THREAT ACTOR
SHINYHUNTERS_
ActiveSHINYHUNTERS is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of SHINYHUNTERS, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 136
Leak site mirrors
10 mirrors tracked, 4 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
toolatedhs5dtr2pv6h5kdraneak5gs3sxrecqhoufc5e45edior7mqd.onionSH snapshot · 2026-04-01 01:14 -
shinypogk4jjniry5qi7247tznop6mxdrdte2k6pdu5cyo43vdzmrwid.onionshnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onion snapshot · 2026-10-06 15:20 -
91.215.85.22.// SH snapshot · 2026-09-29 12:13 -
shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onionsnapshot · 2026-09-30 06:11 -
shinyhunte.rs[sh] shinyhunters snapshot · 2026-05-11 08:04 -
91.202.233.104.snapshot · 2026-10-08 02:29 -
176.120.22.24.snapshot · 2026-10-08 02:27 -
91.215.85.103.// SH snapshot · 2026-10-08 02:16 -
91.215.85.22.// SH snapshot · 2026-09-29 12:24 -
espeonsh2drryv4bsonur5ud7d6gooho2mvktqdmakdpoxkwwersinid.onionsnapshot · 2026-10-08 01:26
Recent victims
The 50 most recent victims claimed by SHINYHUNTERS. Total in the index: 136.
| Date listed | Victim | Description |
|---|---|---|
| 2026-10-02 | DexCom, Inc. | Data is being published by end of day Friday if you do not reach out t… |
| 2026-10-02 | O'Reilly Automotive | Data is being published by end of day Friday if you do not reach out t… |
| 2026-09-30 | WARNING | Due to certain disinformation spreading once again, we are releasing t… |
| 2026-09-24 | Final statement re PSA | Good afternoon, We have no further comments to make regar… |
| 2026-09-23 | PRESS RELEASE RE PSA | We are currently not distributing samples to any media agencies. Furth… |
| 2026-09-23 | Fresenius Medical Care | You have exactly two days to contact us to prevent publication of all … |
| 2026-09-22 | PSA - READ THIS NOW | Dear Assistant Director Brett Leatherman of the FBI Cyber Division & D… |
| 2026-09-20 | Note to Cl0p-_- | IF YOU WANT TO SAVE YOUR BRAND AND NOT DIE BY MY HANDS: Email us from … |
| 2026-09-17 | Qi**** | Processing publication of this company unless they start negotiating a… |
| 2026-09-13 | Kimberly-Clark | This is a final warning to reach out by 16 Sep 2026 before we leak alo… |
| 2026-09-07 | State of Florida DMV | Contact us, you know how. or we will release the files. View download … |
| 2026-09-07 | Medela.com | This is a final warning to reach out by 08 Sep 2026 before we leak alo… |
| 2026-09-04 | Note to mr. databroker1 NEXUS DL Service | We've been trying to get ahold of you. We've made you several large of… |
| 2026-09-03 | NeoGen Corporation | Over 5 million Salesforce records compromised containing some PII and … |
| 2026-08-30 | Neogen Corporation | This is a final warning to reach out by 1 Sep 2026 before we leak alon… |
| 2026-08-29 | McKesson Corporation | Hundreds of millions of records/rows of data was compromised containin… |
| 2026-08-29 | Elekta AB | This is a final warning to reach out by 1 Sep 2026 before we leak alon… |
| 2026-08-29 | Jack Henry & Associates | This is a final warning to reach out by 1 Sep 2026 before we leak alon… |
| 2026-08-23 | CyrusOne, LLC. | Update 23 Aug: We are removing the clients name off this post. They ar… |
| 2026-08-23 | ReliaQuest, LLC | This time the post is about you, not us. Let Mandiant report and advis… |
| 2026-08-22 | NovoCure Limited | This is a final warning to reach out by end of day 24 Aug 2026 before … |
| 2026-08-22 | BOK Financial | This is a final warning to reach out by end of day 24 Aug 2026 before … |
| 2026-08-20 | Cyrus****** | This is a final warning to reach out by end of day 24 Aug 2026 before … |
| 2026-08-18 | Logitech/ Streamlabs | This is a final warning to reach out by 21 Aug 2026 before we leak alo… |
