Shinyhunters
ActiveShinyHunters · UNC6240 · Bling Libra also known as
Total victims
72
This month
0
Active
—
DayBreach AI intelligence
How it operates
ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.
MITRE ATT&CK profile
G1057
[ShinyHunters](https://attack.mitre.org/groups/G1057) is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. [ShinyHunters](https://attack.mitre.org/groups/G1057) has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. [ShinyHunters](https://attack.mitre.org/groups/G1057) has been associated with the broader collective called The Community, also known as The Com whose members have also included [Scattered Spider](https://attack.mitre.org/groups/G1015) and [LAPSUS$](https://attack.mitre.org/groups/G1004). Public reporting has mentioned a variety of names for operations [ShinyHunters](https://attack.mitre.org/groups/G1057) members have reportedly conducted with members of other groups, including “Scattered Lapsus Hunters,” “Scattered Lapsus Shiny Hunters,” and “SLSH.”(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)(Citation: SOCRadar_ShinyHunters_Mar2024)(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)(Citation: Intel471_SH_Aug2021)(Citation: FBI_SHLMS_May2026)(Citation: Google_SHOracle_Jun2026)(Citation: Mandiant_SHDataTheft_Jan2026)(Citation: Google Salesforce JUN 2025)
Techniques it uses
Archive via Library
T1550.001Application Access Token
T1573.002Asymmetric Cryptography
T1585.002Email Accounts
T1082System Information Discovery
T1105Ingress Tool Transfer
T1190Exploit Public-Facing Application
T1530Data from Cloud Storage
T1059.007JavaScript
T1078Valid Accounts
T1567Exfiltration Over Web Service
T1598.003Spearphishing Link
T1203Exploitation for Client Execution
T1528Steal Application Access Token
T1083File and Directory Discovery
T1588.002Tool
Associated malware and tools