SHINYHUNTERS
rooting your systems since '19 ;)
rooting your systems since '19 ;)
rooting your systems since '19 ;)
Over 62 gigabytes of Glendale Community College data (304,000+
files) was compromised across PeopleSoft Campus Solutions (GCC,
integrations, financial aid, and admission processing),
including 150,000+ student records with names, dates of birth,
and @student.glendale.edu emails, login and enrollment mapping
files, new student enrollment CSVs, immunization compliance
logs, admission checklist reports, financial aid batch exports,
and transcript PDFs spanning September 2020 through June
2026.
This is a final warning to reach out by 18 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 23 gigabytes of Moody Bible Institute data (1,300+ files,
tens of millions of records) was compromised across enrollment,
donor relations, payroll, and communications systems (MBI,
EDC/Salesforce leads, PeopleSoft PS_COMMUNICATION, Horizon SIS,
WHPD donor database, and Cadence admissions), including 46
million communication records, 2.2 million enrollment lead
records, 108,000 biodemographic master files with addresses and
birthdates, 3.3 gigabytes of donor gift data, employee payroll
XML with home addresses and earnings, 1,100+ admissions outreach
files, and student housing assignment records.
This is a final warning to reach out by 18 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 28 gigabytes of Illinois Central College data (122,000+
files) was compromised across PeopleSoft Campus Solutions and
Human Resources (ICC, SURS pension reporting, Workday costing,
and ICCB curriculum systems), including 9,200+ employee payslip
PDFs, 500+ SURS payroll files with Social Security numbers,
direct deposit records with bank account and routing numbers,
student financial aid and grade roster exports, enrollment CSVs
with @icc.edu accounts, and Workday salary allocation data
spanning 2021 through June 2026.
This is a final warning to reach out by 18 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 61 million Salesforce records across several tables, some
containing customer data/PII, employee data, and other internal
corporate data was compromised.
This is a final warning to reach out by 18 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 7k records containing customer PII and other internal
corporate data was compromised.
This is a final warning to reach out by 18 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 2.2 million records containing customer PII and other
internal corporate data was compromised.
This is a final warning to reach out by 18 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Hundreds of thousands of student records containing full name,
home address, phone, email, date of birth, gender, ethnicity,
enrollment status, GPA, major, and student ID across all
campuses. Daily and full student roster exports library
credentials, PINs, and @student[.hccs[.edu accounts. Over 12,000
financial aid and bursar reports including FAFSA/ISIR suspense
data with names, birthdates, emails, phones, and home addresses.
Class rosters with birthdates, grades, academic programs, and
contact information for tens of thousands of enrolled students
per term. Over 344,000 international student documents including
SEVIS I-20 forms, visa applications, passports, bank statements,
tax returns, immigration affidavits, and acceptance letters.
Over 14,000 student immunization and vaccination records
including meningitis compliance documentation. Over 15,000
additional health and immunization documents across report
archives and A LOT more was compromised.
This is a final warning to reach out by 18 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 297 GB of Council of Europe HR and payroll data (429,000+
files) was compromised across the Secretariat, Directorate of
Human Resources, Parliamentary Assembly, EDQM, permanent and
temporary staff, interpreters, conference services, language
booth units, and payroll administration, including 409,000+
payslips for 10,000+ staff from 2011 to 2026, 14,000+ CVs and
3,700+ in-house personnel files, 10,700+ per-employee document
stores, contract and purchase order records, mission travel
overpayments, interpreter scheduling and 2026 salary scales,
Blue List rosters, absence and illness reports, bank account and
URSSAF payroll data, performance evaluations, and payroll
exports, covering full names, employee IDs, home addresses,
phone numbers, dates of birth, salaries, bank details, tax and
social security information, medical and absence records,
mission references, and other internal institutional data.
This is a final warning to reach out by 16 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 5.2 million records consiting of a significant amount of
customer and landowner PII, other records tied to other high
profile telecom/ISP companies, several tower asset records
containing GPS data and plaintext physical access/gate codes for
cell tower compunds across the United States, thousands of
internal corporate data, and a lot more were compromised.
We urge you to reach out.
