There’s a particular kind of breach story that’s become almost routine at this point. A company sends out an email, apologizes, offers a year of credit monitoring, and life goes on. But every so often, the same name keeps showing up at the bottom of these stories, over and over, across companies that have nothing in common a ticketing platform, a bank, a photo editor, an auto parts chain. That name is ShinyHunters.
What’s odd about ShinyHunters isn’t that they’re especially skilled. Most of what they’ve pulled off didn’t require any real technical wizardry. What’s odd is how long they’ve lasted, how many arrests they’ve survived, and how deliberately they’ve run the whole thing like a business with pricing strategies, product launches, and even a kind of franchise model.
The name first appeared in underground circles in late 2019, but 2020 is really when it started meaning something. A handful of big breaches that year put ShinyHunters on the radar, and looking back, you can already see the pattern that would define the group for the next half-decade: get in quietly, grab everything, leak a sample to prove it’s real, then sell the rest.
Tokopedia was one of the first. Indonesia’s largest online marketplace lost roughly 91 million user records emails, birthdates, hashed passwords, that sort of thing. The breach itself happened sometime in late 2019, though nobody found out until the database turned up on a forum the following May. The asking price? About $5,000. Cheap, in hindsight, but this was still early days.
Then came Wattpad, a few months later, and this one was on a different scale entirely 270 million records, one of the largest hauls the group has ever claimed. What’s more interesting than the size, honestly, is how they sold it. Rather than dumping the whole thing at once, they sold it privately first to a small group of buyers, reportedly for around $100,000. Only once that window of exclusivity closed did the data eventually spread to the wider forums for free. It’s basically the same logic a software company uses with early-access pricing, just applied to stolen identities.
There was also a strange little episode involving Microsoft, in May 2020, when the group claimed to have taken over 500GB of private source code from a Microsoft GitHub account. They posted about a gigabyte as proof. Microsoft locked the account, the group lost access, and that was that no big payday, no lasting damage. But it did something for their reputation that money couldn’t buy: it told the rest of the underground that no name was too big to go after.
If you had to pick one moment where ShinyHunters stopped being “just another breach crew” and became something closer to a systemic threat, it would be the Snowflake campaign in 2024.
Here’s the thing people often get wrong about it: Snowflake itself was never hacked. Not their infrastructure, not their code. Every single incident traced back to individual customer accounts accounts that had no multi-factor authentication, passwords that hadn’t been changed in years, and no restrictions on where logins could come from. The credentials themselves had been sitting around in infostealer logs for ages, some dating as far back as 2020, scooped up by malware like Vidar, RedLine, Raccoon Stealer and Lumma, often from a contractor’s personal laptop that had nothing to do with the company being targeted the kind of machine that’s also got a couple of pirated games installed on it.
Once they were in, there wasn’t much drama to it. They used Snowflake’s own legitimate tools SnowSight, SnowSQL, a utility called DBeaver to run queries that, on the surface, looked like ordinary business analytics. They built a custom recon tool to map out each environment before pulling data. They routed everything through commercial VPNs and a Moldovan hosting provider, and staged the stolen files on MEGA. Because none of it looked unusual from the outside, some of these intrusions went unnoticed for weeks.
And the list of who got hit is honestly kind of staggering when you see it all together. Ticketmaster and Live Nation around 560 million customer records, including partial card data. AT&T call and text metadata for nearly all of its wireless customers, roughly 109 million people, and reportedly a $370,000 payout just to get the data deleted (complete with a “proof of deletion” video from the hacker, for whatever that’s worth). Santander lost data on about 30 million people across Spain, Chile and Uruguay. Then there’s Advance Auto Parts, Neiman Marcus, LendingTree, Pure Storage, Bausch Health, and the Los Angeles school district, among others.
None of these needed a custom attack. One weak habit customers not locking down their own cloud accounts turned into dozens of breaches spanning retail, banking, healthcare, education, and telecom, all through the same door.
This is maybe the most underrated part of the ShinyHunters story. Most crews sell what they steal on someone else’s marketplace. ShinyHunters ended up running the marketplace itself.
BreachForums came up as the replacement for RaidForums after law enforcement shut that one down in 2022. When BreachForums’ own admin, “Pompompurin,” got arrested in 2023 and the site went dark, ShinyHunters partnered with a previous admin and relaunched it this time under their own control. From that point on, they weren’t just another vendor. They owned the platform where everyone’s stolen goods, not just their own, got bought and sold.
