Ransomware Group intelligence
Shinyhunters
ActiveTrack Shinyhunters with 181 published victims and 4 known leak locations in a single intelligence view.
Overview
Shinyhunters is tracked by Breach House as a ransomware group with 181 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Up checked 4h ago | shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onion |
| Leak location 2 | Web location | Up checked 4h ago | breachforums.hn |
| Leak location 3 | Onion service | Down checked 4h ago | toolatedhs5dtr2pv6h5kdraneak5gs3sxrecqhoufc5e45edior7mqd.onion |
| Leak location 1 | Onion service | Down checked 4h ago | shinypogk4jjniry5qi7247tznop6mxdrdte2k6pdu5cyo43vdzmrwid.onion |
Top Activity Sectors (17)
- Communication / Marketing 23
- Retail / E-commerce 18
- IT 16
- Not identified 15
- Education 14
- Finance / Legal / Insurance 13
- Services 11
- Healthcare / Pharma 10
- Transportation / Travel / Logistics 8
- Manufacturing / Engineering 5
- Hospitality / Food & Beverage / Tourism 5
- Telecommunications 4
- Construction / Real Estate 4
- Energy 3
- Public Sector 2
- Agriculture / Food 1
- NGOs / Associations 1
Typical Attacks (46)
▼How Shinyhunters typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via ShinyHunters.
-
T1589.001 Credentials Reconnaissance
What they do: ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.
What that means: Adversaries may gather credentials that can be used during targeting.
-
T1593.003 Code Repositories Reconnaissance
What they do: ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.
What that means: Adversaries may search public code repositories for information about victims that can be used during targeting.
-
T1595.002 Vulnerability Scanning Reconnaissance
What they do: ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.
What that means: Adversaries may scan victims for vulnerabilities that can be used during targeting.
-
T1598 Phishing for Information Reconnaissance
What they do: ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.
What that means: Adversaries may send phishing messages to elicit sensitive information that can be used during targeting.
-
T1598.003 Spearphishing Link Reconnaissance
What they do: ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials.
What that means: Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
-
T1583.001 Domains Resource Development
What they do: ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data.
What that means: Adversaries may acquire domains that can be used during targeting.
-
T1583.004 Server Resource Development
What they do: ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.
What that means: Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting.
-
T1585.002 Email Accounts Resource Development
What they do: ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.
What that means: Adversaries may create email accounts that can be used during targeting.
-
T1587.004 Exploits Resource Development
What they do: ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.
What that means: Adversaries may develop exploits that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1588.007 Artificial Intelligence Resource Development
What they do: ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.
What that means: Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting.
-
What they do: ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments.
What that means: Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1195.001 Compromise Software Dependencies and Development Tools Initial Access
What they do: ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.
What that means: Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
-
T1059.007 JavaScript Execution
What they do: ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems.
What that means: Adversaries may abuse various implementations of JavaScript for execution.
-
T1059.009 Cloud API Execution
What they do: ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.
What that means: Adversaries may abuse cloud APIs to execute malicious commands.
-
What they do: ShinyHunters has abused software deployment tools for lateral movement.
What that means: Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
-
T1203 Exploitation for Client Execution Execution
What they do: ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks.
What that means: Adversaries may exploit software vulnerabilities in client applications to execute code.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1684 Social Engineering Stealth
What they do: ShinyHunters has used social engineering to demand payment from victims.
What that means: Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instructions (i.e., introduction of malicious payloads or software), while minimizing technical indicators.
-
T1110 Brute Force Credential Access
What they do: ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1528 Steal Application Access Token Credential Access
What they do: ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository.
What that means: Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
-
T1552.001 Credentials In Files Credential Access
What they do: ShinyHunters has gathered PII from database infrastructure.
What that means: Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
-
T1016 System Network Configuration Discovery Discovery
What they do: ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1069.003 Cloud Groups Discovery
What they do: ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.
What that means: Adversaries may attempt to find cloud groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1580 Cloud Infrastructure Discovery Discovery
What they do: ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.
What that means: An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.
-
T1619 Cloud Storage Object Discovery Discovery
What they do: ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.
What that means: Adversaries may enumerate objects in cloud storage infrastructure.
-
T1210 Exploitation of Remote Services Lateral Movement
What they do: ShinyHunters has exploited vulnerabilities in remote services for lateral movement.
