k Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 6 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 3 May 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | TOWERPOINT WEALTH, LLC id28402 View details | United States | Finance / Legal / Insurance | — | |
|
Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 4 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 1 May 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Follett Software LLC id28403 View details | United States | Education | — | |
|
Over 4M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 4 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 1 May 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Vimeo, Inc. id28511 View details | United States | IT | — | |
|
Your Snowflake and Bigquery instances data was compromised thanks to Anodot.com. Pay or Leak. This is a final warning to reach out by 30 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 28 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Udemy, Inc. (udemy.com) id28654 View details | United States | Education | — | |
|
Over 1.4M records containing PII and other internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 27 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 24 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | ADT, Inc. (adt.com) id28655 View details | United States | Services | — | |
|
Over 10M records containing PII and other internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 27 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 24 Apri 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Aman Resorts (aman.com) id28749 View details | Singapore | Hospitality / Food & Beverage / Tourism | — | |
|
Over 500k Salesforce records containing PII have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | The Canada Life Assurance Company (canadalife.com) id28750 View details | Canada | Finance / Legal / Insurance | — | |
|
Over 5.6M Salesforce records containing PII have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Pitney Bowes Inc. (pb.com) id28751 View details | United States | Transportation / Travel / Logistics | — | |
|
Over 25M Salesforce records containing PII have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | 7-Eleven, Inc. (7-eleven.com) id28752 View details | United States | Retail / E-commerce | — | |
|
Over 600k Salesforce records containing PII and other internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Carnival Corporation & plc (carnivalcorp.com) id28753 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Over 8.7M records containing PII and other terabytes of internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Zara (zara.com) id28754 View details | Spain | Retail / E-commerce | — | |
|
Your Bigquery instances data was compromised thanks to Anodot.com. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Alert 360 Opco Inc. (alert360.com) id28755 View details | United States | Services | — | |
|
Over 2.5M records containing PII and other internal corporate data have been compromised. Please read the chatlog of the negociation by cliking the Download button below to see why this data was leaked. | Size: 10GB+ (compressed) | Updated: 18 Apr 2026 | SHA256: 9c5c8225f27a23f1a03526bfd15dad02b5976797664a92bdd53b23f5f9ef3fe3 |
|||||
| Ransomware | Rockstar Games id28086 View details | United States | IT | — | |
|
Your Snowflake instances metrics data was compromised thanks to Anodot.com. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Abrigo, Inc. id28085 View details | United States | Finance / Legal / Insurance | — | |
|
Over 1.7M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Marcus & Millichap, Inc. id28084 View details | United States | Construction / Real Estate | — | |
|
Over 30M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Kemper Corporation id28083 View details | United States | Finance / Legal / Insurance | — | |
|
Over 13M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Ryan, LLC. id28082 View details | Finance / Legal / Insurance | — | ||
|
Over 4.8M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | McGraw Hill, Inc. (mheducation.com) id28081 View details | United States | Education | — | |
|
Over 45M Salesforce records containing PII data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | National Railroad Passenger Corporation (amtrak.com) id28080 View details | United States | Transportation / Travel / Logistics | — | |
|
Over 9.4M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||