Keeping that control turned out to be a fight in itself. The FBI seized the domain in May 2024, and the operators got it back within hours using nothing more than a registrar transfer code. The site disappeared again in April 2025 (a claimed zero-day in the forum software), came back in June, and by the end had basically stopped being a general marketplace at all it became a dedicated extortion page for the group’s Salesforce campaign, complete with countdown timers hanging over non-paying victims. Authorities finally took the domain down for good in October 2025. ShinyHunters’ response was to walk away entirely, leak roughly 300,000 of their own users’ data on the way out, and warn everyone that any BreachForums site still standing was probably a law-enforcement trap.
In August 2025, something changed that made all of this more dangerous. ShinyHunters publicly merged with two other well-known crews Scattered Spider and Lapsus$ into a combined operation calling itself Scattered Lapsus$ Hunters.
The logic isn’t hard to follow once you break it down. Scattered Spider is good at getting in the door social engineering, help-desk manipulation, SIM-swapping, bypassing MFA. Lapsus$ brings insider recruitment and a flair for loud, public extortion. ShinyHunters brings what it’s always done best: pulling the data out efficiently and turning it into cash. Put those three together and you’ve got a full attack chain, start to finish and the group has more or less said as much themselves, describing the arrangement almost like a division of labor on an org chart.
Since then they’ve tried an “extortion-as-a-service” model, where smaller affiliates rent the brand and infrastructure to go after their own targets, and they’ve teased a custom ransomware strain called ShinySp1d3r, apparently meant to compete with the likes of LockBit.
Their biggest move under the new name was a wave of attacks against Salesforce customers using pure social engineering calling employees, posing as IT support, and talking them into approving a fake “Data Loader” app that then quietly exported huge amounts of customer data. The group has claimed data from something like 760 companies through this and related token abuse, with names like Google, Adidas, Cartier, Louis Vuitton, Chanel, Qantas, Cisco, and even Harvard showing up on the list. It was serious enough that the FBI put out a FLASH alert over it in September 2025.
And then there’s Jaguar Land Rover, which is worth mentioning because it shows this alliance isn’t limited to quiet data theft. The August 2025 intrusion attributed to the same three-group alliance forced JLR to shut down production lines globally for weeks. That’s the kind of real-world, physical disruption you’d usually associate with a ransomware gang, not a data broker. It says something about how far this group is now willing to go.
To be fair to law enforcement, there have been real wins. Sébastien Raoult, known online as “Sezyo Kaizen,” was arrested in Morocco back in 2022 and sentenced to three years in the US. Connor Riley Moucka, believed to be one of the central figures behind the Snowflake campaign, was picked up in Canada in late 2024. Kai West, allegedly a BreachForums admin operating as “IntelBroker,” was arrested in France in early 2025. Four more people tied to the ShinyHunters name were arrested in France that June.
And yet, none of it has really slowed things down. The group keeps calling those arrested “affiliates” rather than core members and in a strange twist, one of the group’s own former administrators publicly claimed in late 2025 that the “real” ShinyHunters had already been caught, and that whoever was still posting under the name had inherited the group’s PGP key and was essentially running a con. Whether that’s true or not, it says something honest about this whole scene: the brand has grown bigger than any one person behind it. Names, keys, and personas get passed around and impersonated so often that arresting someone doesn’t guarantee you’ve stopped the operation.
If there’s a single lesson buried in all of this, it’s that almost none of it required breaking through a firewall or finding some obscure zero-day. ShinyHunters built its entire reputation on stolen passwords, credentials nobody bothered to rotate, employees who got talked into clicking the wrong thing, and OAuth tokens that were trusted far more than they should have been.
That’s the part that should worry security teams more than any single flashy exploit. You can’t patch your way out of this kind of problem. What actually matters is identity enforcing MFA everywhere, rotating credentials on a schedule, watching for unusual bulk exports, and treating every contractor, vendor integration, and help-desk call as a potential opening. As long as valuable data sits behind logins that can be phished, stolen, or just handed over by a tired employee on the phone, the model ShinyHunters built isn’t going anywhere. It’ll just keep resurfacing under whatever name comes next.