What that means: Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
-
T1550.001 Application Access Token Lateral Movement
What they do: ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.
What that means: Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems.
-
T1213.003 Code Repositories Collection
What they do: ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.
What that means: Adversaries may leverage code repositories to collect valuable information.
-
T1213.006 Databases Collection
What they do: ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.
What that means: Adversaries may leverage databases to mine valuable information.
-
T1530 Data from Cloud Storage Collection
What they do: ShinyHunters has collected data from insecure cloud buckets.
What that means: Adversaries may access data from cloud storage.
-
T1560.002 Archive via Library Collection
What they do: ShinyHunters has used the following command to compress collected data: ` pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst `.
What that means: An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: ShinyHunters has used Tor to host their DLS.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: ShinyHunters has established a connection between the staging host and the C2 using SSH.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1567 Exfiltration Over Web Service Exfiltration
What they do: ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data.
What that means: Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.
-
T1485 Data Destruction Impact
What they do: ShinyHunters has executed the `DeleteBucket` API call to delete buckets.
What that means: Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
-
T1491.001 Internal Defacement Impact
What they do: ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1657 Financial Theft Impact
What they do: ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Victims (181)
Search, filter and paginate the victim timeline for Shinyhunters. Showing 101–181 of 181.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Mytheresa id28079 View details | Germany | Retail / E-commerce | — | |
|
Sensitive customer PII data and transactional history data was compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK |
|||||
| Ransomware | Cisco Systems, Inc. (cisco.com) id27796 View details | United States | IT | — | |
|
3 breaches ( UNC6040 , Salesforce Aura, and AWS accounts). Total over 3M Salesforce records containing PII, Github repositories, AWS buckets and other internal corporate data have been compromised. This is a final warning to reach out by 3 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 31 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Hallmark Cards, Inc. & Hallmark Plus id27761 View details | United States | Retail / E-commerce | — | |
|
Over 7.9M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 2 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 31 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | European Commission (*.europa.eu) id27648 View details | Public Sector | — | ||
|
Over 350 GB+ of data was compromised, including data dumps of mail servers, databases, confidential documents, contracts, and much more sensitive material. | Size: 350GB+ (uncompressed) | Updated: 28 Mar 2026 | SHA256: 697c5cfbc64fa5cfbe3dd59a5cb4a2ee10ade8c53ef4c36f3ab3c7e1e35ff66e |
|||||
| Ransomware | BreachForums version 5 id27608 View details | IT | — | ||
|
BreachForums has been run by many fakes, but by us, following the FBI seizure on 10 Oct 2025. Maintaining such an ecosystem is a waste of our time. There was an unauthorised leak on 9 Jan 2026. Ever since then, false personas going by “N/A“ and “Indra“ were successfully able to restore a similar-looking “legitimate“ forum. All the current forums are fake [ .sb, .ac, .fi, .bf, .us, ect.]. If they continue to exist, we'll leak all the BF backups, including every private message, emails, IP addresses, posts, ect. We have exploits for all 1.8 versions of MyBB. |
|||||
| Ransomware | ZenBusiness, Inc. id27578 View details | United States | Finance / Legal / Insurance | — | |
|
Several terabytes from Snowflake, Mixpanel, Salesforce, and ect. have been compromised. This is a final warning to reach out by 30 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 26 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Berkadia Commercial Mortgage, LLC. (berkadia.com) id27558 View details | United States | Construction / Real Estate | — | |
|
Salesforce records containing PII and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care. | Size: 27GB (compressed) | Updated: 25 Mar 2026 | SHA256: 2ae1c2804c01f5894143620518ec41fceb98e330f408c7f38e3d6ef93ebe8f21 |
|||||
| Ransomware | Ameriprise Financial, Inc. id27518 View details | United States | Finance / Legal / Insurance | — | |
|
Salesforce records containing PII and over 200GB compressed Sharepoint internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Infinite Campus, Inc. id27517 View details | United States | Education | — | |
|
Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Berkadia Commercial Mortgage LLC id27457 View details | United States | Finance / Legal / Insurance | — | |
|
Over 5M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 22 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 19 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Aura Group, Inc. (aura.com) id27345 View details | United States | Other | — | |
|
Over 2M records containing PII and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care. | Size: 12GB (compressed) | Updated: 15 Mar 2026 | SHA256: 0d5bf85c7865b023266adc95a7449dd1bff6b208b4634976441ce5ee650894d0 |
|||||
| Ransomware | Aura Group, Inc id27279 View details | United States | Communication / Marketing | — | |
|
Over 2M records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 14 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | CFGI Management (cfgi.com) id27217 View details | United States | Services | — | |
|
Over 800k records containing PII and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors. | Updated: 10 Mar 2026 | SHA256: 1dbf6b9a06960cc8c4043de9f94a2494845b96d07a8a14aab89099ced8baef0c |
|||||
| Ransomware | Vertex Inc. id27216 View details | United States | Communication / Marketing | — | |
|
Over 2M records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 12 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 10 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Salesforce Aura Campaign id27215 View details | Retail / E-commerce | — | ||
|
Several hundreds of companies set to release with FINAL WARNINGs upon failure to comply. To all affected companies who will be or are being contacted by us ("ShinyHunters"), please consider this a preliminary warning before we release your name with FINAL WARNING or a complete data leak. Reply, engage, pay a small price, and prevent a publication. Make the right decision, don't be the next headline. | Updated: 10 Mar 2026 | Warning: NOTICE OF WARNING |
|||||
| Ransomware | CFGI Management, LLC. id27114 View details | United States | Services | — | |
|
Over 800k records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 09 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 06 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Pathstone.com id27113 View details | United States | Communication / Marketing | — | |
|
Salesforce records were compromised and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors. | Size: 15GB (compressed) | Updated: 06 Mar 2026 | SHA256: 6377f58fe8229bc376bbcf6acc32d00cdfb0ac415b8660106f29ca14fa6d0561 |
|||||
| Ransomware | Woflow, Inc. id26996 View details | United States | Communication / Marketing | — | |
|
Several hundreds of millions of records containing PII, transaction/order data, other internal corporate data, and a lot more (you don't want us to say publicly) have been compromised. This is a final warning to reach out by 05 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 03 Mar 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | Pathstone Family Office, LLC id26886 View details | United States | Communication / Marketing | — | |
|
Over 641k records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 2 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 Feb 2026 | Warning: FINAL WARNING |
|||||
| Ransomware | University of Pennsylvania id26787 View details | United States | Education | — | |
|
Records: 1.2M Records | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you. |
|||||
| Ransomware | Harvard University id26786 View details | United States | Education | — | |
|
Size: 1.1GB (compressed) | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you. |
|||||
| Ransomware | Figure Technology Solutions, Inc. id26785 View details | United States | IT | — | |
|
Size: 2.5GB (compressed) | Updated: 13 Feb 2026 | Note: Pay or be humiliated. | They were given multiple chances to pay the ransom, but they decided to waste time and hide instead. |
|||||
| Ransomware | Canada Goose id26784 View details | Canada | Other | — | |
|
Updated: 15 Feb 2026 |
|||||
| Ransomware | CarGurus, Inc. id26783 View details | United States | Communication / Marketing | — | |
|
Size: 6.1GB (compressed) | Updated: 21 Feb 2026 |
|||||
| Ransomware | Mercer Advisors id26782 View details | United States | Other | — | |
|
Updated: 21 Feb 2026 |
|||||
| Ransomware | Beacon Pointe Advisors id26781 View details | United States | Communication / Marketing | — | |
|
Size: 60GB (compressed) | Updated: 22 Feb 2026 |
|||||
| Ransomware | Odido NL & Ben.nl id26780 View details | Netherlands | Other | — | |
|
Records: ~21M Records | Updated: 24 Feb 2026 |
|||||
| Ransomware | Bumble Inc. id25896 View details | United States | Services | — | |
|
Updated: 29 Jan 2026 |
|||||
| Ransomware | Match Group id25858 View details | United States | Services | — | |
|
Records: 10M Records | Updated: 28 Jan 2026 | Note: Your greed is killing you. | Don't be an idiot like this company. Make the right decision; don't be the next headline. Get off your moral high horse and make the right decision for your stakeholders. PAY OR LEAK otherwise you'll be made an example of. |
