DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // SHINYHUNTERS-2026FIRST SEEN: 2020

SHINYHUNTERS

ALSO KNOWN AS: ShinyHunters
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (international)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:2020
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL71/100
RESOURCES71/100
PERSISTENCE74/100
STEALTH66/100
IMPACT80/100

ShinyHunters remained one of the most prolific data extortion actors through July 2026, with a confirmed breach of Abbott Laboratories' Cancer Diagnostics business (via a vishing campaign in mid-June 2026 that compromised a Microsoft Entra SSO account) and a subsequent claim against Fairlife, the Coca-Cola dairy brand, alleging exfiltration of 1TB of confidential data. Microsoft Defender Security Research published research on July 13 mapping a year of ShinyHunters campaigns abusing trusted OAuth relationships and long-lived application tokens across Salesforce environments, matching the Abbott intrusion's technical fingerprint. The group threatened Abbott with a July 18 deadline later extended to July 21, claiming 30M+ records including 1M+ Social Security numbers.

Financial extortion via large-scale data theft from enterprise cloud and identity infrastructure; double-extortion with public leak threats

Vishing (voice phishing), Microsoft Entra SSO compromise, OAuth abuse, long-lived application token hijacking, API credential harvesting, Salesforce ecosystem targeting, double-extortion, dark web leak site, MFA device registration abuse

HEALTHCARE
TECHNOLOGY
RETAIL
EDUCATION
MANUFACTURING
CLOUD-PLATFORMS

Dark web data leak site; Microsoft Entra/Azure identity exploitation; Salesforce OAuth token abuse; victim-branded credential harvesting pages; legitimate SSO/OAuth tokens for persistence

FILE DATE: JUL 2026
Abbott Laboratories Cancer Diagnostics Breach
Compromised Abbott's Cancer Diagnostics business via June 2026 vishing attack on employees, hijacking a Microsoft Entra SSO account to exfiltrate data from connected applications; claimed 30M+ records including 1M+ SSNs.
FILE DATE: JUL 2026
Fairlife (Coca-Cola) Extortion
ShinyHunters claimed exfiltration of 1TB of confidential Fairlife data and set ██████████████████ leak deadline, applying the same double-extortion pressure model used in the Abbott campaign.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn