ShinyHunters is a financially motivated hacking and extortion group that has spent the past several years breaching companies, universities, and cloud platforms, stealing data, and threatening to leak it unless victims pay. The group’s highest-profile attack came in 2026, when it claimed to have exfiltrated roughly 3.65 terabytes of data tied to more than 8,800 schools and universities worldwide from Instructure, the company behind the Canvas learning management system, one of the largest education-sector breaches on record. Since then, ShinyHunters has expanded its target list to include Salesforce, Rockstar Games, Google, TransUnion, and dozens of other organizations, making it one of the most active and closely tracked threat actors in cybersecurity today. This guide covers who ShinyHunters is, how the Canvas breach unfolded, and every company the group has claimed to hack so far.
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
Who Is ShinyHunters?
ShinyHunters is a financially motivated cybercriminal group that breaches companies and then sells or leaks the stolen data unless a ransom is paid. Active since 2020, the group has claimed responsibility for hundreds of data breaches spanning e-commerce, healthcare, education, and technology, making it one of the most prolific extortion operations in modern cybercrime.

Origin and History of the Group
ShinyHunters first surfaced in May 2020, when it began selling a database of roughly 91 million Tokopedia user accounts on a dark web marketplace. Within two weeks of its debut, the group had over 200 million stolen records listed for sale. The name comes from “shiny hunting,” a term borrowed from the Pokémon games for the search for rare, alternate-colored creatures, a nod to the group’s fixation on rare, high-value data. Over the following year, ShinyHunters built one of the largest breach records of any group by exploiting misconfigured cloud storage and stolen credentials at companies including Microsoft, Wattpad, Bonobos, and Pixlr. They became closely tied to the hacking forums RaidForums and later BreachForums, which they took control of in 2023, before the FBI seized them in October 2025. By 2025, its tactics had shifted toward voice-phishing (vishing) attacks against corporate help desks, primarily targeting Salesforce-connected environments, alongside a new ransomware-as-a-service offering called ShinySp1d3r.
Is ShinyHunters a Real Hacking Group?
Yes, ShinyHunters is a real, active criminal group, not an urban legend or a hoax, and law enforcement has already secured at least one confirmed conviction tied to it. In January 2024, French national Sébastien Raoult, known online as “Sezyo Kaizen,” was sentenced to three years in a U.S. federal prison and ordered to pay $5 million in restitution for his role in the group’s breach of more than 60 companies between 2020 and 2021. His case remains the clearest legal confirmation that ShinyHunters is an organized group of individuals, not a single actor. However, most of its members remain unidentified, and the group has continued operating since his arrest.
ShinyHunters vs. Scattered Spider and Lapsus$ (Shared Alliance)
ShinyHunters is not the same group as Scattered Spider or Lapsus$, but by 2025 the three had formed a working alliance known as Scattered LAPSUS$ Hunters. Each brings a different specialty: Scattered Spider is known for help-desk impersonation and SIM-swapping to gain initial access, Lapsus$ for insider recruitment and source-code leaks, and ShinyHunters for large-scale data harvesting and extortion. Researchers publicly documented the alliance in September 2025, after the FBI linked Salesforce-related breach clusters tracked as UNC6040 and UNC6395 to ShinyHunters and Scattered Spider, respectively; evidence that treating them as fully separate groups is now more about branding than operational reality.
The Canvas / Instructure Breach Explained
In late April 2026, the extortion group ShinyHunters breached Instructure, the company behind the Canvas learning management system used by schools and universities worldwide. It threatened to leak stolen student and staff data unless it paid a ransom. Instructure confirmed the intrusion within days, making it one of the largest education-sector breaches on record by number of institutions affected.

Full List of Schools and Universities Affected
No single official list of every school hit by the Canvas breach exists. Still, ShinyHunters claimed to have accessed data tied to more than 8,800 educational institutions worldwide, spanning K-12 districts and major research universities alike. Named institutions confirmed in reporting include Harvard, MIT, Stanford, Princeton, Columbia, Duke, Georgetown, UC Berkeley, Oxford, and Cambridge. However, the true scope covers far more schools than any single article can enumerate. Because Canvas runs on shared infrastructure across its customer base, any institution using the platform during the breach window should assume its data may have been included and check directly with Instructure or its own IT department for confirmation, rather than relying on unofficial victim lists circulating online.
