ShinyHunters is a
black-hat
A black hat (black hat hacker or blackhat) is a computer security hacker, hacker who violates laws or ethical standards for nefarious purposes, such as cybercrime, cyberwarfare, or malice. These acts can range from Online piracy, piracy to identi ...
criminal
hacker group
Hacker groups are informal communities that began to flourish in the early 1980s, with the advent of the home computer.
Overview
Prior to that time, the term ''hacker'' was simply a referral to any Hacker (hobbyist), computer hobbyist. The hacker ...
that is believed to have formed in 2020 and is said to have been involved in numerous data breaches. The stolen information is often sold on the
dark web
The dark web is the World Wide Web content that exists on darknets ( overlay networks) that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communica ...
.
Name and alias
The name of the group is believed to be derived from
shiny Pokémon, a mechanic in the
''Pokémon'' video game franchise where Pokémon have a rare chance of being encountered in an alternate, "shiny" color scheme; players who actively try to collect such Pokémon through in-game strategies are often referred to as "shiny hunters".
Notable data breaches
*AT&T Wireless: In 2021, ShinyHunters began selling information on 70 million AT&T wireless subscribers, which contained users' phone numbers, personal information and social security numbers. AT&T acknowledged the data breach in 2024.
*Tokopedia: On 2 May 2020
Tokopedia was breached by ShinyHunters, which claimed to have data for 91 million user accounts, revealing users' gender, location, username, full name, email address, phone number, and hashed passwords.
*Wishbone: Also in May 2020, ShinyHunters leaked the full user database of Wishbone, which is said to contain personal information such as usernames, emails, phone numbers, city/state/country of residence, and hashed passwords.
*Microsoft: In May 2020, ShinyHunters also claimed to have stolen over 500 GB of
Microsoft
Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
source code from the company's private
GitHub
GitHub () is a Proprietary software, proprietary developer platform that allows developers to create, store, manage, and share their code. It uses Git to provide distributed version control and GitHub itself provides access control, bug trackin ...
account. The group published around 1GB of data from the hacked GitHub account to a hacking forum. Some cybersecurity experts doubted the claims until analyzing the code; upon analysis, ShinyHunters' claims were no longer in question. Microsoft told ''Wired'' in a statement that they are aware of the breach. Microsoft later secured their GitHub account, which was confirmed by ShinyHunters as they reported being unable to access any repositories.
*Wattpad: In July 2020, ShinyHunters gained access to the
Wattpad database containing 270 million user records. Information leaked included usernames, real names, hashed passwords, email addresses, geographic location, gender, and date of birth.
*Pluto TV: In November 2020, it was reported that ShinyHunters gained access to the personal data of 3.2 million
Pluto TV
Pluto TV is an American free ad-supported streaming television service owned and operated by the Paramount Streaming division of Paramount Global. Founded by Tom Ryan (business executive), Tom Ryan, Ilya Pozin and Nick Grouf in 2013 and based in ...
users. The hacked data included users' display names, email addresses, IP addresses, hashed passwords and dates of birth.
*Animal Jam: It was also reported in November 2020 that ShinyHunters was behind the hack of
Animal Jam, leading to the exposure of 46 million accounts.
*Mashable: In November 2020, ShinyHunters leaked 5.22GB worth of the
Mashable
Mashable is a Online newspaper, news website, digital media platform and entertainment company founded by Pete Cashmore in 2005.
History
Mashable was founded by Pete Cashmore while living in Aberdeen, Scotland, in July 2004. Early iterations o ...
database on a prominent hacker forum.
*Pixlr: In January 2021, ShinyHunters leaked 1.9 million user records from
Pixlr.
*Nitro PDF: In January 2021, a hacker claiming to be a part of ShinyHunters leaked the full database of
Nitro PDF
Nitro Pro is a Portable Document Format (PDF) editing application and electronic signature software.
History
Nitro Software was founded in Melbourne, Australia, by a team of three. The company developed PDF software as an alternative to Adobe ...
— which contains 77 million user records — on a hacker forum for free.
*Bonobos: Also in January 2021 it was reported that ShinyHunters leaked the full
Bonobos
The bonobo (; ''Pan paniscus''), also historically called the pygmy chimpanzee (less often the dwarf chimpanzee or gracile chimpanzee), is an endangered great ape and one of the two species making up the genus ''Pan (genus), Pan'' (the other bei ...
backup cloud database to a hacker forum. The database is said to contain the address, phone numbers, and order details for 7 million customers; general account information for another 1.8 million registered customers; and 3.5 million partial credit card records and hashed passwords.
*Aditya Birla Fashion and Retail: In December 2021, Indian retailer
Aditya Birla Fashion and Retail was breached and ransomed. The ransom demand was allegedly rejected and data containing 5.4 million unique email addresses were subsequently dumped publicly on a popular hacking forum the next month. The data contained extensive personal customer information including names, phone numbers, physical addresses, birth dates, order histories and passwords stored as
MD5
The MD5 message-digest algorithm is a widely used hash function producing a 128-bit hash value. MD5 was designed by Ronald Rivest in 1991 to replace an earlier hash function MD4, and was specified in 1992 as Request for Comments, RFC 1321.
MD5 ...
hashes
*Mathway: In January 2020, ShinyHunters breached Mathway, stealing roughly 25 million users' data. Mathway is a popular math app for students that helps solve algebraic equations.
