APT Cloud-Native Data Extortion Group Active since 2020

ShinyHunters

560M+ records stolen. 160+ Snowflake victims. Formal alliance with Scattered Spider and LAPSUS$.

Scroll

ShinyHunters is a prolific data extortion group specializing in cloud-native attacks against SaaS platforms and cloud infrastructure. The group gained access to 160+ Snowflake customer environments in 2024, exfiltrating over 560 million records from Ticketmaster alone. They maintain formal alliances with Scattered Spider and LAPSUS$.

AttributeDetail
NamesShinyHunters / UNC5537 / ShinyCorp
AttributionCloud-Native Data Extortion Group
Active Since2020
Primary Focus560M+ records stolen. 160+ Snowflake victims. Formal alliance with Scattered Spider and LAPSUS$.

Overview

ShinyHunters is a prolific data extortion group specializing in cloud-native attacks against SaaS platforms and cloud infrastructure. The group gained access to 160+ Snowflake customer environments in 2024, exfiltrating over 560 million records from Ticketmaster alone. They maintain formal alliances with Scattered Spider and LAPSUS$.

Attribution

ShinyHunters / UNC5537 / ShinyCorp is attributed to Cloud-Native Data Extortion Group, active since at least 2020. 560M+ records stolen. 160+ Snowflake victims. Formal alliance with Scattered Spider and LAPSUS$.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1078Valid AccountsHigh
T1530Data from Cloud Storage ObjectHigh
T1567Exfiltration Over Web ServiceHigh
T1657Financial TheftHigh
T1213Data from Information RepositoriesHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for ShinyHunters activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting ShinyHunters TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875