SHINYHUNTERS
SCATTERED SPIDER
LAPSUS$
UNC5537
Threat IntelligenceData ExtortionCloudMarch 13, 202622 min read

ShinyHunters: Anatomy of a
Cloud-Native Extortion Empire

From Pokemon-named forum admins to a global criminal alliance — a deep-dive into the TTPs, infrastructure, and threat anthropology of one of the most prolific data extortion groups operating today.

Scroll

Bottom Line Up Front: ShinyHunters is a financially motivated, cloud-specialist extortion collective that has evolved from bulk database reselling (2020–2023) into a highly coordinated vishing-and-OAuth-abuse operation. In 2024–2026 the group breached 160+ Snowflake customer environments, compromised 560M+ Ticketmaster records, and pivoted to Salesforce environment hijacking — all without exploiting a single platform vulnerability. Their modus operandi is social engineering at scale. As of 2025 they have formally allied with Scattered Spider and LAPSUS$, creating an industrialized cybercrime supply chain. Expect continued targeting of cloud-first enterprises, luxury goods, aviation, financial services, and any organization with an exposed Salesforce or Okta surface.

560M+ Records Stolen

Ticketmaster alone (2024). Total across all breaches exceeds 1 billion records.

160+ Snowflake Victims

Customers breached in a single mid-2024 credential-stuffing campaign.

$8M Ransom Demands

Peak demand for Ticketmaster data after raising from initial $500K ask.

400+ Salesforce Orgs

Experience Cloud instances claimed breached via AuraInspector automation in 2025.

2019 Year Founded

Believed operational since at least mid-2019; public debut on RaidForums 2020.

16+ Alliance Channels

Telegram channels created since the Scattered Spider / LAPSUS$ merger in Aug 2025.

Who Are ShinyHunters?

The name "ShinyHunters" derives from a niche corner of the Pokemon universe: players who obsessively hunt rare, alternate-coloured "shiny" Pokemon through grinding in-game encounters. It is an apt metaphor — the group relentlessly grinds for rare, high-value data assets and sells them to the highest bidder.

SH
ShinyHunters
UNC5537 / UNC6040 / UNC6240 / Bling Libra / ShinyCorp

A financially motivated, cloud-specialist extortion collective evolved from bulk database reselling into industrialized vishing-and-OAuth-abuse operations. Part of "the Com" — an informal English-speaking ecosystem of predominantly young Western hackers.

Motivation
Financial — data resale, extortion, ransom
Origin
Western (North America & UK); members in France, Turkey, Eastern Europe
Active Since
~2019 (publicly surfaced 2020 on RaidForums)
Alliance
Scattered Spider (UNC3944) + LAPSUS$ as of late 2024
Criminal Ecosystem
RaidForums, BreachForums (admin), Telegram, dark web markets
Threat Score
Critical (9.4/10)
Cloud ExtortionSnowflakeSalesforceVishingOAuth AbuseData BrokerBreachForums

ShinyHunters is not a monolithic APT in the traditional state-actor sense. Rather, it operates as a loose cybercrime collective — with a core leadership persona ("ShinyCorp") directing operations and recruiting specialist contractors. The group is believed to be part of "the Com," an informal English-speaking ecosystem of predominantly young Western hackers whose skills were sharpened on cryptocurrency scams and SIM-swapping before graduating to enterprise-scale intrusions.

Law enforcement has made inroads: in January 2024, French member Sebastien Raoult was sentenced to three years in prison and ordered to pay back $5 million. In June 2025, French authorities arrested four additional members operating under the aliases ShinyHunters, Hollow, Noct, and Depressed. Despite these arrests, the group has proven operationally resilient, re-emerging with new campaigns within weeks.

Evolution & Group Anthropology

Understanding ShinyHunters requires understanding their cultural context. They emerged not from a secretive, nation-state-sponsored lab, but from online gaming communities, Discord servers, and Telegram channels where young people traded hacked account credentials like trading cards. This origin shapes everything: their branding, their bravado, their communication style, and crucially, their social engineering psychology — they understand how people behave online.

