Shiny Hunters: One Name Behind a Dozen Mega-Breaches

Infographic 2026

Find Threat Talks on

Shiny Hunters: One Name Behind a Dozen Mega-Breaches

 

Salesforce, Google, Okta, Louis Vuitton, Allianz, Odido: all breached under the same name. Shiny Hunters may not even be one group. It is a brand that different criminal crews borrow to extort their victims, because the reputation does half the work. Almost none of it required sophisticated tooling.

 

 

Host Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Field CTO Rob Maas and ON2IT researcher Yuri Witt to trace how these breaches actually happen. The pattern is a phishing call to the help desk, over-permissive credentials, and data copied straight out of a SaaS platform. The controls that stop it are basic, which is exactly why so few teams have switched them on.

 

What you’ll learn

 

  • A brand, not a gang.** Why criminals rent a known extortion name instead of building their own.
  • The phone is the exploit.** How attackers pose as internal IT and get handed the keys.
  • Turn on the controls you already have.** IP-locking SaaS and deleting data you don’t need stop most of the damage, yet almost no one does either

Your cybersecurity experts

Rob Maas

Lieuwe Jan Koning

Co-founder & CTO
ON2IT

Yuriwit

Yuri Wit

Cybersecurity Reseacher ON2IT

Episode details

Shiny Hunters behaves less like a hacking group and more like a franchise. The leading theory is that it is a shared brand: a name and a single leak site that multiple crews reuse because credibility is what makes extortion pay. Victims only pay if they believe the data will stay offline, so the reputation is the product. One crew that breaks the promise devalues the name for everyone.

 

For defenders, that distinction is noise. As Rob Maas notes, it is still a group attacking you, only the publication changes. Chasing which crew is behind a given leak wastes energy that belongs on controls. The intrusions themselves are simple: phishing, often a plain phone call impersonating internal IT, followed by over-permissive credentials used to copy data directly from its source, most often Salesforce.

 

The fixes map to fundamentals. Multi-factor authentication, so a stolen password is not enough. IP access control on SaaS tenants, so a login from an unmanaged device simply fails, a measure Rob estimates only around 5% of organizations have configured properly. No over-permissive accounts, no unnecessary admin rights, and limits on living-off-the-land tools.

 

The overlooked control is data retention. Odido was still holding customer records seven years after those people left, plus social security numbers kept long after their one-time purpose. Attackers can only leak what you store. Reframing retention as a security decision, not just a backup or compliance question, is the takeaway most teams miss. It all traces back to trust being exploited, which is the problem Zero Trust was built to solve.
Infographic 2026

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

15 + 2 =

Christmas Hacker