*Santander: On 30 May 2024
Santander was breached by ShinyHunters, which resulted in all Santander staff and '30 million' customers in Spain, Chile and Uruguay hacked.
*Ticketmaster: Hackers working with ShinyHunters have claimed responsibility for breaching
Ticketmaster
Ticketmaster Entertainment, LLC is an American ticket sales and distribution company based in Beverly Hills, California, with operations in many countries around the world. In 2010, it merged with Live Nation under the name Live Nation Ente ...
.
*AT&T Wireless: In April 2024, hackers affiliated with ShinyHunters hacked AT&T Wireless and stole data on over 110 million customers. In May, AT&T paid a $370,000 ransom to one of the group's members to delete the data.
Snowflake data hacks
In 2024, someone associated with the group ShinyHunters claimed to have
hacked Snowflake-related customers including
Ticketmaster
Ticketmaster Entertainment, LLC is an American ticket sales and distribution company based in Beverly Hills, California, with operations in many countries around the world. In 2010, it merged with Live Nation under the name Live Nation Ente ...
,
Santander Bank, and
Neiman Marcus
Neiman Marcus is an American department store chain founded in 1907 in Dallas, Texas by Herbert Marcus, his sister Carrie Marcus Neiman, and her husband Abraham Lincoln Neiman. It has been owned by Saks Global, a Corporate spin-off, spin-o ...
. The group was also responsible for publishing data stolen from
Twilio and
Truist Bank.
Other data breaches
The following are other hacks that have been credited to or allegedly done by ShinyHunters. The estimated impacts of user records affected are also given.
*
JusPay - 100 million user records
*
Zoosk - 30 million user records
*
Chatbooks - 15 million user records
*
SocialShare - 6 million user records
*
Home Chef - 8 million user records
*
Minted - 5 million user records
*
Chronicle of Higher Education
''The Chronicle of Higher Education'' is an American newspaper and website that presents news, information, and jobs for college and university faculty and student affairs professionals, including staff members and administrators. A subscriptio ...
- 3 million user records
*
GuMim - 2 million user records
*Mindful - 2 million user records
*
Bhinneka - 1.2 million user records
*
StarTribune - 1 million user records
*
Dave.com - 7.5 million users
*
Drizly.com - 2.4 million user records
*
Havenly - 1.3 million user records
*
Hurb.com - 20 million user records
*
Indabamusic - 475,000 user records
*
Ivoy.mx - 127,000 user records
*
Mathway - 25.8 million user records
*
Proctoru - 444,000 user records
*
Promo.com - 22 million user records
*
Rewards1 - 3 million user records
*
Scentbird - 5.8 million user records
*
Swvl
Swvl Holdings Corp. is an Dubai-based provider of intercity, intracity, B2B and B2G transportation products and services. Swvl operates in 135 cities in 20 countries across Latin America, Europe, Africa and Asia. The company went public in March ...
- 4 million user records
*
Glofox - Unknown
*
Truefire - 602,000 user records
*
Vakinha - 4.8 million user records
*
Appen.com - 5.8 million user records
*
Styleshare - 6 million user records
*
Bhinneka - 1.2 million user records
*
Unacademy
Unacademy is an Indian educational technology company headquartered in Bangalore. It provides an Distance education, online educational platform that hosts online courses and exam preparation materials. The company was founded by Gaurav Munjal, ...
- 22 million user records
*
Upstox - 111,000 user records
*
Aditya Birla Fashion and Retail - 5.4 million user records
Lawsuits
ShinyHunters group is under investigation by the
FBI
The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
, the Indonesian police, and the Indian police for the Tokopedia breach. Tokopedia's CEO and founder also confirmed this claim via a statement on Twitter.
Minted company reported the group's hack to US federal law enforcement authorities; the investigation is underway.
Administrative documents from California reveal how ShinyHunters' hack has led to Mammoth Media, the creator of the app Wishbone, getting hit with a
class-action lawsuit
A class action is a form of lawsuit.
Class Action may also refer to:
* ''Class Action'' (film), 1991, starring Gene Hackman and Mary Elizabeth Mastrantonio
* Class Action (band), a garage house band
* "Class Action" (''Teenage Robot''), a 2002 e ...
.
Animal Jam stated that they are preparing to report ShinyHunters to the FBI Cyber Task Force and notify all affected emails. They have also created a 'Data Breach Alert' on their site to answer questions related to the breach.
BigBasket filed a
First Information Report (FIR) on November 6, 2020, to the Bengaluru Police to investigate the incident.
Dave also initiated an investigation against the group for the company's security breach. The investigation is ongoing and the company is coordinating with local law enforcement and the FBI.
Wattpad stated that they reported the incident to law enforcement and engaged third-party security experts to assist them in an investigation.
Arrests
In May 2022,
Sébastien Raoult, a French programmer suspected of belonging to the group, was arrested in Morocco and extradited to the United States. He faced 20 to 116 years in prison.
In January 2024 Raoult was sentenced to three years in prison and ordered to return five million dollars.
Twelve months of the sentence are for conspiracy to commit wire fraud and the remainder for aggravated
identity theft
Identity theft, identity piracy or identity infringement occurs when someone uses another's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. ...
.
[ He will face 36 months of supervised release afterwards.][ Raoult had worked for the group for more than two years according to the US Attorney's Office for the Western District of Washington.][
]
References
{{Hacking in the 2020s
Hacker groups
Hacking in the 2020s
Cybercrime in India