This is a final warning to reach out by 15 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Hundreds of thousands of records containing PII (SSN, DOB,
etc.), W-2 tax records, pay data, physical scans of government
identity documents, drive licenses, and a lot more was
compromised.
This is a final warning to reach out by 15 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 26 million records containing customer PII and other
internal corporate data was compromised.
This is a final warning to reach out by 15 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 220GB of data containing customer PII, purchase/trasnaction
info, future unreleased releases from 2027 and onward, and more
was compromised.
This is a final warning to reach out by 14 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Over 1 million Salesforce records and other internal corporate
data containing PII was compromised.
This is a final warning to reach out by 14 June 2026 before we
leak along with several annoying (digital) problems that'll come
your way. Make the right decision, don't be the next headline.
Due to the significant influx of activity going on, we are
kindly advising everyone who is being contacted by us to start
responding or the inevitable will happen after the deadline. We
are not bluffing. Thank you.
Make the right decision, don't be the next headline.
Over 40 GB of billing and payment records, credit card and payment details, student finance data, and campus portal exports from the University of Nottingham and its Malaysia and China campuses was compromised, including payer contact information, transaction amounts, IP addresses, full names, home addresses, postcodes, email addresses, phone numbers, dates of birth, and other internal campus data.
Over 260k Salesforce records and various Sharepoint sites
corporate data has been compromised.
The company
failed to reach an agreement with us despite our incredible
patience, all the chances and offers we made. They don't care.
Over 700k Salesforce records and various Sharepoint sites
corporate data has been compromised.
The company
failed to reach an agreement with us despite our incredible
patience, all the chances and offers we made. They don't care.
The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Over 42M records containing PII have been compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
The domain shinyhunte.rs was suspended, it is not operated and
owned by us anymore.
We will not operate on any clearnet domain moving forward
unless otherwise stated.
DISCLAIMER: It may be reclaimed by unknown persons in the
future for malicious use. We do not control shinyhunte.rs
anymore, it has been suspended by the registry.
Update, May 27, 4:30 a.m. ET: We will operate at this
onion domain only moving forward. This onion page is the only
official page for updates. We will not operate on any other
clearnet domain unless otherwise stated here. Anyone claiming to
be us anywhere is impersonating. Our new PGP key is listed in
the « Contact us! » button
Over 500k Salesforce records containing PII and other internal
corporate data have been compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 16M unique persons records containing significant PII,
financial/transactions (credit cards), KYC and
data from TransUnion and Experian (background checks).
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 250k+ Salesforce records containing PII was compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Your Snowflake and Bigquery instances data was compromised
thanks to Anodot.com.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 10M Salesforce records containing PII and other internal
corporate data was compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 1.4M Salesforce records containing PII and other internal
corporate data was compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 30M Salesforce records containing PII and other internal
corporate data was compromised. Interesting and compromising
data in here for this company.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Sensitive customer PII data and transactional history data was
compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care.
Your Bigquery instances data was compromised
thanks to Anodot.com.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 600k Salesforce records containing PII and other internal
corporate data have been compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 8.7M records containing PII and other terabytes of internal
corporate data have been compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 25M Salesforce records containing PII have been
compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 5.6M Salesforce records containing PII have been
compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
BreachForums has been run by many fakes, but not by us anymore,
following the FBI seizure on 10 Oct 2025.
We (real
ShinyHunters
group) also do not operate on any Telegram platform or leak
forum platforms. People claiming to be us are fake,
impersonators, and scammers. Including breachforums.ai being a
scam and a fake.
Maintaining such an ecosystem is a waste of our time. There was
an unauthorised leak on 9 Jan 2026. Ever since then, false
personas going by “N/A“ and “Indra“ were successfully able to
restore a similar-looking “legitimate“ forum. All the current
forums are fake [ .ai, .sb, .ac, .fi, .bf, .us, ect.]. If they
continue to exist, we'll leak all the BF backups, including
every private message, emails, IP addresses, posts, ect. We have
exploits for all 1.8 versions of MyBB.
Over 2.5M records containing PII and other internal corporate
data have been compromised.
Please read the chatlog of the negociation by cliking the
Download button below to see why this data was leaked.