Phase 1: Data Broker Era (2020–2023)

ShinyHunters launched its public identity on RaidForums in 2020 with a torrent of high-volume breaches — Tokopedia (91M records), Microsoft GitHub, Wattpad, Promo.com, and dozens more. The model was simple: breach, exfiltrate, sell or dump. Monetisation came primarily through selling databases on criminal forums. The "pay or we leak" model became their trademark.

Phase 2: Infrastructure Elevation (2023–2024)

The group became a power broker on BreachForums — first partnering with "Baphomet" to relaunch v2 of the forum in June 2023, then operating v4 independently in 2025. This forum administration gave them structural influence over the broader criminal data ecosystem: they could prioritise, amplify, or suppress listings, generating leverage well beyond their own breaches.

Phase 3: Cloud Extortion Pivot (2024–Present)

The 2024 Snowflake campaign marked a strategic inflection point. Rather than targeting individual companies directly, ShinyHunters attacked a cloud platform's customer base at scale, breaching 160+ enterprises in a single coordinated credential-stuffing wave. Monetisation shifted from one-time data sales to direct extortion — demanding ransoms in exchange for deletion of stolen data. AT&T reportedly paid $370,000. Ransom demands across victims ranged from $300K to $8M.

Phase 4: Alliance & Social Engineering Industrialisation (2025–2026)

By mid-2025, ShinyHunters had formalised a criminal alliance with Scattered Spider and LAPSUS$, creating 16+ coordinated Telegram channels. The alias Sp1d3rHunters — literally merging both groups' names — appeared on BreachForums as early as May 2024. This merger industrialised vishing: ShinyCorp explicitly recruited members based on proven social engineering skills on phone calls, targeting candidates who had previously run cryptocurrency scams impersonating Coinbase or Apple support.

Key Anthropological Insight

ShinyHunters selects and trains social engineers specifically from the cryptocurrency scam ecosystem — individuals who are already comfortable deceiving people over the phone, comfortable with impersonation, and experienced in exploiting trust. This talent pipeline makes their vishing campaigns disproportionately effective against corporate helpdesks.

Notable Attacks & Campaigns

2020
Mass Database Exfiltration Wave

Tokopedia (91M records), Microsoft GitHub repositories, Wattpad (270M records), Dave.com, Promo.com, and dozens more. Data sold on RaidForums. Establishes the group's brand as a prolific bulk data broker.

2021
AT&T (70M Wireless Subscribers)

Claimed sale of data on 70M AT&T customers including SSNs and personal info. AT&T denied the breach at the time. The company quietly confirmed the breach in 2024. Aditya Birla Fashion (India) also hit and dumped publicly after ransom refusal.

2023
Pizza Hut Australia / BreachForums v2 Launch

1M+ customer records and 30M order records from Pizza Hut Australia. Simultaneously, ShinyCorp partners with Baphomet to co-administer BreachForums v2, cementing the group's forum power.

May–Jun 2024
The Snowflake Campaign — 160+ Victims

Credential-stuffing attack using infostealer-harvested credentials targets 160+ Snowflake customer environments. Victims include Ticketmaster (560M records, $500K to $8M demand), Santander Bank (30M+ customers across Spain, Chile, Uruguay), Neiman Marcus, Advance Auto Parts, AT&T (call metadata for ~110M customers; $370K paid), and Truist Bank.

Dec 2024
PowerSchool Breach — $2.85M Ransom Paid

Education-software vendor PowerSchool breached. Tens of millions of student and teacher records exfiltrated. PowerSchool paid the ransom. Extortion attempts against individual school districts continued into May 2025.

Mid 2025
Salesforce Vishing Campaign — UNC6040

Attackers impersonate IT support staff over phone calls, tricking employees into connecting malicious Salesforce Data Loader OAuth apps. Victims include Qantas (6M customers), Adidas, Cartier, Dior, Louis Vuitton, Tiffany & Co., LVMH, plus insurance, aviation, and retail targets globally. Google Threat Intelligence tracks as UNC6040.