| 2026-08-18 | Brinks Home | Over 4.9 million Salesforce records containing some PII was compromise… |
| 2026-08-18 | Alcon, Inc. | Over 25 million Salesforce records containing some PII was compromised… |
| 2026-08-18 | Lumenis Ltd. | Over 1.1 million records containing some PII of customers/employees an… |
| 2026-08-18 | Questel SAS | Over 21 million Salesforce records containing some PII and 147GB+ of i… |
| 2026-08-18 | Metabase | 😛 |
| 2026-08-18 | Sharecare, Inc. | This Company data was published due to them hiring a very incompetent … |
| 2026-08-18 | NOTICE OF WARNING | We are currently experiencing an influx of volume. More leaks are on t… |
| 2026-08-18 | Carhartt, Inc. | Our demand for this Company was $3.3 million. The Company reached out.… |
| 2026-08-18 | Cook Medical LLC | Customer data, employee data, and other internal corporate data was co… |
| 2026-08-18 | Baxter International, Inc. | Over 7.1M Salesforce records containing some PII was compromised. Th… |
| 2026-07-27 | BH Security, LLC. (brinkshome.com) | Over 4.9 million Salesforce records containing some PII was compromise… |
| 2026-07-27 | RingCentral, Inc. | Over XX of data was compromised. This is a final warning to reach out… |
| 2026-07-27 | Ernst & Young | Yes it was us. Now come talk to us. We have been trying to reach you. … |
| 2026-07-25 | [cdn] Notification | All CDN mirrors are currently experiencing a service disruption. All f… |
| 2026-07-15 | Abbott owned Exact Sciences Corporation | You wouldn't want us to describe what was exfiltrated from you publicl… |
| 2026-07-06 | Fluke Corporation | Over 21 million Salesforce records containing some PII were compromise… |
| 2026-07-06 | Ingram Content Group, Inc. | The Company failed to reach an agreement with us despite our incredibl… |
| 2026-06-25 | naic.org | The previous statement was overstated due to an analytical error and a… |
| 2026-06-19 | icsecurity.com | Over 2.7 million records and other internal corporate data was comprom… |
| 2026-06-18 | Amazon owned OneMedical.com | Over 8.8TB of data was compromised. This is a final warning to reach … |
| 2026-06-18 | NAIC.org | Over 3.1 terabytes of National Association of Insurance Commissioners … |
| 2026-06-17 | Service Notice: Scheduled Maintenance and Infrastructure Upgrades | * The primary server hosting all leaked data is currently undergoing s… |
| 2026-06-16 | Ralph Lauren | Over 220GB of data containing customer PII, purchase/trasnaction info,… |
| 2026-06-15 | icc.edu | Over 28 gigabytes of Illinois Central College data (122,000+ files) wa… |
| 2026-06-15 | moody.edu | Over 23 gigabytes of Moody Bible Institute data (1,300+ files, tens of… |
| 2026-06-15 | glendale.edu | Over 62 gigabytes of Glendale Community College data (304,000+ files) … |
CONFIRMED ATTACKS
ShinyHunters confirmed attacks: 2 verified incidents
Ransomnews has verified 2 ShinyHunters incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from November 2025 to April 2026. United Kingdom accounts for 1 of them (50%), with victims recorded in 2 countries in total. The most affected sector is technology, at 2 confirmed victims. A ransom payment was publicly confirmed in 1 case and publicly refused in 1; the outcome is unrecorded in the remaining 0.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified ShinyHunters incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| April 2026 | Canvas (Instructure) | Technology | Utah, United States | — | Yes | Source |
| November 2025 | Checkout.com | Technology | London, United Kingdom | — | No | Source |
Claimed vs confirmed. The figures above the fold on this page come from ShinyHunters's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.