Actor Profile

ShinyHunters is a prolific extortion-focused cybercrime group known for large-scale data theft operations targeting cloud platforms and enterprise systems. The group operates a dark web leak site where they publish stolen data after failed ransom negotiations. ShinyHunters is financially motivated, demanding multi-million dollar ransoms and publicly releasing victim data to pressure payment and damage organizational reputation. In this incident, they demanded $3.3 million from Carhartt before leaking approximately 50GB of stolen data affecting 12.9 million customer accounts.

TTPs (Tactics, Techniques, Procedures)

The Carhartt breach involved compromise of the company's Databricks analytics platform, a cloud-based data warehouse environment. ShinyHunters gained unauthorized access to sensitive customer and employee data stored within this platform. Key TTPs include: exploitation of cloud platform misconfigurations or compromised credentials (T1078 - Valid Accounts), data exfiltration from cloud storage (T1530 - Data from Cloud Storage), and extortion tactics involving ransom demands and public data leaks (T1657 - Financial Theft). The group exfiltrated over 50GB of data including customer PII, employee records, and corporate documents. ShinyHunters has demonstrated capability to exploit zero-day vulnerabilities (Oracle PeopleSoft), compromise third-party cloud platforms (Snowflake, Salesforce), and conduct mass credential-based attacks.

Targets & Patterns

ShinyHunters targets organizations across diverse sectors with emphasis on entities using cloud-based data platforms and analytics services. In this campaign, the retail sector was targeted via Carhartt, a major American apparel manufacturer. Historical targeting patterns show the group focuses on high-value data repositories containing large volumes of customer PII suitable for resale or extortion leverage. Previous victims span technology (Google, Cisco), entertainment (Rockstar Games, PornHub, Vimeo), education (McGraw Hill, Udemy), healthcare (Medtronic), government (European Commission), and hospitality (Carnival, 7-Eleven, Match Group). The group systematically exploits cloud platform vulnerabilities and misconfigurations, particularly targeting Snowflake, Salesforce, Databricks, and Oracle PeopleSoft environments. Target selection appears driven by data volume, sensitivity of exposed information, and organizational ability to pay substantial ransoms.

Historical Context

ShinyHunters has maintained sustained operations over the past year with escalating scope and sophistication. The group claimed responsibility for breaches at over a dozen Snowflake customers and numerous third-party integration providers. They conducted large-scale campaigns against Salesforce customers (Aura and Salesloft Drift campaigns), claiming theft of over 1.5 billion records. Most recently prior to Carhartt, ShinyHunters exploited an Oracle PeopleSoft zero-day vulnerability to breach more than 100 organizations. Notable historical victims include the European Commission, Google, Cisco, Match Group, Rockstar Games, McGraw Hill, 7-Eleven, Carnival, Udemy, and Medtronic. The Carhartt breach follows ShinyHunters' established pattern: initial access to cloud platforms, mass data exfiltration, ransom demands in the millions, and public data leaks following non-payment. The group's operational tempo and victim count indicate an active, well-resourced threat actor with deep expertise in cloud platform exploitation.

Defensive Recommendations

  • Implement strict access controls and multi-factor authentication for all cloud analytics platforms including Databricks, Snowflake, and Salesforce environments to mitigate T1078 (Valid Accounts) abuse
  • Deploy cloud access security broker (CASB) solutions with data loss prevention (DLP) policies to detect and block large-scale data exfiltration attempts from cloud storage (T1530)
  • Conduct regular security audits of cloud platform configurations, focusing on publicly exposed storage buckets, overly permissive IAM roles, and credential hygiene in data warehouse environments
  • Monitor for anomalous data access patterns including bulk downloads, unusual query volumes, or access from unfamiliar IP ranges within cloud analytics platforms
  • Establish incident response procedures specifically for extortion scenarios, including pre-approved communication protocols and decision frameworks for ransom demands to minimize negotiation exposure