Also known as: UNC6240, Bling Libra
ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. Known victims: 102
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ShinyHunters is a medium-sophistication criminal cyber threat actor primarily motivated by financial gain through ransomware and extortion activities. They are known for targeting educational institutions and other sectors in the United States, Australia, and the United Kingdom since their first appearance in April 2024. The group operates with a focus on data theft and has expanded their operations to include a ransomware-as-a-service (RaaS) offering called 'shinysp1d3r.' ShinyHunters has been linked to numerous high-profile breaches across multiple industries, including education, finance, retail, and healthcare. Their activities demonstrate a clear intent to exploit vulnerabilities for financial profit and organizational gain.
Goals & Targeting
ShinyHunters' strategic objectives are driven by financial gain through ransomware and data extortion. Their targeting profile focuses on industries with large user bases and sensitive data, such as education, retail, finance, and healthcare. The group's preference for English-speaking countries (United States, Australia, United Kingdom) suggests a potential geographic focus tied to their operational base or language capabilities. ShinyHunters' victims include both small businesses and large enterprises, indicating an adaptive approach to campaign targeting. Their operations often involve high-profile campaigns that attract media attention and serve as a deterrence to other threat actors.
Enhanced Description
ShinyHunters is a financially motivated cybercriminal group that emerged in 2024, primarily targeting organizations across the education sector and other industries through data-theft and extortion campaigns. Initially known for their involvement in ticket sales fraud via malicious software such as 'Snowflake,' ShinyHunters has evolved into a prominent player in the ransomware landscape. By late 2025, they launched their RaaS offering, 'shinysp1d3r,' which enables affiliates to carry out ransomware attacks under their banner. This expansion underscores their strategic shift toward broader criminal operations. The group has demonstrated significant capability in compromising large enterprise systems, including educational platforms like Instructure (Canva LMS) and McGraw Hill, as well as financial institutions, retail chains, and government entities. ShinyHunters' activities are notable for their use of double extortion tactics—encrypting data and threatening to leak it if demands are not met. This approach has made them one of the most impactful criminal groups in the cyber threat landscape. The arrest of four members by French authorities in August 2025 indicates law enforcement efforts to disrupt their operations, though ShinyHunters remains active as of July 2026.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ShinyHunters' campaigns are characterized by their double extortion tactics and the use of high-pressure demands to ensure payment. Their victims include educational institutions, healthcare providers, financial services companies, and retail chains. Notable campaigns have targeted organizations such as Instructure (Canva LMS), McGraw Hill, and multiple schools affected by the 2024 breach. The group's operational tempo is steady but often shifts in response to law enforcement actions or public exposure. ShinyHunters has demonstrated a preference for encrypting data and using fear tactics to maximize their financial gain.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in ShinyHunters' threat intelligence is high due to their extensive campaign activity, public reporting, and law enforcement actions. However, gaps exist regarding the group's exact geographic origin and the full extent of their operational infrastructure. Additionally, the evolution of their RaaS offering introduces new potential capabilities that may not yet be fully understood.
No tools linked yet.
No observed data linked yet.
46
Techniques
0
Tools
78
Campaigns
29
IOCs
0
Observed Data
12
Tactics