|||||
| Ransomware | Panera Bread id25836 View details | United States | Other | — | |
|
Records: 14M Records | Updated: 27 Jan 2026 | Note: Don't be the next headline. | Don't be an idiot like this company. Make the right decision, don't be the next headline. |
|||||
| Ransomware | Edmunds.com, Inc. id25736 View details | United States | Communication / Marketing | — | |
|
Size: 12 GB (compressed) | Updated: 24 Jan 2026 |
|||||
| Ransomware | CarMax, Inc. id25732 View details | United States | Communication / Marketing | — | |
|
Size: 1.7 GB (compressed) | Records: 500k Records | Updated: 24 Jan 2026 |
|||||
| Ransomware | SoundCloud id25719 View details | Germany | IT | — | |
|
Size: 2.8 GB (compressed) | Records: 30M Records | Updated: 23 Jan 2026 |
|||||
| Ransomware | Crunchbase, Inc. id25718 View details | United States | Communication / Marketing | — | |
|
Size: 1.3 GB (compressed) | Records: 2M Records | Updated: 23 Jan 2026 |
|||||
| Ransomware | Betterment, LLC. id25717 View details | United States | Communication / Marketing | — | |
|
Size: 1.6 GB (compressed) | Records: 20M Records | Updated: 23 Jan 2026 | Note: Betterment better(get some)help | Betterment refused our generous offers as low as $0.95 per active customer record stolen. If you are a Betterment customer, remember that they value your privacy and peace of mind lower than the price of a roll of toilet paper. |
|||||
| Ransomware | Engie Resources id22969 View details | United States | Energy | ||
|
[AI generated] Engie Resources is a subsidiary of Engie, a global energy player. The company provides commercial and industrial customers with comprehensive energy solutions, including electricity supply, natural gas, renewable energy, and demand response capabilities. They are committed to responsible energy management and deliver custom strategies to help their clients control energy costs, manage risk, and influence energy infrastructure development. |
|||||
| Ransomware | Albertsons Companies, Inc. id22968 View details | United States | Retail / E-commerce | ||
|
[AI generated] Albertsons Companies, Inc. is one of the largest food and drug retailers in the United States, serving millions of customers each week. The company operates stores across 35 states and the District of Columbia under 20 leading banners including Albertsons, Safeway, Vons, and Jewel-Osco. In addition to its retail operations, Albertsons also has a health and wellness business and a private brand portfolio. |
|||||
| Ransomware | Qantas Airways Limited id22967 View details | Australia | Transportation / Travel / Logistics | ||
|
qantas.com is the official website of Qantas, Australia’s flag carrier and a major airline group headquartered in Australia. The Qantas Group focuses on transporting passengers and freight through its airline brands, including Qantas and Jetstar, across domestic and international routes. As a transportation, travel, and logistics business, it supports flight booking, customer service, and broader airline operations for travelers and commercial customers. In the threat-intelligence index, qantas.com was listed as a ransomware victim associated with shinyhunters. |
|||||
| Ransomware | Telstra id22894 View details | Australia | Communication / Marketing | ||
|
[AI generated] Telstra Corporation Limited is the largest telecommunications and media company in Australia. Founded in 1975 and based in Melbourne, it provides a wide range of services domestically and internationally. These include broadband and internet products and services, mobile, digital television, radio and satellite services. Telstra also offers a host of technology products such as cloud storage and data security. |
|||||
| Ransomware | Red Hat, Inc. id22820 View details | United States | IT | ||
|
[AI generated] Red Hat, Inc. is a leading American multinational software company that provides open-source software products to businesses. It became a subsidiary of IBM in 2019. The company is best known for Red Hat Enterprise Linux, a top-level operating system. Other notable offering includes its architecture service, cloud computing (virtualization), and storage solutions. |
|||||
| Ransomware | S&P Global (spglobal.com) id22817 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] S&P Global is an American company that provides high-quality market intelligence in the form of credit ratings, analytics, data, and insights to help customers make informed decisions. It operates through four divisions: S&P Global Ratings, S&P Global Market Intelligence, S&P Dow Jones Indices, and S&P Global Platts, covering various sectors like energy, finance, commodities, and technology. |
|||||
| Ransomware | CIC Vietnam id22816 View details | Viet Nam | Services | ||
|
[AI generated] CIC Vietnam is a Vietnamese consultancy firm that helps its clients develop business strategies and investment projects. It provides services such as market research, business planning, investment advisory, and project management. The company leverages local industry expertise and international business standards to assist both local and foreign companies. |
