# ShinyHunters

Type: organization

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/shinyhunters
Canonical HTML page: https://getcyberbrief.com/entity/shinyhunters

## Timeline

- **2026-06-18**: Investigation Announced for JCPenney/Catalyst Brands — Edelson Lechtzin LLP issued a separate press release launching an investigation into the JCPenney and Catalyst Brands data breach.
- **2026-06-17**: Investigation Announced for The Credit Pros — Edelson Lechtzin LLP issued a press release launching an investigation into data privacy claims against The Credit Pros.
- **2026-06-16**: ShinyHunters announces additional victims — On June 16, the group reveals new targets including Glendale Community College, Moody Bible Institute, Illinois Central College, and Houston City College.
- **2026-06-16**: The Credit Pros Breach Detected — The Credit Pros discovered a breach of its Salesforce environment, with Icarus claiming access to customer financial and personal data.
- **2026-06-12**: JCPenney/Catalyst Brands Breach Detected — JCPenney and Catalyst Brands learned of a data breach, later linked to ShinyHunters, compromising employee and possibly customer records including W-2s, SSNs, and government IDs.
- **2026-06-11**: Google/Mandiant publish findings — Google’s threat intelligence blog details the campaign, attribution, and sector impact.
- **2026-06-10**: Oracle issues security advisory — Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.
- **2026-06-09**: Campaign window closes — Last observed exploitation activity before Oracle issues its advisory.
- **2026-06**: FulcrumSec ransomware attack on Global Schools Foundation — The group exfiltrates data and disrupts operations across GSF's international network of schools in early June, causing widespread service outages.
- **2026-05-27**: Campaign begins — ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.
- **2026-03-14**: ShinyHunters Claim — The threat actor ShinyHunters publicly claims responsibility for stealing 1PB of data and issues an extortion threat.
- **2026-03-13**: Official Confirmation — Telus issues a statement confirming it is investigating a hack of its internal systems.
- **2026-03-12**: Initial Breach Reports — Reports surface on cybercrime forums claiming a massive data theft from Telus Digital.
- **2026-03**: ShinyHunters breaches Infinite Campus via Salesforce — Cybercriminals exploit a vulnerability to steal personal information from 137,000 school staff accounts, affecting the widely used K-12 student information system.

## Recent coverage (4 stories)

### ShinyHunters and Icarus claim 2 high-impact breaches in one week
2026-06-19 21:15:15 · Sentiment: Very Bearish · Impact: 6/10 · Sources: 3

Two distinct threat groups, ShinyHunters and Icarus, have publicly claimed responsibility for separate breaches at JCPenney/Catalyst Brands and The Credit Pros, respectively. The attacks expose evolving cybercriminal tactics, including Salesforce environment exploitation and high-value PII harvesting.
Full story: https://getcyberbrief.com/story/shinyhunters-icarus-credit-pros-jcpenney-breach-2026

### ShinyHunters & FulcrumSec Ramp Up EdTech Attacks: 137K Accounts Stolen
2026-06-18 00:56:16 · Sentiment: Bearish · Impact: 8/10 · Sources: 2

Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.
Full story: https://getcyberbrief.com/story/cyber-edtech-breach-shinyhunters-fulcrumsec-timeline

### 68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch
2026-06-12 04:54:34 · Sentiment: Bearish · Impact: 7/10 · Sources: 2

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.
Full story: https://getcyberbrief.com/story/shinyhunters-oracle-peoplesoft-zero-day-education

### Telus Probes Massive Data Breach as ShinyHunters Claims 1PB Theft
2026-03-14 02:06:05 · Sentiment: Bearish · Impact: 6/10 · Sources: 2

Canadian telecommunications giant Telus is investigating a significant breach of its systems, specifically targeting its Telus Digital subsidiary. The threat actor ShinyHunters has claimed responsibility for the multi-month intrusion, allegedly exfiltrating one petabyte of sensitive data.
Full story: https://getcyberbrief.com/story/telus-investigating-system-hack-shinyhunters

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.