Aug 2025
Salesloft/Drift OAuth Token Theft

Stolen OAuth tokens from the Salesloft Drift integration enable unauthorised access to 760 customer Salesforce instances. A near-identical campaign repeated in November 2025 via the Gainsight–Salesforce integration (tracked by Google TIG as UNC6395).

Late 2025
Salesforce Experience Cloud — 400+ Orgs

ShinyHunters claim to have breached 400+ organisations by exploiting overly permissive Salesforce Experience Cloud guest user configurations. AuraInspector open-source tooling used to automate vulnerability scanning. GraphQL API limit bypass discovered via the sortBy parameter.

TTP Analysis (MITRE ATT&CK)

ShinyHunters' operational playbook has matured significantly from 2020 to 2026. What follows is a comprehensive breakdown of observed techniques mapped to the MITRE ATT&CK Enterprise framework.

TID Tactic Technique Observed Behaviour Sev
T1566 Initial Access Phishing Spear-phishing to harvest cloud credentials; cloned Okta SSO portals sent via SMS/email lures
T1199 Initial Access Trusted Relationship Supply chain breach of EPAM Systems to obtain Ticketmaster's Snowflake credentials from Jira
T1110.004 Credential Access Credential Stuffing Infostealer-harvested credentials replayed against Snowflake environments; no MFA = no friction
T1552 Credential Access Unsecured Credentials Credentials stored unencrypted in Jira (EPAM), Git repos, CI/CD pipelines, BrowserStack API keys
T1078 Defense Evasion Valid Accounts All cloud access performed via legitimate stolen credentials — no malware on cloud infrastructure
T1556 Persistence Modify Auth Process OAuth app registration in victim Salesforce orgs creates persistent access surviving password resets
T1580 Discovery Cloud Infrastructure Discovery DBeaver Ultimate and custom SQL tools used to enumerate Snowflake tables; AuraInspector for Salesforce
T1560.001 Collection Archive via Utility Temporary Snowflake stages used to GZIP-compress data before exfiltration via GET command
T1567 Exfiltration Exfil Over Web Service Data exfiltrated via Snowflake's own GET command infrastructure; Salesforce Data Loader for SFDC orgs
T1657 Impact Financial Theft / Extortion "Pay or leak" model. Ransoms $300K–$8M. AT&T paid $370K. PowerSchool paid $2.85M.
T1530 Collection Data from Cloud Storage Direct queries against S3-backed Snowflake stages; Salesforce GraphQL API data extraction
T1588.002 Resource Dev Tool Acquisition S3 Browser, WinSCP, DBeaver Ultimate, AuraInspector (open source) — all commercially available
T1583 Resource Dev Acquire Infrastructure Phishing infra via Njalla (privacy-protected registrar); Mullvad VPN for data exfiltration obfuscation

Vishing Playbook — Deep Dive

The most operationally sophisticated component of the current ShinyHunters methodology is their voice-phishing (vishing) pipeline. The attack chain for the Salesforce campaigns follows a reproducible playbook:

STEP 1 — RECONNAISSANCE
  # Mandiant notes campaigns are built on extensive target profiling
   LinkedIn / company directories to identify helpdesk / IT staff
   Public Salesforce org URLs identified via standard endpoint patterns
   Okta subdomain enumeration and clone creation (e.g. trial-XXXXXXX.okta.com)

STEP 2 — VISHING CALL
  # ShinyCorp recruits from crypto-scam vishing talent pool
   Attacker impersonates IT support / Salesforce vendor representative
   Instructs target employee to visit Salesforce Connected App setup page
   Victim enters "connection code" — authorises actor-controlled OAuth app
   OAuth token grants persistent, MFA-bypassing access to the Salesforce org

STEP 3 — PERSISTENCE
  # Connected app survives password changes and MFA resets
   Malicious Data Loader app registered in victim org
   Refresh tokens maintained for extended access
   Extortion contact made weeks to months after initial breach

STEP 4 — EXFILTRATION & EXTORTION
   Bulk export via Salesforce APIs using Mullvad VPN for obfuscation
   Data staged, compressed, exfiltrated to attacker-controlled storage
   Ransom demand sent; failure to pay → data listed on leak site / BreachForums

Insider Recruitment

In a significant operational escalation, on August 31, 2025, a ShinyHunters-controlled Telegram channel published an open recruitment message seeking corporate insiders with access to:

This insider-recruitment model mirrors the tactics of LAPSUS$ and represents a maturation of the group's initial access capability that defenders cannot address purely through technical controls.