What Data Was Stolen from Canvas
The confirmed data taken from Canvas includes names, email addresses, student ID numbers, and private in-platform messages exchanged between students, teachers, and staff. Instructure has stated it has found no evidence that passwords, Social Security numbers, dates of birth, or financial information were affected. ShinyHunters separately claimed to have stolen 3.65 terabytes of data covering roughly 275 million individuals and to have accessed a connected Salesforce instance figures Instructure has not independently verified, and which security researchers treat with skepticism given the group’s history of inflating breach numbers to pressure victims into paying.
Timeline: How the Canvas Attack Unfolded
The breach played out over about two weeks, escalating each time Instructure didn’t move fast enough for the attackers’ liking:
- April 30, 2026: Instructure detects unauthorized access to its production systems.
- May 1: The company confirms a criminal breach and brings in forensic investigators.
- May 3: Instructure publicly confirms the incident and the types of data involved.
- May 6 ShinyHunters’ initial contact deadline passes without a response from Instructure.
- May 7 The group defaces Canvas login pages at roughly 330 institutions with a ransom note and a new May 12 deadline.
- May 8 Canvas goes down during finals week at many schools; Instructure restores access later that day.
- Mid-May Reporting indicates Instructure paid a ransom and received claims from ShinyHunters that the stolen data was destroyed, a claim that, as with the theft figures, has not been independently verified.
Every Company ShinyHunters Has Hacked
ShinyHunters has claimed breaches at dozens of companies since 2020. Still, its most damaging run came in 2025 and 2026, when it pivoted from one-off consumer data dumps to a sustained enterprise extortion campaign. Below is a breakdown of the most significant confirmed and claimed victims, grouped by how the group got in.

Salesforce and CRM-Linked Breaches
The single largest wave of ShinyHunters activity ran through Salesforce-connected corporate environments. Starting in mid-2025, the group used voice-phishing (vishing) calls to trick employees into authorizing a malicious Salesforce Data Loader tool, gaining access to CRM data at Google (2.5 million SMB contact records), Qantas (5.7 million customers), Adidas, Cisco, Allianz Life, Workday, and several LVMH brands including Louis Vuitton, Dior, and Tiffany & Co. The campaign escalated in August 2025 when the group exploited stolen OAuth tokens from a separate breach of Salesloft’s Drift integration. At that point, ShinyHunters claimed to have exfiltrated roughly 1.5 billion records across 760 Salesforce tenants, the largest single figure the group has claimed in its history. However, as with most ShinyHunters numbers, that total hasn’t been independently verified.
Rockstar Games, Grubhub, Medtronic, and Other 2025–2026 Victims
Into 2026, ShinyHunters expanded well beyond Salesforce, hitting companies through whatever third-party vendor offered the easiest way in. In April 2026, the group claimed to have breached Rockstar Games through a compromised third-party billing platform, gaining access to the studio’s Snowflake data warehouse and leaking about 8.1GB of internal files, including anti-cheat source code and customer support records; Rockstar said only “limited, non-material” data was affected. That same month, ShinyHunters listed medical device maker Medtronic on its leak site, claiming more than 9 million records of personal and health information; the listing quietly disappeared just before its ransom deadline, a pattern researchers associate with a likely payment, and Medtronic confirmed the breach in an SEC filing. Grubhub was hit twice: once in February 2025 through the original Salesforce campaign, and again in January 2026, when credentials stolen in the Salesloft Drift attack let the group access Grubhub’s Zendesk support data and issue a fresh bitcoin ransom demand.
Vercel, TransUnion, Udemy, Telus, and Recent Breaches
Several other 2025–2026 incidents round out the list, though attribution remains disputed in one case. In July 2025, ShinyHunters breached credit bureau TransUnion through a third-party Salesforce-connected application, exposing the Social Security numbers and dates of birth of 4.4 million U.S. consumers among the most sensitive datasets the group has claimed to date. In April 2026, the group issued a “pay or leak” ultimatum to online learning platform Udemy over roughly 1.4 million user and instructor records, later publishing the data after the deadline passed, and separately listed Telus Digital, claiming nearly one petabyte of stolen data. A breach of developer platform Vercel that same month, in which attackers tried to sell internal API keys and employee data for $2 million, is a rare case where ShinyHunters publicly denied involvement and said the real perpetrators were impersonating the brand a useful reminder that not every attack carrying the ShinyHunters name is confirmed to be the group’s own work.
