SUBJECT PROFILE
ShinyHunters remained one of the most prolific data extortion actors through July 2026, with a confirmed breach of Abbott Laboratories' Cancer Diagnostics business (via a vishing campaign in mid-June 2026 that compromised a Microsoft Entra SSO account) and a subsequent claim against Fairlife, the Coca-Cola dairy brand, alleging exfiltration of 1TB of confidential data. Microsoft Defender Security Research published research on July 13 mapping a year of ShinyHunters campaigns abusing trusted OAuth relationships and long-lived application tokens across Salesforce environments, matching the Abbott intrusion's technical fingerprint. The group threatened Abbott with a July 18 deadline later extended to July 21, claiming 30M+ records including 1M+ Social Security numbers.
Financial extortion via large-scale data theft from enterprise cloud and identity infrastructure; double-extortion with public leak threats
OPERATIONAL HISTORY
Vishing (voice phishing), Microsoft Entra SSO compromise, OAuth abuse, long-lived application token hijacking, API credential harvesting, Salesforce ecosystem targeting, double-extortion, dark web leak site, MFA device registration abuse
KNOWN INFRASTRUCTURE
Dark web data leak site; Microsoft Entra/Azure identity exploitation; Salesforce OAuth token abuse; victim-branded credential harvesting pages; legitimate SSO/OAuth tokens for persistence