The Trinity: ShinyHunters x Scattered Spider x LAPSUS$

The merger of these three groups represents the most significant development in the Western cybercrime ecosystem since the rise of ransomware-as-a-service. Each group brings distinct capabilities:

SH
ShinyHunters
Data Broker Expertise

BreachForums administration, mass credential processing, cloud platform exploitation, extortion infrastructure, dark web distribution network.

SS
Scattered Spider
Social Engineering Mastery

SIM swapping, helpdesk impersonation, MFA bypass, Okta phishing — especially effective in hospitality, telecom, and financial services sectors.

L$
LAPSUS$
Extortion Brand

High-profile extortion playbook (Microsoft, Nvidia, Samsung, Uber), insider-bribery model, public embarrassment tactics, and a brazen public communications strategy.

The composite capability is formidable: ShinyHunters brings the data monetisation infrastructure and cloud breach expertise, Scattered Spider brings the social engineering talent pipeline, and LAPSUS$ brings the extortion methodology and brand intimidation. Together, they represent a full-spectrum cloud-native attack chain that requires no malware, no CVE exploitation, and no network perimeter breach.

Critical Intelligence

Domain registration analysis (2025) targeting financial companies increased by 12% following the alliance formation. Banks, insurance companies, and financial services organisations are assessed as priority near-term targets.

IOCs & Detection Signals

The following are representative observable indicators attributed to ShinyHunters infrastructure and operations.

Phishing Domains (Confirmed / High Confidence)
  • BLESS-INVITE[.]COM — Registered 5 Apr 2025; Njalla privacy; Okta phishing infra
  • Pattern: Okta SSO clones targeting trial-XXXXXXX.okta.com subdomains
  • Pattern: Salesforce Data Loader masquerading connected app names
IP Infrastructure
  • 196.251.83[.]162 — Identified hosting BLESS-INVITE[.]COM phishing domain
Tooling (Dual-Use — Context-Dependent)
  • DBeaver Ultimate — Used for Snowflake table enumeration and data staging
  • S3 Browser — Used in AWS S3 reconnaissance (Bling Libra IR)
  • WinSCP — Used in S3 data exfiltration operations
  • AuraInspector — Open-source; used to automate Salesforce Experience Cloud scanning
  • Mullvad VPN — Used for exfiltration traffic obfuscation
Registrar Pattern
  • ShinyHunters consistently uses Njalla as a privacy-protected registrar
  • Registrar: Tucows + Njalla privacy protection = elevated suspicion signal
Forum Personas (Historical Attribution)
  • ShinyHunters — BreachForums primary identity
  • ShinyCorp — Operational leader persona; Telegram admin
  • Sp1d3rHunters — Joint ShinyHunters/Scattered Spider alias; BreachForums May 2024
  • Hollow — Alternate admin account (self-disclosed)
  • Anastasia — Alternate admin account (self-disclosed)
  • Arrested aliases: Noct, Depressed (French authorities, Jun 2025)

Behavioural Detection Signals

Defensive Posture & Mitigations

Key Assessment

ShinyHunters exploits zero platform vulnerabilities. Every documented breach results from misconfiguration, absent MFA, credential compromise, or social engineering. The defences below are correspondingly identity-and-configuration-focused.

