Sentiment skews more negative than the wider beat, at 100% negative against 57% across all 584 Cybersecurity stories in the same window. Coverage clusters in data-breach, which accounts for 3 of those 5, with the remainder spread across 2 other categories.
Figures are computed live from our source-verified story record
— see our methodology for how impact and
sentiment are derived.
What the coverage shows about ShinyHunters
Sentiment skews more negative than the wider beat, at 100% negative against 57% across all 584 Cybersecurity stories in the same window. Coverage clusters in data-breach, which accounts for 3 of those 5, with the remainder spread across 2 other categories. Each story carries 2.2 original sources on average, compared with 3.1 for the broader beat in this window. Across a 154-day span, the pace is roughly 0.2 stories per week. The 6.6 average consequence score is below the beat benchmark of 6.8 in the same window. ShinyHunters is most often covered alongside Canvas, which appears in 1 of these 5 stories. We currently track 5 Cybersecurity stories that mention ShinyHunters, published between March 14, 2026 and August 14, 2026.
Stories tracked
5
Per week
0.2
Negative
100%
Sources per story
2.2
Computed from the 5 stories linked to this entity, with beat comparisons drawn from all 584 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.
Coverage cohort
Appears alongside
Other entities that clear the same relevance threshold in stories also covering ShinyHunters. Shared-story counts are live from our verified record — not editorial picks.
Have I Been Pwned confirms the leak and reports approximately 1.6 million unique email addresses with names, addresses, and phone numbers.
ShinyHunters leaks archive
After RingCentral does not pay, ShinyHunters publishes a compressed 280GB archive containing allegedly stolen data.
RingCentral discloses breach
RingCentral publishes a notice saying it detected and stopped unauthorized activity and began a forensic investigation.
ShinyHunters claims responsibility
ShinyHunters adds RingCentral to its Tor-based leak site and claims to have stolen 623GB of data.
Initial compromise
RingCentral later states the incident occurred in July as the result of a sophisticated social engineering campaign.
Investigation Announced for JCPenney/Catalyst Brands
Edelson Lechtzin LLP issued a separate press release launching an investigation into the JCPenney and Catalyst Brands data breach.
ShinyHunters announces additional victims
On June 16, the group reveals new targets including Glendale Community College, Moody Bible Institute, Illinois Central College, and Houston City College.
The Credit Pros Breach Detected
The Credit Pros discovered a breach of its Salesforce environment, with Icarus claiming access to customer financial and personal data.
JCPenney/Catalyst Brands Breach Detected
JCPenney and Catalyst Brands learned of a data breach, later linked to ShinyHunters, compromising employee and possibly customer records including W-2s, SSNs, and government IDs.
Google/Mandiant publish findings
Google’s threat intelligence blog details the campaign, attribution, and sector impact.
Oracle issues security advisory
Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.
Campaign window closes
Last observed exploitation activity before Oracle issues its advisory.
FulcrumSec ransomware attack on Global Schools Foundation
The group exfiltrates data and disrupts operations across GSF's international network of schools in early June, causing widespread service outages.
Campaign begins
ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.
ShinyHunters Claim
The threat actor ShinyHunters publicly claims responsibility for stealing 1PB of data and issues an extortion threat.
Official Confirmation
Telus issues a statement confirming it is investigating a hack of its internal systems.
Initial Breach Reports
Reports surface on cybercrime forums claiming a massive data theft from Telus Digital.
ShinyHunters breaches Infinite Campus via Salesforce
Cybercriminals exploit a vulnerability to steal personal information from 137,000 school staff accounts, affecting the widely used K-12 student information system.
RingCentral disclosed a sophisticated social engineering attack in July 2026 that ShinyHunters exploited to exfiltrate 623GB of data and leak a 280GB archive. Have I Been Pwned confirmed 1.6 million unique email addresses with names, phone numbers, and physical addresses are now in the wild, escalating phishing and account takeover risk for affected users.
Two distinct threat groups, ShinyHunters and Icarus, have publicly claimed responsibility for separate breaches at JCPenney/Catalyst Brands and The Credit Pros, respectively. The attacks expose evolving cybercriminal tactics, including Salesforce environment exploitation and high-value PII harvesting.
Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.
An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.
Canadian telecommunications giant Telus is investigating a significant breach of its systems, specifically targeting its Telus Digital subsidiary. The threat actor ShinyHunters has claimed responsibility for the multi-month intrusion, allegedly exfiltrating one petabyte of sensitive data.