CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Threat actor

Shinyhunters

extortion121 leak-site claims, all timeLatest observed leak-site post 2026-09-07ORKL search ↗

Portable threat brief

Shinyhunters

Versioned profile fields only · no model narrative

Opens the browser print dialog; choose Save as PDF.

PDF export is unavailable. The threat brief remains available below; use your browser's Print command.

Executive facts

Actor
Shinyhunters
Kind
extortion
Actor record created
2026-07-06
Latest observed
2026-09-07
Leak-site claims
121
Catalogued techniques
0

Scope

Tracked sectors
Technology, Business & Professional Services, Education, Financial Services, Healthcare
Claim records
2026-01-23 to 2026-09-07
Suspected origin
[Unknown]
Motivation
Financial gain

Decisive signals with dates

No dated decisive signals are attached to this actor's linked vulnerabilities.

Verified techniques

No verified ATT&CK mapping in this corpus.

Defensive actions

No defensive actions are attached to this profile.

Ransomware claim data is unverified: RansomLook (CC BY 4.0) and ransomware.live (No data licence; credited voluntarily).

© Electronic Transactions Development Agency, 2019-2026. ETDA/ThaiCERT Threat Group Cards, CC BY-NC-SA 4.0; source card. The tracker uses a deterministic exact name-or-alias join and reformats the attributed fields. All information contained herein is provided on an “As Is” basis with no warranty whatsoever.

Most-claimed sectorsTechnologyBusiness & Professional ServicesEducationFinancial ServicesHealthcare
Activity window in this corpus

This is only the tracker's observed corpus window. It is not this actor's lifetime or evidence of dormancy outside these dates.

Claim records
First observed Latest observed
Verified ATT&CK phases represented

No verified ATT&CK mapping in this corpus

Origin and motivation
Suspected origin
[Unknown]
Motivation
Financial gain

Attributed by ETDA Threat Group Cards (Source last updated: ), by a deterministic exact name or alias match.

No MITRE ATT&CK group mapping exists for this actor yet. Mappings here are strict: an actor links to a MITRE group only when the group's own name, aliases, or MITRE-published description match, and MITRE has not catalogued this group. Technique and defensive action data will appear automatically if a verified mapping lands.

Claims attributed to this actor or leak site
121 in this corpus
View all on Breaches →
Leak-site claim activity

0 additional claims without a disclosure date

2026-012026-09

Ransomware claim data is unverified: RansomLook (CC BY 4.0) and ransomware.live (No data licence; credited voluntarily).

Glossary