|||||
| Ransomware | IKEA id22786 View details | Sweden | Retail / E-commerce | ||
|
[AI generated] IKEA is a Swedish-based multinational company that designs and sells ready-to-assemble furniture, kitchen appliances, and home accessories. It's known worldwide as an industry leader for affordable, modern, flat-packed furniture. Founded in 1943 by Ingvar Kamprad, IKEA has over 400 stores in 50 countries, making it one of the largest furniture retailers globally. |
|||||
| Ransomware | Chanel id22785 View details | France | Communication / Marketing | ||
|
[AI generated] Chanel is a renowned French luxury fashion house founded by designer Coco Chanel in 1910. Specializing in women's haute couture, ready-to-wear clothes, luxury goods, and fashion accessories, Chanel has a significant influence in the world of fashion. In addition to its clothing line, Chanel also produces fragrances, most notably No. 5, and high-end cosmetic products. The company's logo, two interlocked C's, is globally recognizable. |
|||||
| Ransomware | TransUnion id22784 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] TransUnion is a global credit reporting agency that provides credit information and analytics services to businesses and individual consumers. It collects and aggregates information on over a billion individual consumers in over thirty countries including "Big Three" credit-reporting agencies in the United States. The data they handle includes credit history, credit scoring, and personal information protection services. |
|||||
| Ransomware | Pandora.net id22783 View details | Denmark | IT | ||
|
[AI generated] Pandora.net is the official website of Pandora A/S, a company based in Denmark. It specializes in the design, manufacturing, and selling of high-quality hand-finished jewelry. Pandora's product range includes bracelets, charms, rings, earrings, and necklaces, among others. Its jewelry combines traditional crafting techniques with modern technology. They target customers seeking affordable luxury jewelry. |
|||||
| Ransomware | Cisco id22782 View details | United States | IT | ||
|
[AI generated] Cisco Systems, Inc. is a multinational company based in San Jose, California. It specializes in developing and selling networking hardware, high-technology services, and products. Founded in December 1984, it has been paving the way for digital innovation primarily in the IT industry. Much of the internet protocols and its infrastructure are driven by Cisco's technological advancements. |
|||||
| Ransomware | Google Adsense id22781 View details | United States | Communication / Marketing | ||
|
[AI generated] Google AdSense is a program run by Google through which website publishers in the Google Network of content sites serve text, image, video, or interactive media advertisements, that are targeted to site content and audience. These advertisements are administered, sorted, and maintained by Google, providing a revenue generating opportunity for publishers. |
|||||
| Ransomware | Air France & KLM id22780 View details | France | Transportation / Travel / Logistics | ||
|
[AI generated] Air France & KLM is an international airline partnership under the parent company Air France-KLM Group. Based respectively in France and Netherlands, the airlines provide passenger and cargo services globally. Offering premium and economy services, they operate in major domestic and international routes. The brands stand for comfort, reliability, and customer service. The loyalty programme 'Flying Blue' rewards frequent flyers. |
|||||
| Ransomware | 1-800Accountant id22779 View details | United States | Services | ||
|
[AI generated] 1-800Accountant is a nationwide virtual accounting firm merging the convenience of technology with proactive professional services to provide small businesses with tax, accounting and advisory services. They serve start-ups, small and medium-sized businesses across various industries. The services include tax preparation and planning, bookkeeping, payroll, entity formation, tax planning and audit defense. Their mission is to make accounting and taxes easy and affordable for individuals and small businesses. |
|||||
| Ransomware | Saks Fifth id22778 View details | United States | Retail / E-commerce | ||
|
[AI generated] Saks Fifth Avenue is a luxury retail store originating from the United States. It is renowned for its high-end offerings in clothing, shoes, handbags, jewelry, beauty products, and home goods. Founded in 1867, Saks has garnered global recognition with its flagship store located on Fifth Avenue, New York City. The company also operates numerous department and outlet stores across the United States and online platforms. |
|||||
| Ransomware | CarMax id22777 View details | United States | Communication / Marketing | ||
|
[AI generated] CarMax is a leading car dealership company in the United States that specializes in used cars. The company offers a unique car buying experience to its customers with its no-haggling and fair pricing model. In addition, CarMax also offers financing options and a wide range of car types, makes and models. They are renowned for their thorough inspections, warranties, and return policy. |
