Gangs
S

Shinyhunters

Active

ShinyHunters · UNC6240 · Bling Libra also known as

Total victims

72

This month

0

Active

—

DayBreach AI intelligence

Gang profile and current news · from web sources

Loading…

How it operates

ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.

T1560.002 · Archive via LibraryT1550.001 · Application Access TokenT1573.002 · Asymmetric CryptographyT1585.002 · Email AccountsT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1190 · Exploit Public-Facing ApplicationT1530 · Data from Cloud StorageT1059.007 · JavaScriptT1078 · Valid AccountsT1567 · Exfiltration Over Web ServiceT1598.003 · Spearphishing LinkT1203 · Exploitation for Client ExecutionT1528 · Steal Application Access TokenT1083 · File and Directory DiscoveryT1588.002 · ToolT1213.003 · Code RepositoriesT1684 · Social EngineeringT1552.001 · Credentials In FilesT1078.004 · Cloud AccountsT1078.002 · Domain AccountsT1016 · System Network Configuration DiscoveryT1491.001 · Internal DefacementT1036.005 · Match Legitimate Resource Name or LocationT1219 · Remote Access ToolsT1598 · Phishing for InformationT1195.001 · Compromise Software Dependencies and Development ToolsT1657 · Financial TheftT1580 · Cloud Infrastructure DiscoveryT1018 · Remote System DiscoveryT1059.009 · Cloud APIT1583.004 · ServerT1072 · Software Deployment ToolsT1588.007 · Artificial IntelligenceT1110 · Brute ForceT1213.006 · DatabasesT1589.001 · CredentialsT1593.003 · Code RepositoriesT1583.001 · DomainsT1090.003 · Multi-hop Proxy

MITRE ATT&CK profile

G1057

[ShinyHunters](https://attack.mitre.org/groups/G1057) is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. [ShinyHunters](https://attack.mitre.org/groups/G1057) has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. [ShinyHunters](https://attack.mitre.org/groups/G1057) has been associated with the broader collective called The Community, also known as The Com whose members have also included [Scattered Spider](https://attack.mitre.org/groups/G1015) and [LAPSUS$](https://attack.mitre.org/groups/G1004). Public reporting has mentioned a variety of names for operations [ShinyHunters](https://attack.mitre.org/groups/G1057) members have reportedly conducted with members of other groups, including “Scattered Lapsus Hunters,” “Scattered Lapsus Shiny Hunters,” and “SLSH.”(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)(Citation: SOCRadar_ShinyHunters_Mar2024)(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)(Citation: Intel471_SH_Aug2021)(Citation: FBI_SHLMS_May2026)(Citation: Google_SHOracle_Jun2026)(Citation: Mandiant_SHDataTheft_Jan2026)(Citation: Google Salesforce JUN 2025)

MITRE

Associated malware and tools

Tor

Targeted sectors

Professional Services%19
Teknoloji%18
Eğitim%18
Retail & E-Commerce%11
Other%35