rift.cysentrix
← Back to actors

Threat actor

ShinyHunters

14 observed events

AIThe observations include 13 ransomware incidents and 1 data breach, targeting the retail, technology, healthcare, and business services sectors, with the United States as the only country identified.

Activity type

Ransomware
13
Data breach
1

Verification

Claim
13
Confirmed
1

Top sectors

Business Services
1
Healthcare
1
Retail
1
Technology
1

Top countries

US
4

Observed events

Confirmed Critical Data breach

JCPenney

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later publi…

Actor ShinyHunters 1 source
Records 368,418
Claim High Ransomware

icsecurity.com

AIShinyHunters claims to have breached icsecurity.com, as listed on the RansomLook extortion site. The claim is unverified.

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

icsecurity.com

AIShinyHunters listed technology

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

Amazon owned OneMedical.com

AIShinyHunters claims to have data from healthcare provider Amazon-owned OneMedical.com in an unverified listing on Ransomware.live.

Actor ShinyHunters 2 sources
Records Undisclosed
Claim High Ransomware

NAIC.org

AIShinyHunters claims to have listed NAIC.org, a business services organization, on its extortion site. The claim is unverified.

Actor ShinyHunters 2 sources
Records Undisclosed
Claim High Ransomware

Ralph Lauren

AIShinyHunters claims to have breached Ralph Lauren and listed the organization on their extortion site.

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

icc.edu

AIShinyHunters listed icc.edu on their extortion site, claiming a breach. This claim is unverified.

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

moody.edu

AIShinyHunters claims to have breached moody.edu, listed on its extortion site (unverified).

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

glendale.edu

AIShinyHunters claims to have listed glendale.edu on RansomLook, an extortion-site listing. The claim is unverified.

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

hccs.edu

AIShinyHunters claims to have breached hccs.edu, as listed on their extortion site and tracked by RansomLook.

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

kodak.com

AIShinyHunters claims to have listed kodak.com on RansomLook, an extortion-site listing, as an unverified breach.

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

Deep Well Services

AIShinyHunters has listed Deep Well Services on its extortion site, claiming to have stolen data. This is an unverified claim.

Actor ShinyHunters 1 source
Records Undisclosed
Claim High Ransomware

Sysco Corporation

AISysco Corporation was listed by ShinyHunters on RansomLook; this is an unverified claim.

Actor ShinyHunters 1 source
Records Undisclosed