Cybersecurity entity

ShinyHunters

organization

Of the tracked stories, 1 of 4 also mention Canvas, the most common co-covered peer. Source depth averages 2.3 original sources per story, versus 3.1 across the same-window beat baseline. Across a 98-day span, the pace is roughly 0.3 stories per week.

Last mentioned: Jun 19, 2026

Entity pulse

Recent coverage · ShinyHunters

4 stories
6.8 avg impact
0% positive
100% negative

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

What the coverage shows about ShinyHunters

Of the tracked stories, 1 of 4 also mention Canvas, the most common co-covered peer. Source depth averages 2.3 original sources per story, versus 3.1 across the same-window beat baseline. Across a 98-day span, the pace is roughly 0.3 stories per week. At 6.8, the average consequence score sits below the same-window beat average of 7.1. Coverage clusters in data-breach, which accounts for 2 of those 4, with the remainder spread across 2 other categories. ShinyHunters appears in 4 tracked Cybersecurity stories published from March 14, 2026 through June 19, 2026.

Stories tracked
4
Per week
0.3
Sources per story
2.3

Computed from the 4 stories linked to this entity, with beat comparisons drawn from all 244 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.

Coverage cohort

Appears alongside

Other entities that clear the same relevance threshold in stories also covering ShinyHunters. Shared-story counts are live from our verified record — not editorial picks.

Timeline

  1. Investigation Announced for JCPenney/Catalyst Brands

    Edelson Lechtzin LLP issued a separate press release launching an investigation into the JCPenney and Catalyst Brands data breach.

  2. ShinyHunters announces additional victims

    On June 16, the group reveals new targets including Glendale Community College, Moody Bible Institute, Illinois Central College, and Houston City College.

  3. The Credit Pros Breach Detected

    The Credit Pros discovered a breach of its Salesforce environment, with Icarus claiming access to customer financial and personal data.

  4. JCPenney/Catalyst Brands Breach Detected

    JCPenney and Catalyst Brands learned of a data breach, later linked to ShinyHunters, compromising employee and possibly customer records including W-2s, SSNs, and government IDs.

  5. Google/Mandiant publish findings

    Google’s threat intelligence blog details the campaign, attribution, and sector impact.

  6. Oracle issues security advisory

    Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.

  7. Campaign window closes

    Last observed exploitation activity before Oracle issues its advisory.

  8. FulcrumSec ransomware attack on Global Schools Foundation

    The group exfiltrates data and disrupts operations across GSF's international network of schools in early June, causing widespread service outages.

  9. Campaign begins

    ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.

  10. ShinyHunters Claim

    The threat actor ShinyHunters publicly claims responsibility for stealing 1PB of data and issues an extortion threat.

  11. Official Confirmation

    Telus issues a statement confirming it is investigating a hack of its internal systems.

  12. Initial Breach Reports

    Reports surface on cybercrime forums claiming a massive data theft from Telus Digital.

  13. ShinyHunters breaches Infinite Campus via Salesforce

    Cybercriminals exploit a vulnerability to steal personal information from 137,000 school staff accounts, affecting the widely used K-12 student information system.

Stories mentioning ShinyHunters 4

Data Breaches Strongly negative

ShinyHunters and Icarus claim 2 high-impact breaches in one week

Two distinct threat groups, ShinyHunters and Icarus, have publicly claimed responsibility for separate breaches at JCPenney/Catalyst Brands and The Credit Pros, respectively. The attacks expose evolving cybercriminal tactics, including Salesforce environment exploitation and high-value PII harvesting.

3 sources
Data Breaches Negative

ShinyHunters & FulcrumSec Ramp Up EdTech Attacks: 137K Accounts Stolen

Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.

2 sources
Threat Intelligence Negative

68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.

2 sources

Source: The Star Online (my) · Reuters Last Updated (in)

ShinyHunters is linked from 4 stories on this site, each scored at or above our 35% relevance threshold — see how these pages are built.

See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.