← BACK TO FEED
TAG

shinyhunters5 articles

ShinyHunters Padded the Carhartt Breach With Millions of Fake Records

Carhartt suffered a data breach affecting approximately 12.9 million individuals — roughly half the 25 million claimed by hacking group ShinyHunters, which had padded the dataset with millions of lines of synthetic data. Troy Hunt of Have I Been Pwned uncovered the inflation through careful analysis, using tools to identify fake email domains, implausible demographics, and other anomalies before arriving at the genuine figure. The real breach exposed names, email addresses, phone numbers, and physical addresses, with Carhartt yet to publicly comment on the incident.

27 Aug 2026

ShinyHunters Turns Up the Heat on Ernst & Young After Tax Data Breach

Ernst & Young (EY) suffered a data breach between March 28 and April 12, in which hackers stole sensitive client information — including Social Security numbers, account numbers, and tax-related documents — from a third-party service management platform. The notorious extortion group ShinyHunters has since claimed responsibility, adding EY to its leak site and threatening to release the stolen data if the firm does not make contact by July 31. EY has not disclosed the number of affected individuals or confirmed the attacker's identity, but is offering impacted clients 24 months of free credit monitoring and identity protection services.

16 Aug 2026

ShinyHunters Dumps 41GB of Brinks Home Data After Ransom Goes Unpaid

Brinks Home, a Dallas-based home security firm, has suffered a data breach carried out by the ShinyHunters extortion group, who claim to have stolen over 4.9 million records from the company's Salesforce instance. After Brinks Home refused to pay a ransom, the hackers leaked more than 41GB of files online, which allegedly include personally identifiable information (PII). The company has confirmed the breach but stated that its alarm monitoring and core security systems were not affected, and is working to identify impacted individuals.

3 Aug 2026

ShinyHunters Breach Exposes Data of 3.8 Million Medtronic Patients

Medical technology company Medtronic suffered a data breach in April 2026 when the extortion group ShinyHunters accessed its corporate IT systems, compromising the personal and medical information of over 3.8 million individuals. Stolen data included names, contact details, dates of birth, Social Security numbers, and health-related information, though Medtronic states there is no evidence the data was publicly exposed. The company is offering affected individuals 24 months of free credit monitoring and identity theft protection services, and has implemented additional cybersecurity safeguards.

14 Jul 2026

Medtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach

Medtronic is notifying patients that their personal and health data — including names, Social Security numbers, and medical information — may have been stolen during a cyberattack in which unauthorised actors accessed its corporate systems for nearly a week in April. The extortion group ShinyHunters claimed responsibility, alleging it stole over nine million records and demanding a ransom, though Medtronic has not publicly attributed the attack or confirmed whether data was actually exfiltrated. The company states that no medical devices were affected and is offering impacted individuals two years of complimentary credit and identity monitoring services.

11 Jul 2026