Identity & Access Management

Credential Hygiene

Vishing & Social Engineering Defence

Detection & Monitoring

Third-Party Risk

Threat Outlook & Assessment

ShinyHunters in 2026 is categorically more dangerous than the bulk-database-reselling operation of 2020. The group has achieved three things that most criminal organisations do not: strategic patience (the Ticketmaster breach went undetected long enough to exfiltrate 1.3 TB), platform specialisation (they are now genuinely expert in Salesforce, Snowflake, and Okta architecture), and alliance leverage (the com-coalition multiplies their reach and capability without proportional expansion of internal headcount).

Law enforcement pressure has proven insufficient to suppress the group. The June 2025 arrests of four French members produced no detectable operational pause. BreachForums continues to cycle through takedowns and rebirths — ShinyHunters themselves publicly warned that the latest iteration was a law enforcement honeypot, then proceeded to launch a new instance. This resilience is structural, not accidental: the group is designed to operate with a rotating cast of contractors rather than a fixed membership.

Near-term targeting assessment (High Confidence): Financial services and insurance organisations are the most likely near-term primary targets based on domain registration trend analysis (+12% financial targeting increase since July 2025). Organisations using Salesforce Financial Services Cloud, Salesforce Health Cloud, or Salesforce with Gainsight/Salesloft integrations should treat themselves as actively targeted.

Mjolnir Assessment — Critical

The normalisation of remote IT support and outsourced service desks has created an industrial-scale attack surface for ShinyHunters' vishing playbook. Until organisations implement mandatory callback verification and out-of-band OAuth authorisation approval workflows, the fundamental vulnerability that powers this threat actor's most effective technique remains fully exploitable.

How Mjolnir Security Can Help

ShinyHunters' cloud-native, social-engineering-driven methodology demands a security posture that extends beyond traditional perimeter defence. Mjolnir Security offers integrated services designed to counter this exact threat profile.

Cloud Security Assessment Identity & Access Audit Social Engineering Testing Dark Web Monitoring Incident Response Threat Hunting Salesforce Security Review
  • Cloud Security & Identity AuditingComprehensive review of Salesforce, Snowflake, Okta, and AWS configurations — identifying misconfigured OAuth apps, overly permissive guest users, and credential hygiene gaps before ShinyHunters does.
  • Social Engineering Red TeamRealistic vishing and phishing simulations modelled on ShinyHunters' documented playbook. Test your helpdesk, measure response, and build resilience against the exact tactics this group employs.
  • Threat Intelligence & Dark Web MonitoringContinuous monitoring of BreachForums, Telegram channels, and stealer log markets for compromised credentials and early indicators of targeting against your organisation.
  • Incident Response & Digital Forensics24/7 rapid-response capability for cloud-based breach investigation, OAuth token forensics, and Salesforce/Snowflake audit log analysis.

Contact Mjolnir Security: mjolnirsecurity.com  |  24/7 Incident Response Line

References

  1. "Threat actor profile: ShinyHunters," Mandiant / Google Threat Intelligence.
  2. "UNC5537 targets Snowflake customer instances for data theft and extortion," Mandiant, 2024.
  3. "Threat Brief: UNC6040 Salesforce vishing campaign," Google Threat Intelligence Group, 2025.
  4. "Ticketmaster breach: 560M records stolen in Snowflake credential-stuffing campaign," BleepingComputer, 2024.
  5. "AT&T paid $370,000 ransom to delete stolen customer data," Wired, 2024.
  6. "PowerSchool breach: $2.85M ransom paid, extortion continues," KrebsOnSecurity, 2025.
  7. "Bling Libra's evolved AWS cloud attack," Palo Alto Unit 42, 2024.
  8. "Sebastien Raoult sentenced to three years for ShinyHunters crimes," US DOJ, 2024.
  9. "French authorities arrest four ShinyHunters members," Europol, 2025.
  10. "Salesforce Experience Cloud guest user misconfiguration exploitation," AppOmni, 2025.
  11. "The convergence of chaos: Scattered Spider, ShinyHunters, LAPSUS$," Mjolnir Security / Skuggaheimar.
  12. "Salesloft/Drift OAuth token theft impacts 760 Salesforce instances," Salesforce Security Advisory, 2025.
Written by: Mjolnir Security Intelligence  |  Published: March 13, 2026