|||||
| Ransomware | Qantas Airways id22776 View details | Australia | Transportation / Travel / Logistics | ||
|
[AI generated] Qantas Airways, an Australian-based airline, is indeed one of the oldest in the world, having been founded in 1920. Known for its excellent service, the company offers both international and domestic routes, with a reputation for safety and comfort. Qantas operates a mix of short, medium, and long-haul flights, and is part of the OneWorld airline alliance. |
|||||
| Ransomware | TripleA (aaa.com) id22775 View details | Singapore | Services | ||
|
[AI generated] TripleA is a fintech company that aims to simplify cryptocurrency transactions. It provides a business-to-business platform for companies to accept Bitcoin and other cryptocurrency payments. Using blockchain technology, TripleA converts received cryptocurrencies into a local currency, mitigating exchange rate risks. It also supports cross-border transactions, enabling businesses globally to accept cryptocurrency payments from any country. |
|||||
| Ransomware | Adidas id22774 View details | Germany | Communication / Marketing | ||
|
[AI generated] Adidas is a multinational corporation, founded in Germany in 1949. It is one of the largest sportswear manufacturers in the world, known for its signature three-stripe logo. Adidas designs and produces a wide range of athletic and casual clothing, shoes, and accessories. The brand has substantial influence in sports like football, basketball, and athletics, sponsoring numerous teams and athletes globally. |
|||||
| Ransomware | Cartier id22773 View details | France | Communication / Marketing | ||
|
[AI generated] Cartier is a renowned French luxury goods conglomerate that specializes in designing, manufacturing, and selling high-end jewelry and watches. Since its founding in 1847 by Louis-François Cartier in Paris, it has become globally recognized for its elegant, high-quality items, symbolizing prestige and opulence. It further diversifies into perfumes and accessories. Its products are adorned by many celebrities and royals. |
|||||
| Ransomware | Puma id22772 View details | Germany | Communication / Marketing | ||
|
[AI generated] Puma is a globally renowned German multinational corporation that designs and manufactures athletic and casual footwear, apparel, and accessories. The company, founded in 1948 by Rudolf Dassler, is one of the top sporting brands worldwide. Puma sponsors numerous high-profile athletes and teams across different sports globally. The headquarters are located in Herzogenaurach, Germany. |
|||||
| Ransomware | Petco id22771 View details | United States | Communication / Marketing | ||
|
[AI generated] Petco is a leading pet specialty retailer in the US providing essential pet products and services. Founded in 1965, it offers a variety of pet food, supplies, and services such as grooming and dog training. Petco operates more than 1,500 locations across the US and Puerto Rico. Its goal is to improve the lives of pets, pet parents, and Petco employees. |
|||||
| Ransomware | Instacart id22770 View details | United States | Retail / E-commerce | ||
|
[AI generated] Instacart is an American company that operates as a same-day grocery delivery and pick-up service in the U.S. and Canada. Customers shop for groceries through their mobile app or website from participating stores. The purchased items are delivered to customers' doorsteps by a personal shopper. |
|||||
| Ransomware | HBO Max id22769 View details | United States | Communication / Marketing | ||
|
[AI generated] HBO Max is a premium streaming service offered by Home Box Office, Inc., a subsidiary of WarnerMedia Entertainment. Launched in 2020, it delivers a vast library of personalized content like original series, theatrical films, and specials directly to viewers. It combines HBO's content with shows, movies, and originals from Warner Bros., DC, CNN, TNT, TBS, and more. |
|||||
| Ransomware | Kering (Gucci, Balenciaga, Brioni, AlexMcQ) id22768 View details | France | Construction / Real Estate | ||
|
[AI generated] Kering is a global luxury group that manages the development of renowned houses in fashion, such as Gucci, Balenciaga, Brioni, and Alexander McQueen. These brands are popular in clothing, leather goods, footwear, and accessories sector. Kering, based in Paris, France, empowers its brands to reach their potential in the most imaginative and sustainable manner. |
|||||
| Ransomware | Engie Resources (Plymouth) id22767 View details | United States | Energy | ||
|
[AI generated] Engie Resources (Plymouth) is one of the leading energy providers in the United States. The company operates from Plymouth, Massachusetts, and offers competitive electricity and gas plans for large and medium-sized businesses, local authorities, and institutions. As part of the global ENGIE group, it emphasizes renewable energy and sustainable business practices. From energy procurement to risk management and advising services, they provide comprehensive energy solutions. |
