The ShinyHunters Franchise: How a Cybercrime Brand Learned to Multiply

ShinyHunters has been claiming victims across nearly every sector for the past year, from Salesforce and Oracle clients to the Council of Europe. But ask three CTI analysts to define what ShinyHunters actually is today, and you may get three different answers. That confusion isn’t an accident. It’s the point.
In the third episode of Threat Signal, Citalid’s CTI Analyst Lorena Michoud walked through how ShinyHunters went from a single financially motivated intrusion set to a name that multiple distinct groups now claim, contest, or impersonate. For risk managers and CISOs trying to assess exposure to this actor, understanding that fragmentation matters as much as understanding the attacks themselves.
A name built on more than intrusions
ShinyHunters has been active since 2019, tracked by Citalid as a financially motivated, affiliate-type criminal collective with a structural organization and real operational capacity. Its core specialty is social engineering, particularly voice phishing (vishing), paired with a straightforward extortion model: exfiltrate sensitive data, then pressure the victim into paying to avoid disclosure, sometimes escalating through DDoS attacks, defacement, or harassment of employees.
But the name carries weight beyond the intrusions themselves. The individuals behind ShinyHunters also administered BreachForums, one of the largest cybercrime marketplaces, gathering around 300,000 user accounts between 2023 and its takedown in 2025. “It became a brand, and it is now a nerve center in the cybercrime ecosystem, gravitating around certain forums and communities, which makes it a very complex threat actor to map clearly.” Lorena Michoud explained. Running BreachForums is a separate role from the intrusion set’s own campaigns, but it’s a large part of why the name reached the notoriety it has.
From a phone call to a data leak site
That vishing specialty isn’t a side detail. It’s the hinge the entire operation turns on, and it’s worth walking through because it explains why the brand keeps generating new claims faster than most defenders can track them.
Watch the replay of Threat Signal Episode 3 with Lorena Michoud
Watch the replayThe main access vector is impersonation: ShinyHunters operators call employees while posing as the IT helpdesk of a SaaS provider, with the objective of obtaining authentication resources. Citalid tracks two distinct ways they get there. The first relies on fake connectors, decoy versions of legitimate tools such as the Salesforce Data Loader, which the victim is asked to connect. That action triggers an OAuth authorization that lets the operators capture and steal authentication tokens. The second relies on phishing sites built around convincing fake login pages, as was the case in the Okta campaign in January. That site was sophisticated enough to include a kit generating real-time MFA challenge notifications in the victim’s browser, mimicking the legitimate authentication flow closely enough to defeat standard push or OTP-based MFA.
Once the credentials and tokens are in hand, the operators use them to connect to third-party connectors or software extensions, which grant access to other SaaS solutions through single sign-on (SSO) mechanisms. That’s the pivot point: a single compromised login becomes a foothold across an entire chain of connected platforms, from which data can be accessed and exfiltrated before being claimed on ShinyHunters’ own data leak site.
But social engineering isn’t the only route in. ShinyHunters has also been observed exploiting vulnerabilities directly within SaaS solutions, notably a recent case involving Oracle PeopleSoft, which granted direct access to the system and allowed the operators to move laterally and exfiltrate data without needing to manipulate anyone first. That range, fluidly switching between vishing, fake connectors, phishing kits, and direct exploitation depending on what works against a given target, is how the group has claimed more than 90 victims since January 2026 alone.
From alliance to dissolution to impersonation
The clearest illustration of that complexity played out over the past year. ShinyHunters operates within a criminal community known as The Com, active on Telegram and largely made up of English and French speaking teenagers with financial motivations. Within that community, ShinyHunters operators interact with people behind other known intrusion sets, including Scattered Spider.
