ShinyHunters
Aliases: UNC6040, UNC6240, Scattered Lapsus$ Hunters
Source profile review date: 2026-06-21
Added to the source registry: 2025-10-03 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
Locally generated translation; linguistic review is still pending.
Executive summary
ShinyHunters is not a classic encryption group but a data diode and extortion brand that leans heavily on SaaS, social engineering, tokens and cloud data.
ShinyHunters is relevant because the group shows that extortion does not always require ransomware payloads. The damage comes from stolen CRM, ticketing, Snowflake, Salesforce or other SaaS data and press to prevent publication.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Management summary
ShinyHunters is an important profile for Amuneth because it shows the shift from classic ransomware to pure data-extortion. The actor does not need to encrypt files to cause damage. If CRM-data, customer records, support tickets, analytics, tokens or cloud exports are stolen, the same administrative pressure arises: what is gone, who has been hit, which legal notification is needed and how do we prevent repetition?
The risk lies mainly in SaaS and identity. Organisations that do not sufficiently monitor Salesforce, Snowflake, support platforms, marketing tools, integrations and OAuth links can be vulnerable without endpoint detection. The actor uses social engineering, stolen credentials, tokens, misconfigurations and integration accounts to retrieve data where normal security checks are less sharp.
For visitors, the most important lesson is that cloud data needs to be protected as much as file servers. MFA, device trust, OAuth governance, logging export functions, secret management and vendor control are primary ransomware weasurability when the actor ShinyHunters-like works.
Grouping and development
ShinyHunters has been visible as data diode and extortion name for years. In public coverage, the group is linked to sales or publication of large datasets and later on to cloud and SaaS campaigns. In 2024 and 2025, Snowflake and Salesforce-related data diode campaigns attracted a lot of attention.
Google Threat Intelligence linked Salesforce fishing campaigns to UNC6040 and later extortion communications to UNC6240. In such campaigns, employees are misled to give access, for example through custom tools, OAuth consent or support-like scenario scenarios. The technical core is not always an exploit, but abuse of trust.
The brand name ShinyHunters can also function as a criminal label. Various clusters, forum identities and collaborations can use the name. Therefore, attribution should remain cautious and the file should focus on working methods: SaaS access, tokens, data diary, social engineering and extortion.
Operation and attack chain
A ShinyHunters-like attack often starts with access to a SaaS environment or integration chain, which can be done via vishing, smishing, credential theft, infostealer data, stolen OAuth or API-tokens, misconfigurations or access from a supplier. The actor subsequently searches for environments where many customer or business data is central.
Salesforce cases are important to exploit export capabilities. Data Loader-like behaviour, unusual OAuth consents, new connected apps, massiveSOQL /API- queries and exports of Account, Contact, Case, Opportunity or User objects are signals that organizations need to monitor.
Snowflake-like incidents are about credentials, MFA- absence, network policy, old tokens and integration accounts. The actor does not have to hack the platform if he can log in with valid data and export large datasets. Infostealerlogs and third parties increase that risk.
After data diving, extortion follows. Victims receive reports with claims, samples or threat to publication. The technical response should not only do endpointforensics, but especially secure cloudlogs: login history, API calls, OAuth grants, query history, export logs, storage access and vendor access.
Known IOCs and artifacts
Important artifacts include unusual Salesforce Data Loader activity, new or suspicious connected apps, OAuth permissions, massive CRM-object exports, Snowflake query history, logins without MFA, access from unusual ASN p.m.ph., use of stolen tokens and communication from extortion addresses.
Public reporting mentions ShinyHunters related to Snowflake and Salesforce data theft. Specific IP debt instruments or user agents can change per campaign. Therefore, the value is in detection on export behaviour: many records, many object types, API-volume outside normal pattern and access by a user or integration that does not normally do so.
Secrets in CRM or support data are also an important artifact. If exports contain support tickets, environment variables, access keys or customer configurations, further abuse can occur. Scanning on AWS keys, Snowflake tokens, API keys and passwords in looted datasets is therefore part of the response.
Victim pattern and lessons
ShinyHunters campaigns are publicly associated with major brands and data-rich platforms. The theme "Snowflake" is Snowflake customers, Salesforce customers, ticketing dates, telecom data, retail data, aviation customers and SaaS suppliers. The selection is about scale: a single SaaS environment can hold millions of records.
The lesson is that SaaS security cannot be outsourced to the supplier. Often, the platform itself is not technically broken, but customer configurations, credentials, integrations or users are abused. That makes shared responsibility very concrete.
A second lesson is that data export is a critical action. Many organizations have severe malware detection, but hardly on massive CRM- exports. ShinyHunters shows that this blind spot can lead to extortion instantly.
How to arm yourself
Force phishing-resistant MFA for SaaS and administrators. Use conditional access, device trust and network restrictions for critical cloud data. Remove old integrations and limit OAuth consents to explicitly approved apps.
Monitor SaaS export behaviour. Alerts on new connected apps, Data Loader activity, large exports, query peaks, unusual API-clients and access to sensitive objects. Link those signals to identity: who logged in, from where, on which device and with what token?
Check suppliers and integrations for token hygiene. Rotate tokens, limits scopes, log API- usage and scan code, tickets and CRM- fields on secrets. If a third party is hit, you should be able to quickly determine which own data or tokens were accessible via that route.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| behavior | voice phishing against SaaS users | Google Threat Intelligence UNC6040 reporting | Used to obtain Salesforce access or tooling. |
| tooling | Salesforce Data Loader or modified Data Loader-style exports | Google Threat Intelligence reporting | Monitor API/export behavior, not just file names. |
| behavior | Snowflake or SaaS data theft using stolen credentials/tokens | Mandiant / public Snowflake reporting | Focus on MFA, query history and network policies. |
| artifact | extortion emails under ShinyHunters branding | public victim reporting | Extortion communication; validate technical claims. |
Sources
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.