Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShinyHunters publicly operates extortion-as-a-service with partner crews

Threat Actor Meta
First reported
Last updated
Happening score
H score 24
1 unique sources, 2 articles

Summary

Hide ▲

ShinyHunters publicly framed itself as an extortion-as-a-service (EaaS) operator, a shift that can scale multi-victim extortion and blur attribution across partner breaches. The model turns ShinyHunters into a revenue-sharing broker for stolen data and ransom pressure rather than just a single intrusion crew. Its cooperation with Crimson Collective and Scattered Lapsus$ Hunters suggests a broader extortion ecosystem around one public leak brand.

Related Happenings

Charter Communications hit by network compromise linked to ShinyHunters

Incident
H score25 First: 26.05.2026 22:46 Last: 26.05.2026 22:46 Sources 1

About this happening: **Charter Communications** confirmed a **data breach** tied to **ShinyHunters** extortion, with the company saying it is **alerting authorities** and that **no sensitive personal...

Latest development: 29.05.2026 11:29

Have I Been Pwned analyzed leaked Charter Communications data and confirmed that the incident affected 4.9 million accounts, with exposed records including names, email addresses, job titles, phone numbers, and physical addresses. The published data also included a subset of about 85,000 records from an internal employee directory.

MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy

Campaign
H score43 First: 06.05.2026 16:02 Last: 06.05.2026 16:02 Sources 1

About this happening: The **MuddyWater** campaign used **Microsoft Teams** social engineering and a **Chaos ransomware** decoy to gain access, steal credentials, and establish persistence. The operatio...

Scattered LAPSUS$ Hunters IT help-desk vishing campaign

Campaign
H score33 First: 25.02.2026 17:06 Last: 25.02.2026 17:06 Sources 1

About this happening: **Scattered LAPSUS$ Hunters (SLH)** is running a **help-desk vishing campaign** that recruits women to impersonate employees, raising the success rate of **account-takeover attemp...

Vect RaaS affiliate recruitment and early ecosystem buildout

Threat Actor Meta
H score16 First: 03.02.2026 16:00 Last: 03.02.2026 16:00 Sources 1

About this happening: **Vect** has moved into **affiliate recruitment**, marking an early-stage **ransomware-as-a-service** buildout that could expand its reach and victim volume. The group has already...

Scattered Lapsus Shiny Hunters' harassment-driven extortion operating model

Threat Actor Meta
H score24 First: 02.02.2026 18:15 Last: 02.02.2026 18:15 Sources 1

About this happening: **Scattered Lapsus Shiny Hunters (SLSH)** is now using a **harassment-driven extortion model** that pairs stolen data with swatting, threats, and publicity pressure, raising the s...

Timeline

  1. 07.10.2025 00:08 2 articles · 8mo ago

    Crimson Collective and Scattered Lapsus$ Hunters align with ShinyHunters

    Campaign Scope Update

    Crimson Collective announced collaboration with Scattered Lapsus$ Hunters and said it would use the newly launched ShinyHunters data leak site for future attacks and releases against Red Hat, indicating a partner-crew extortion workflow around the Red Hat matter.

    Show sources
  2. 07.10.2025 00:08 2 articles · 8mo ago

    ShinyHunters says it is operating as extortion-as-a-service

    Initial Disclosure

    ShinyHunters said it has been privately operating as an extortion-as-a-service broker, taking a revenue share from extortion payments generated by other threat actors' attacks and positioning itself as an intermediary for stolen-data monetization.

    Show sources
  3. 07.10.2025 00:08 1 articles · 8mo ago

    ShinyHunters posts Red Hat leak entry and CER samples

    Victim Impact Update

    A Red Hat entry appeared on ShinyHunters' new data leak extortion site with a warning that data would be publicly leaked on October 10th unless a ransom demand was negotiated, and the site released stolen customer engagement report (CER) samples tied to organizations including Walmart, HSBC, Bank of Canada, Atos Group, American Express, Department of Defence, and Société Française du Radiotéléphone.

    Show sources
  4. 07.10.2025 00:08 1 articles · 8mo ago

    ShinyHunters extends public extortion to SP Global

    Campaign Scope Update

    ShinyHunters is also extorting SP Global on behalf of another threat actor linked to a claimed February 2025 breach, and the data leak site sets an October 10th deadline for public release unless a ransom is negotiated.

    Show sources