In August 2025, the two proclaimed an alliance under the name Scattered Lapsus$ Hunters, or SLH, and claimed a campaign against roughly 40 Salesforce client companies, with named victims including Toyota, Disney, Kering, Adidas, and IKEA. A month later, the alliance announced its own dissolution. What followed was more revealing than the announcement itself: ShinyHunters kept operating alone under the SLH banner on a new data leak site before that banner disappeared too, and the group disengaged from BreachForums and other social channels entirely, now communicating exclusively through its own data leak site.
That vacuum left room for others. Citalid tracks a separate collective calling itself Scattered Lapsus$ Shiny Hunters, or SLSH, a name close enough to the original to create confusion, running several Telegram channels with a loud, offensive communication style.
Using different names, joining genuine or invented alliances, creating brands, all of this is very beneficial for this kind of attacker, as it scatters attribution and generates interest.
Michoud noted. The BreachForums takedown itself triggered another round of fragmentation. Its dismantlement in October 2025 sparked an internal war over who would inherit its role, resulting in two new forums, PwnForums and Breached, run by competing actors who claim ties to ShinyHunters or impersonate the name outright to borrow its legitimacy.
Branding as a criminal strategy, not an exception
This isn’t unique to ShinyHunters. Cybercriminal branding is an established dynamic among affiliate-type intrusion sets, used partly to distract law enforcement, since extortion inherently exposes the actor behind it, and partly as an internal marketing strategy to assert dominance and recruit new members while pressuring victims. DragonForce follows a comparable logic, using its own sub-brand, RansomBay, to scatter attribution across its affiliates’ attacks.
For organizations trying to assess their exposure, the practical consequence is that chasing a stable definition of “who ShinyHunters is” can be the wrong question entirely. The group’s tactics, techniques, and procedures, particularly its reliance on social engineering against software as a service providers, are the more stable signal. The name attached to a given claim is often deliberately unstable.
Key takeaways
- ShinyHunters’ main access vector is vishing against SaaS helpdesks, combined with fake connectors, phishing kits, and direct exploitation of SaaS vulnerabilities, an adaptable playbook behind more than 90 claimed victims since January 2026.
- ShinyHunters has evolved from a single intrusion set into a brand that multiple actors now claim, contest, or impersonate.
- Its access relies mainly on social engineering (helpdesk impersonation, fake connectors, phishing sites) but also on direct exploitation of SaaS vulnerabilities, a versatility that has helped it claim more than 90 victims since January 2026.
- The August 2025 alliance with Scattered Spider (SLH), its subsequent dissolution, and the emergence of impersonators like SLSH illustrate how fluid these identities are.
- BreachForums’ takedown in October 2025 fueled further fragmentation, spawning competing forums (PwnForums, Breached) that also claim ties to the name.
- Criminal branding is a deliberate strategy across the ecosystem, seen elsewhere with DragonForce, used to scatter attribution and pressure victims.
- For risk assessment, focusing on tactics and third-party exposure is more reliable than trying to pin the name to a single, stable group.
Frequently asked questions
What is the link between ShinyHunters and BreachForums?
BreachForums was one of the most active criminal forums, used to exchange stolen data, tools, and access, and to announce claims or alliances. Individuals behind ShinyHunters administered it for two years before it was dismantled in October 2025. That takedown triggered an internal war within the ecosystem, leading to two new forums, PwnForums and Breached, run by competing actors who also claim ties to ShinyHunters or impersonate the brand to boost their own credibility.
Did ShinyHunters compromise Microsoft SharePoint?
No. ShinyHunters accesses the SharePoint instances of organizations it has already compromised through software as a service breaches. Microsoft SharePoint as a platform has not itself been compromised.
From brand confusion to defensible risk decisions
The fragmentation around the ShinyHunters name is a reminder that attribution in cybercrime is often a moving target, shaped as much by marketing incentives inside criminal communities as by the underlying intrusions. For CTI and risk teams, that argues for building assessments around observed tactics and third-party dependencies rather than a single actor’s identity, and for treating any claim from a data leak site as one data point among several rather than a verified fact.
Want the full breakdown?
