Actor Profile

ShinyHunters is a financially motivated cybercrime extortion gang known for large-scale data theft and public leak operations. The group specializes in breaching organizations to exfiltrate sensitive customer and employee data, which they leverage for extortion by threatening public disclosure on their data leak site. ShinyHunters has demonstrated proficiency in social engineering attacks, particularly voice phishing (vishing) targeting cloud identity platforms, and has established a pattern of targeting diverse sectors including healthcare, professional services, and now residential security providers. The actor operates a dedicated leak site where they list victims and threaten data publication to pressure ransom payment.

TTPs (Tactics, Techniques, Procedures)

Initial Access: T1566.004 (Phishing: Spearphishing Voice/Vishing) - ShinyHunters conducted a Microsoft Entra voice phishing attack on July 13, 2026, calling a Brinks Home employee and convincing them to complete authentication or registration, resulting in account compromise. Collection: T1213.002 (Data from Information Repositories: Sharepoint) and T1213 (Data from Information Repositories) - Exfiltrated over 1.1 million rows from Salesforce "Contacts" Object, 4,000+ rows of employee PII, and 3.8 million customer support chat logs from Brinks Care Cresta instance. Credential Access: T1078.004 (Valid Accounts: Cloud Accounts) - Obtained valid Microsoft Entra credentials through social engineering to access cloud resources. Exfiltration: T1567 (Exfiltration Over Web Service) - Extracted approximately 4.9 million Salesforce records containing PII. Impact: T1486 (Data Encrypted for Impact) and T1657 (Financial Theft) - Extortion through threatened public data disclosure on ShinyHunters leak site.

Targets & Patterns

ShinyHunters targets organizations across multiple sectors with valuable customer databases and PII holdings. In this incident, they targeted Brinks Home, a residential security provider with $830M annual revenue serving over 1 million customers across the United States, Canada, and Puerto Rico. The selection appears motivated by the high volume of sensitive customer data (home security customers, contact information, support interactions) and the reputational damage potential for a security-focused company. Related reporting indicates ShinyHunters has also targeted healthcare organizations (Health-ISAC warnings, DentaQuest breach affecting 2.6M accounts), professional services firms (Ernst & Young), and other data-rich enterprises. The targeting pattern suggests opportunistic selection based on cloud infrastructure vulnerabilities, employee accessibility via social engineering, and the presence of large-scale customer databases that can be monetized through extortion or secondary fraud schemes (as evidenced by ShinyHunters data fueling sextortion campaigns).

Historical Context

ShinyHunters has established a consistent operational pattern of high-profile data breaches followed by extortion and public leak threats. Recent campaigns attributed to the group include breaches of Ernst & Young (professional services), DentaQuest (healthcare, 2.6 million accounts exposed), and Abbott (amid extortion claims). Health-ISAC issued warnings about rising ShinyHunters data theft attacks specifically targeting the healthcare sector. The group's stolen data has been observed fueling secondary criminal activity, including $2,000 sextortion email scams leveraging ShinyHunters leak data. The Brinks Home incident follows ShinyHunters' established playbook: social engineering for initial access, mass exfiltration of cloud-hosted customer data (particularly from Salesforce instances), listing victims on their leak site, and threatening public disclosure. The July 2026 Brinks breach demonstrates continued evolution in their vishing techniques, specifically targeting Microsoft Entra (formerly Azure AD) authentication flows to compromise cloud identity infrastructure.

Defensive Recommendations

  • Implement phishing-resistant multi-factor authentication (MFA) such as FIDO2/WebAuthn for all Microsoft Entra accounts to prevent vishing attacks that bypass SMS/voice-based MFA (mitigates T1566.004)
  • Deploy conditional access policies in Microsoft Entra requiring device compliance and trusted location verification for authentication, particularly for access to sensitive cloud applications like Salesforce
  • Establish mandatory employee security awareness training focused on vishing scenarios, including verification procedures for authentication requests received via phone calls claiming to be from IT or security teams
  • Monitor Microsoft Entra sign-in logs (Azure AD Sign-in Logs) for anomalous authentication patterns including unusual geolocation, impossible travel, new device registrations, and MFA method changes
  • Implement data loss prevention (DLP) controls and egress monitoring for Salesforce and other SaaS platforms to detect bulk data export activities (T1567), with alerting on unusual query volumes or mass record access