How ShinyHunters Operates
ShinyHunters gets into networks almost entirely through people rather than code, then uses the threat of a public data leak, not ransomware, to force payment. The group’s entire operation runs on a repeatable playbook: trick someone into granting access, steal the data quietly, then apply public pressure until the victim pays or the data goes live.

Social Engineering and Vishing Tactics
ShinyHunters’ primary entry point is vishing: an attacker poses as internal IT support and walks an employee through installing what looks like a legitimate app, most often a modified version of Salesforce’s Data Loader tool. Once the employee grants access, that “app” is actually a connected integration that lets ShinyHunters pull data straight out of the company’s CRM, often in small, deliberately paced queries designed to avoid tripping security alerts before switching to bulk exports once the group understands the database structure. The group backs this up with more conventional methods too: registering lookalike login pages that mimic real Okta and Microsoft SSO portals, scanning victims’ public GitHub repositories for exposed credentials, and, in the case of the 2026 Canvas breach, exploiting a zero-day vulnerability in Oracle PeopleSoft rather than phishing anyone. The common thread is speed. Google’s own report on its June 2025 breach described the exfiltration happening in “a small window of time” before defenders could react.
Extortion and Ransom Demands
ShinyHunters doesn’t run traditional ransomware; it never encrypts systems or demands payment for a decryption key. Instead, it follows a “pay or leak” model: steal the data, set a short deadline, and publish everything if the victim doesn’t respond in time. Demands are sometimes priced per stolen record; one tracked case valued a haul at roughly $0.95 per record, or close to $19 million total, though the group has also issued flat multimillion-dollar lump sums for higher-profile targets like Instructure. Negotiations, when they happen, run through encrypted channels like the TOX messaging protocol rather than email, and paying offers no real guarantee: researchers who track the group note it has a documented history of not honoring its own agreements, and there’s no technical way to confirm stolen data was actually destroyed after payment.
Their Data Leak Site (DLS): How It Works
ShinyHunters runs its extortion operation through a dedicated data leak site hosted on the dark web, with occasional clearnet mirrors. Victim organizations are listed publicly with a visible countdown timer and small samples of the stolen data, a deliberate pressure tactic meant to embarrass companies into paying before time runs out. When a listing quietly disappears from the site, as happened with Medtronic in April 2026, it typically signals that negotiations are underway or a payment was made, not that the matter is resolved. ShinyHunters coordinates announcements through Telegram and leaves a signature ransom-note file on compromised systems as its calling card. This detail appears consistently across incidents and serves as one of the group’s clearest fingerprints.
Are the Members of ShinyHunters Known?
Law enforcement has identified and prosecuted several individuals tied to the ShinyHunters name, but the group as a whole remains only partially unmasked — a mix of convicted members, unidentified operators, and at least one case where someone falsely claimed the brand to make their own extortion attempt look more credible.

Arrests and Prosecutions (Sébastien Raoult and Others)
The clearest conviction remains French national Sébastien Raoult, sentenced in January 2024 to three years in a U.S. federal prison and ordered to pay $5 million in restitution for his role in ShinyHunters’ breach of more than 60 companies between 2020 and 2021. Since then, enforcement has picked up: in February 2025, U.S. authorities arrested Kai West, known online as “IntelBroker,” who administered the BreachForums marketplace ShinyHunters used to sell stolen data, in connection with a $25 million cybercrime conspiracy. That was followed in June 2025 by a coordinated French operation that arrested four more individuals tied to the personas “ShinyHunters,” “Hollow,” “Noct,” and “Depressed.” A related but distinct case involved Matthew D. Lane, a 19-year-old Massachusetts college student sentenced in October 2025 to four years in prison and $14 million in restitution for the 2024 PowerSchool breach — his ransom notes claimed to represent ShinyHunters, though whether he was an actual member or simply invoking the name for credibility has never been definitively established.
Current Legal Status of the Group
Despite this string of arrests, ShinyHunters as a brand remains active and has continued claiming new breaches — including RingCentral, McKesson, and Trezor’s fulfillment partner — well after every prosecution above concluded. That resilience comes down to how the group is structured: “ShinyHunters” functions less like a fixed organization with stable leadership than a shared identity that different individuals have picked up and run with over time, as shown by BreachForums ownership changing hands multiple times between 2023 and 2025 among different personas. No single alleged leader has been definitively identified or convicted, and most of the group’s day-to-day operators remain unnamed and presumably still at large, which is why researchers generally describe ShinyHunters’ legal status as “actively investigated, partially prosecuted” rather than dismantled.
