Tech News
← Home  ·  All topics

Shinyhunters

21 GoKawiil briefs on this topic

ShinyHunters-linked hackers use fake passkey alerts to breach Microsoft 365 accounts

Microsoft has detailed a social engineering campaign, active since May 2026, in which attackers tied to groups like ShinyHunters and Helix pose as corporate IT help desks and warn employees their passkey, MFA, or SSO settings need urgent updating. Victims are steered to convincing fake Microsoft login pages—often via SMS to personal phones—where attackers harvest credentials and session tokens using adversary-in-the-middle and device-code phishing techniques, rather than actually registering new passkeys.

Hackers Target Personal Phones to Breach Microsoft 365 via BYOD Policies

Microsoft says threat groups Storm-3032 and Storm-3121 have been calling or texting employees on personal devices since May, posing as internal IT helpdesks to steal credentials and bypass corporate authentication protections. The attackers then abuse the Microsoft Graph API to exfiltrate corporate data at scale, and researchers believe they hand off this access to extortion gangs such as ShinyHunters. No specific breaches have yet been tied directly to these campaigns.

AdaptHealth confirms 4.1 million people's data exposed in ShinyHunters breach

AdaptHealth has confirmed that a cyberattack discovered in July, linked to the ShinyHunters group, exposed personal and health data belonging to about 4.1 million patients. The company says attackers gained access on June 5 through a social engineering attack that compromised a third-party contractor's privileged account, reaching cloud-based patient management and record systems. Exposed data includes names, contact and demographic details, health insurance information, and health records.

ShinyHunters gang claims theft of 200,000 records from Florida DMV's DAVID system

The ShinyHunters extortion group says it broke into Florida's DAVID driver database used by law enforcement, allegedly exploiting a password-reset weakness to hijack multiple accounts, including one belonging to an FBI agent. The hackers claim to have exfiltrated over 200,000 driver records and posted Jeffrey Epstein's DMV file—complete with his address, Social Security number, and vehicle history—as proof, while listing the Florida Highway Safety and Motor Vehicles agency on their leak site to pressure payment.

ShinyHunters' claimed ReliaQuest breach limited to view-only SSO access

Threat group ShinyHunters publicly taunted security vendor ReliaQuest, posting screenshots suggesting a compromised employee account and listing the company on its data leak site. ReliaQuest confirmed an employee was tricked via a vishing attack into entering credentials on a fake single sign-on page, but said the attacker only gained view-only access and could not move laterally or reach internal applications.

ShinyHunters claims theft of millions of patient records from McKesson's cloud systems

Pharmaceutical distributor McKesson confirmed hackers broke into several cloud-hosted accounts and stole data tied to its oncology and medical-surgical units. The ShinyHunters group told TechCrunch it used phishing and social engineering to trick employees into granting access, then pulled millions of rows of patient records from Snowflake and Salesforce environments, including names, Social Security numbers, diagnoses, medications, and employee home addresses.

McKesson confirms data breach after ShinyHunters claims 284 million patient records stolen

McKesson, a major U.S. healthcare and pharmaceutical distributor, disclosed in an SEC filing that it discovered unauthorized access to third-party applications and data exfiltration on August 25, 2026. The extortion group ShinyHunters claims responsibility, alleging it stole 284 million patient records, though McKesson has not confirmed the scope or named the affected applications. The company says its investigation is ongoing and has not yet determined whether the incident is financially material.

ShinyHunters leaks data from 12.9 million Carhartt accounts after ransom refusal

ShinyHunters, an extortion group, published roughly 50GB of stolen Carhartt data on the dark web after the apparel maker declined to pay a $3.3 million ransom demand. Have I Been Pwned founder Troy Hunt confirmed the leak stems from a breach of Carhartt's Databricks analytics platform, exposing 12.9 million accounts containing names, emails, phone numbers, and addresses, alongside employee and corporate records.

ReliaQuest says ShinyHunters phishing attempt was blocked before data access

ReliaQuest confirmed that ShinyHunters attackers impersonated its own security staff in vishing calls, directing an employee to a fake single sign-on page hosted on a lookalike domain, reliaquest.claims. The employee entered credentials and approved an MFA prompt, giving attackers brief, view-only access to an identity dashboard, but device-trust controls stopped further access to systems or customer data.