|||||
| Ransomware | Albertsons (Jewel Osco, etc) id22766 View details | United States | Retail / E-commerce | ||
|
[AI generated] Albertsons Companies Inc. is one of the largest American grocery corporations, founded by Joe Albertson in 1939. It operates stores across 34 states under 20 well-known banners including Albertsons, Safeway, Vons, Jewel-Osco, Shaw’s, Acme, Tom Thumb, Randalls, United Supermarkets, Pavilions, Star Market, and Carrs. It remains a leader in the supermarket industry, offering grocery products, pharmacy services, and specialty food products. |
|||||
| Ransomware | Instructure.com - Canvas id22765 View details | United States | IT | ||
|
[AI generated] Instructure Inc. is a technology company that developed the Canvas Learning Management System (LMS). Founded in 2008, Canvas is used by educators and students worldwide to connect and integrate digital learning resources into a school's curriculum. Upgraded features include assessment and reporting tools, plus customizable apps. They also offer Bridge, an employee development and engagement software for businesses. |
|||||
| Ransomware | Fujifilm id22764 View details | Japan | Healthcare / Pharma | ||
|
[AI generated] Fujifilm is a globally recognized Japanese multinational corporation known for its innovative contributions to the photography and imaging industry. Founded in 1934, Fujifilm's portfolio now includes products and services in fields such as medical imaging, graphic arts, optical devices, and data storage. With decades of research and technological advancement, the firm continues to influence photography and other industries worldwide. |
|||||
| Ransomware | HMH (hmhco.com) id22763 View details | United States | Education | ||
|
[AI generated] HMH, or Houghton Mifflin Harcourt, is a long-established publishing company specializing in educational content. They provide a variety of instructional technology, assessments, and other learning materials to schools in over 150 countries. The company also publishes a number of well-known trade and reference works, alongside children's books. Their goal is to foster a lifelong love of learning in every individual they serve. |
|||||
| Ransomware | GAP, INC. id22762 View details | United States | Retail / E-commerce | ||
|
[AI generated] GAP, INC. is an American multinational clothing and accessories retailer. The company was founded in San Francisco, California by Donald Fisher and Doris F. Fisher in 1969. The company operates several well-known brands apart from Gap itself, including Banana Republic, Old Navy, Intermix, Hill City and Athleta. Known for its casual style, Gap is one of the largest apparel retailers in the world. |
|||||
| Ransomware | ASICS id22761 View details | Japan | Healthcare / Pharma | ||
|
[AI generated] ASICS is a globally recognized Japanese athletic equipment company. Founded in 1949 by Kihachiro Onitsuka, ASICS primarily manufactures high-performance footwear, apparel and accessories for a variety of sports. The name "ASICS" stands for the Latin phrase, "Anima Sana In Corpore Sano" which translates to "Healthy Soul In A Healthy Body". Known for their innovative technologies, ASICS promotes health and fitness worldwide. |
|||||
| Ransomware | KFC id22760 View details | United States | Retail / E-commerce | ||
|
[AI generated] KFC (Kentucky Fried Chicken) is a world-renowned fast food restaurant chain known for its fried chicken. It was founded by Colonel Harland Sanders in 1952 in Kentucky, USA. The brand is now a subsidiary of Yum! Brands and operates over 23,000 outlets globally. KFC's secret recipe of "11 herbs and spices" is a distinctive feature of their products. The company also offers burgers, sides and drinks, among other items. |
|||||
| Ransomware | McDonalds id22759 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
[AI generated] McDonald's is a global fast-food chain, established in the USA in 1940 by Richard and Maurice McDonald. It is renowned for its hamburgers, french fries, breakfast items, soft drinks, and desserts. Primarily, the business model is based on franchising, operating over 38,700 restaurants in over 100 countries worldwide. The Golden Arches logo is globally recognized. |
|||||
| Ransomware | Stellantis id22758 View details | Netherlands | Manufacturing / Engineering | ||
|
[AI generated] Stellantis N.V. is a multinational automotive manufacturing corporation, formed through the merger of Fiat Chrysler Automobiles and Group PSA on January 17, 2021. It is the parent company of 14 different automotive brands which include household names such as Peugeot, Citroën, Fiat, Chrysler, and Maserati. Stellantis is based in Amsterdam for tax reasons, but its operational headquarters are in London, UK, and Auburn Hills, Michigan, USA. |
|||||
| Ransomware | Walgreens id22757 View details | United States | Healthcare / Pharma | ||
|