Over 9.4M Salesforce records containing PII and other internal
corporate data have been compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 13M Salesforce records containing PII and other internal
corporate data have been compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Over 40M Salesforce records containing PII data have been
compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care.
Over 1.7M Salesforce records containing PII have been
compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Your Snowflake instances metrics data was compromised
thanks to Anodot.com.
We do not operate a Telegram channel and this data was
never for sale like reported on X (formerly Twitter) for $200k.
It is now leaked.
How does it feel to be the headline?
Over 7.9M records containing PII data have been compromised.
The company failed to reach an agreement with us despite our
incredible patience, all the chances and offers we made. They
don't care.
Several terabytes combined from Snowflake, Mixpanel, Salesforce,
financial/kyc data, other data containing sensitive PII,
business data, and ect. were compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care AT ALL.
Over 350 GB+ of data was compromised, including data dumps of mail servers, databases, confidential documents, contracts, and much more sensitive material.
Salesforce records containing PII and other internal corporate
data have been compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care.
Salesforce records containing PII and other internal corporate data have been compromised.
Salesforce records containing PII and other internal corporate
data have been compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care.
Over 900k records containing PII and other internal corporate
data have been compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care.
Over 800k records containing PII and over 40k financial
documents/internal corporate data have been compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care about their clients
nor investors.
Woflow and clients (DoorDash, Deliveroo, etc.) database records
were compromised and other internal corporate data have been
compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care about their clients,
partners, nor investors. You should've just paid the ransom. See
below.
[22:48:17] aegis_support: honestly we are still freaking out
about the whole thing
Salesforce records were compromised and other internal corporate
data have been compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care about their clients
nor investors.
Due to recent developments regarding this telco, daily leaks
will not happen anymore. Instead, you can download the Odido
dataset concerning its full former and current customers below.
Over 15m Salesforce records containing Full Names, Physical
addresses, email addresses, phone numbers, and plaintext
passwords, IBAN, passport numbers, driver license numbers and
other internal corporate data have been compromised.
This is your fault, Odido. You are the reason why an entire
country is about to suffer for an unestimated amount of years.
Unprecedented.
Over 100k Salesforce records were compromised including over 59k
containing PII and other internal corporate data have been
compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care about their clients
nor investors.
Over 5M Salesforce records were compromised including over 1.3M
containing PII and other internal corporate data have been
compromised.
The company failed to reach an agreement with us despite all the
chances and offers we made. They don't care about their clients
nor investors.
Over 12.4M records containing PII and other internal corporate data have been compromised.
Over 600k records containing PII and payment/financial information have been compromised.
Over 1 million records containing PII were compromised.
They decided to waste time and hide instead because their
leadership is a mess and can't make a decision.
They were given multiple chances to pay the ransom, but they decided to waste time and hide instead.
Over 1 million records containing PII and donation data have been compromised.
This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.
"Fewer than 10 records"* ;)
containing PII and donation data have been compromised.
*: More like 1.2 million
This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.
Thousands of internal documents from Bumble. Our exfiltration focused on documents designated at restricted or confidential. Files primarily from Google Drive and Slack.
Over 10 million lines of Hinge, Match, and OkCupid usage data from Appsflyer and hundreds of internal documents.
Don't be an idiot like this company. Make the right decision; don't be the next headline. Get off your moral high horse and make the right decision for your stakeholders. PAY OR LEAK otherwise you'll be made an example of.
Over 14 million records containing Personally Identifiable Information (PII) have been compromised.
Don't be an idiot like this company. Make the right decision, don't be the next headline.
Records containing Personally Identifiable Information (PII) have been compromised.
Over 400 thousand records containing Personally Identifiable Information (PII) have been compromised.
Over 2 million records containing Personally Identifiable Information (PII) have been compromised.
Betterment refused our generous offers as low as $0.95 per active customer record stolen. If you are a Betterment customer, remember that they value your privacy and peace of mind lower than the price of a roll of toilet paper.
Over 2 million records containing Personally Identifiable Information (PII) have been compromised.
Over 30 million records containing Personally Identifiable Information (PII) have been compromised.