What Happened to ShinyHunters? (Latest Updates)
As of September 2026, ShinyHunters remains active and has claimed several new victims in the months following the Canvas breach, even as law enforcement has made real dents in the group’s infrastructure. The two tracks of continued attacks and continued arrests have been running in parallel rather than one stopping the other.

Most Recent Claimed Breaches
ShinyHunters’ most recent claimed victim is McKesson, the largest U.S. pharmaceutical distributor, which disclosed a breach in late August 2026 after the group claimed to have exfiltrated roughly 1 terabyte of data covering 284 million patient records over four days and demanded $55,236,150 in ransom under a 72-hour deadline. The group also claimed a July 2026 breach of business-communications platform RingCentral, stealing 623GB of data and publicly leaking a 280GB portion after the company refused to pay, and a September 2026 breach of crypto hardware-wallet maker Trezor’s fulfillment partner ShipMonk, which ultimately affected roughly 80,700 customers, including records the company had previously certified as deleted years earlier. Together with the Canvas breach in May, these incidents show a group still operating at full pace and expanding further into healthcare, telecom, and financial-adjacent sectors alongside its original consumer-data playbook.
Law Enforcement Response
Law enforcement has made real progress against ShinyHunters without shutting the group down. In June 2025, French cybercrime police arrested four individuals connected to the personas “ShinyHunters,” “Hollow,” “Noct,” and “Depressed” for their roles running BreachForums, following the earlier February 2025 arrest of Kai West, known online as “IntelBroker.” A few months later, in October 2025, the FBI and France’s BL2C cybercrime unit seized BreachForums’ domains again, this time taking down the extortion portal the group was using to pressure its Salesforce campaign victims. ShinyHunters itself acknowledged the takedown in a PGP-signed Telegram message, admitting the group had been “outmaneuvered.” None of it has stopped the brand from operating. Because “ShinyHunters” functions more as a shared identity used by a loose, rotating set of collaborators than a single organization, arrests have removed individuals without ending the campaigns carried out under the name; both the May 2026 Canvas breach and the August 2026 McKesson breach came after these enforcement actions.
Frequently Asked Questions
Did ShinyHunters Get the Ransom?
In the Canvas breach, multiple reports indicate Instructure paid a ransom and received a claim from ShinyHunters that the stolen data had been destroyed. Still, that claim, like most of the group’s statements, hasn’t been independently verified, and there’s no technical way to confirm data was actually deleted after payment. Outcomes vary by victim: some companies pay and are removed from the group’s leak site (as Medtronic reportedly was). In contrast, others refuse and have their data published in full, as happened with RingCentral in August 2026. Security researchers who track the group generally advise against paying, since ShinyHunters has a documented history of not honoring its own agreements even after receiving funds.
Where Is ShinyHunters Based?
ShinyHunters doesn’t operate out of a single country; it’s a loosely organized, primarily English-speaking collective believed to be part of “The Com,” an international network of young cybercriminals spread across the U.S., U.K., and Europe. The clearest evidence of its makeup comes from arrests rather than self-disclosure: French national Sébastien Raoult was sentenced in the U.S. for his role in the group, and in June 2025 French police arrested four more individuals connected to ShinyHunters personas in multiple regions of France. That mix of nationalities, combined with the group’s practice of rotating members and personas, is why researchers describe ShinyHunters as a brand or identity shared across contributors rather than a single team working from one location.
How Do I Know If My Data Was Exposed?
The fastest way to check is to search your email address on a breach-notification service like Have I Been Pwned, which has already ingested data from several confirmed ShinyHunters incidents, including RingCentral and DentaQuest. Beyond that, watch for direct notification letters from any organization you have an account with. Instructure, TransUnion, Medtronic, and dozens of others have sent formal breach notices to affected individuals as required by state and federal disclosure laws, and these will specify exactly what data of yours was involved. Because ShinyHunters’ claimed breaches often affect third-party vendors rather than the company you actually interact with, it’s worth checking notices from any service provider your school, employer, or healthcare provider uses, not just the primary brand name, which is also where continuous dark-web monitoring earns its keep, since it can flag your data in a leak before an official notice ever arrives.
Article Link: ShinyHunters | Who They Are & Every Company They've Hacked