[AI generated] Walgreens is an American pharmaceutical retail company, established in 1901. It is one of the largest US drugstore chains, known for selling prescription and non-prescription drugs, health and wellness products, cosmetics, and groceries. It also offers health services like immunization and patient care clinics. Often, Walgreens operates 24/7 to allow customers access to their products and services at any hour. |
|||||
| Ransomware | Vietnam Airlines id22756 View details | Viet Nam | Transportation / Travel / Logistics | ||
|
[AI generated] Vietnam Airlines is the national flag carrier of Vietnam, founded in 1956. Headquartered in Long Bien District, Hanoi, the airline operates flights across Asia, Europe, and Oceania. It is a member of SkyTeam, marking its status among global standards of aviation. Its fleet includes modern aircraft such as Airbus A350, Boeing 787, and A320. The airline embodies cultural elements of Vietnam in its service. |
|||||
| Ransomware | Marriott id22755 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
[AI generated] Marriott International is a renowned multinational hospitality company, headquartered in Maryland, USA. Founded in 1927, it operates a broad portfolio of hotels and related lodging facilities globally. Offerings include diverse properties from luxury to economy chain brands. As of today, Marriott has more than 7,000 properties in over 130 countries and territories, making it one of the world's largest hotel companies. |
|||||
| Ransomware | Home Depot id22754 View details | United States | Communication / Marketing | ||
|
[AI generated] Home Depot is the largest home improvement retailer in the United States. It is a one-stop-shop for tools, construction products, and various services. The company caters to do-it-yourself (DIY) customers, professional contractors, and the construction industry. It offers installation services and tool and equipment rental in addition to selling a litany of home improvement items. |
|||||
| Ransomware | Aeroméxico id22753 View details | Mexico | Services | ||
|
[AI generated] Aeroméxico is Mexico's flag carrier and a major international airline. Established in 1934, it operates scheduled services to more than 90 destinations in Mexico; North, South, and Central America; the Caribbean; Europe; and Asia. Its main hub is in Mexico City, with secondary hubs in Guadalajara and Monterrey. Aeroméxico is known for its high-quality services, including in-flight entertainment and meals. |
|||||
| Ransomware | UPS id22752 View details | United States | Transportation / Travel / Logistics | ||
|
[AI generated] United Parcel Service (UPS) is an American multinational company that specializes in logistics, courier delivery services, and supply chain management solutions. Founded in 1907, it's headquartered in Atlanta, Georgia. With a global network, UPS delivers over 20 million packages daily to 220+ countries and territories worldwide. It also offers services like freight forwarding and supply chain designing. |
|||||
| Ransomware | Republic Services id22751 View details | United States | Public Sector | ||
|
[AI generated] Republic Services, Inc. is a leading firm in recycling and non-hazardous solid waste services in the United States. Founded in 1998 and based in Phoenix, Arizona, the company provides waste collection, transfer, evacuation, recycling, and landfill services. It serves commercial, industrial, municipal, and residential customers, catering to multiple sectors including housing, education, and healthcare. |
|||||
| Ransomware | Disney/Hulu id22750 View details | United States | Communication / Marketing | ||
|
[AI generated] Disney/Hulu refers to two separate entities, the Walt Disney Company and Hulu LLC. Walt Disney is a diversified multinational mass media and entertainment conglomerate, known for its film and TV production. Hulu, partially owned by Disney, is an American subscription video-on-demand service offering a variety of TV shows and movies. |
|||||
| Ransomware | FedEx id22749 View details | United States | Transportation / Travel / Logistics | ||
|
[AI generated] FedEx Corporation is a multinational delivery services company headquartered in Memphis, Tennessee. Founded in 1971, it offers courier express, freight forwarding, logistics services globally. Along with these, FedEx provides e-commerce, packaging, shipping and business services. It pioneered a system for real-time tracking of packages which has now become an industry standard. With a fleet of cargo aircraft, FedEx is one of the world's largest airlines. |
|||||
| Ransomware | Toyota Motor Corporations id22748 View details | Japan | Communication / Marketing | ||
|
[AI generated] Toyota Motor Corporation is a multinational automotive manufacturer headquartered in Japan. Founded by Kiichiro Toyoda in 1937, it became the world's largest automaker in 2008. Toyota is known for vehicles that prioritize durability and fuel efficiency. The company further pioneered hybrid electric vehicles with the introduction of Toyota Prius. Additionally, Toyota conducts business in the fields of housing, financial services, communications, marine and biotechnology. |
|||||