Across the most recent 4 stories covering ShinyHunters — 100% negative sentiment, averaging 6.8/10 impact.
This entity profile aggregates every story where the entity meets our minimum relevance
threshold before it is linked here — a story naming this entity only in passing, as
competitive context for an unrelated subject, does not qualify. That threshold exists
because earlier testing surfaced entity pages cluttered with tangential mentions: a story
about two unrelated companies merging could otherwise populate a third company's page
simply because it was named once for comparison, with no real event of its own. The
timeline below reflects genuine milestones and developments specific to this entity,
cross-referenced against the same source-verification standard applied to every story on
this site. Sentiment measures the directional read of each development for this entity
specifically, not the overall tone of the reporting, and impact weights how consequential
a development is rather than how widely it was syndicated across outlets.
Figures are computed live from our source-verified story record — see our methodology for how impact and
sentiment are derived.
Timeline
Investigation Announced for JCPenney/Catalyst Brands
Edelson Lechtzin LLP issued a separate press release launching an investigation into the JCPenney and Catalyst Brands data breach.
ShinyHunters announces additional victims
On June 16, the group reveals new targets including Glendale Community College, Moody Bible Institute, Illinois Central College, and Houston City College.
The Credit Pros Breach Detected
The Credit Pros discovered a breach of its Salesforce environment, with Icarus claiming access to customer financial and personal data.
JCPenney/Catalyst Brands Breach Detected
JCPenney and Catalyst Brands learned of a data breach, later linked to ShinyHunters, compromising employee and possibly customer records including W-2s, SSNs, and government IDs.
Google/Mandiant publish findings
Google’s threat intelligence blog details the campaign, attribution, and sector impact.
Oracle issues security advisory
Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.
Campaign window closes
Last observed exploitation activity before Oracle issues its advisory.
FulcrumSec ransomware attack on Global Schools Foundation
The group exfiltrates data and disrupts operations across GSF's international network of schools in early June, causing widespread service outages.
Campaign begins
ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.
ShinyHunters Claim
The threat actor ShinyHunters publicly claims responsibility for stealing 1PB of data and issues an extortion threat.
Official Confirmation
Telus issues a statement confirming it is investigating a hack of its internal systems.
Initial Breach Reports
Reports surface on cybercrime forums claiming a massive data theft from Telus Digital.
ShinyHunters breaches Infinite Campus via Salesforce
Cybercriminals exploit a vulnerability to steal personal information from 137,000 school staff accounts, affecting the widely used K-12 student information system.
Two distinct threat groups, ShinyHunters and Icarus, have publicly claimed responsibility for separate breaches at JCPenney/Catalyst Brands and The Credit Pros, respectively. The attacks expose evolving cybercriminal tactics, including Salesforce environment exploitation and high-value PII harvesting.
Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.
An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.
Canadian telecommunications giant Telus is investigating a significant breach of its systems, specifically targeting its Telus Digital subsidiary. The threat actor ShinyHunters has claimed responsibility for the multi-month intrusion, allegedly exfiltrating one petabyte of sensitive data.
This page surfaces every story mentioning ShinyHunters across our cybersecurity coverage. We track each entity's appearance over time so readers can trace how the narrative evolves — which developments are isolated incidents, which build into longer arcs, and which reframe how operators in the space think about the entity. Story selection uses the same multi-source verification gate applied across the rest of our coverage.
Read our editorial methodology for how we identify, deduplicate, and score entity references. Our glossary defines the technical terms used across stories on this page, and our trends index contextualizes individual developments against the longer-running cybersecurity beat. Cross-entity comparisons live on our compare view.
Entities only appear on this page once the classifier scores them at a minimum 35 percent
relevance to the story, filtering out passing mentions. According to that methodology,
reviewed July 2026, this follows multi-source corroboration standards recommended by
journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong on this page — a misattributed entity, a wrong stat, a broken source
link? Report a data issue.
What you see
What it tells you
Story count
Number of distinct stories where ShinyHunters was a primary or referenced actor.
Recency clustering
Whether mentions are concentrated in a recent window (a news cycle) or distributed (a sustained arc).
Sentiment distribution
Aggregate sentiment of the stories mentioning this entity, weighted by impact score.
Cross-niche links
When the same entity surfaces in our sibling networks, we link to those views to enrich context.