Who is ShinyHunters, and why is that name in every breach letter?

A hacking group said it took millions of customer records. Somebody opened the file and counted. The first big number in a breach story is a count of rows, not people.

Share
A woman at an office desk holding a corded desk phone to her ear, looking at the monitor in front of her
Most of these break-ins begin with a phone call to somebody at work. Photo: Centre for Ageing Better via Unsplash

ShinyHunters says it took about 284 million patient-related records from McKesson, a major American pharmaceutical distributor.

McKesson has confirmed a cybersecurity incident. Its filing with the SEC says the company found it on August 25, that the investigation is in its early stages, and that it has not determined the incident is material. A notice to customers says intruders reached third-party applications and took data. Over the weekend the company added that the stolen data belonged to a subset of customers in two of its business units, the ones covering cancer care and medical supplies, that it has cut off the access, and that it will give the people affected free credit monitoring. It still has not said what data was taken, how many people are involved, or who did it.

The 284 million is the group's own figure, and early coverage read it as 284 million patients. It is not that. ShinyHunters told BleepingComputer the number is a raw count of records, or lines, and that it has not finished going through the data and does not know how many people are in there.

Carhartt shows what usually happens to a number like that.

On August 13 the same group put Carhartt on its leak site and said it was holding more than 50 gigabytes of the company's data. Carhartt did not pay, and the data was published.

Then somebody opened it.

Troy Hunt runs Have I Been Pwned, the free service that tells you when your email address turns up in a breach. He downloaded the dump and ran his usual extractor over it, which pulled 24,876,077 unique email addresses. That figure is a machine count of every address in the files, and it is roughly what went into the first round of coverage.

Hunt kept hunting. A large share of those addresses sat in folders named for TPC-DS, a standard test dataset companies use to benchmark their analytics systems. Fake customers, generated for load testing. The individual records looked plausible, but the pile did not. Nearly every email domain appeared exactly one time. Birth years ran flat from 1924 to 1992, about 1,100 people a year with no bump anywhere. There were more customers born in Montenegro than in the United States.

He pulled the benchmark records, then duplicate Microsoft 365 addresses, then deactivated accounts and internal test domains. What he loaded into Have I Been Pwned was 12,933,413 addresses. Just under half the original count.

Two figures side by side: 24,876,077 addresses found on the first pass, and 12,933,413 that belonged to real people
The recount, after the benchmark records and duplicates came out.

Carhartt still looks breached

The data left after the cleanup still carries Carhartt's fingerprints. Hunt found 15,057 employee addresses ending in carhartt.com, internal system aliases nobody outside the company would know existed, and roughly 1,150 people who had tagged their own email address with "+carhartt" when they signed up. His conclusion was that Carhartt was almost certainly breached, and that the test records were most likely sitting beside the real ones when the attackers took everything. Carhartt has not put out a public statement about any of it.

Hunt also says he has reviewed close to a hundred leaks on this group's site and has yet to find one where the data was invented. He allows that the criminals may not be the ones who got this number wrong either. A real theft picked up a pile of benchmark records that were sitting in the same place. An automated tool counted them faithfully. Nobody further down the line opened the files. As Hunt puts it, "the truth is in the data."

Fourteen million records, 5.1 million people

Panera Bread ran into the same problem in January. ShinyHunters claimed more than 14 million records. Have I Been Pwned processed the leaked files and found about 5.1 million unique email addresses.

Both numbers are accurate. One person occupies several database rows. Old accounts stay in the table. Internal aliases count separately.

The smaller figure is still a lot of people. Of the Carhartt addresses Hunt loaded, 83 percent had already turned up in earlier breaches.

Arrests have not stopped it

The name ShinyHunters has been in the news since 2020 and people attached to it have been arrested more than once. Sebastien Raoult, a French member of the original crew, was extradited to the United States and sentenced in January 2024 to three years and more than $5 million in restitution. French police arrested four more people in June 2025 over the running of BreachForums, one of them using the ShinyHunters handle. The name was back in operation within weeks of both.

The FBI still calls ShinyHunters a cyber criminal group in its own advisories. Google's threat intelligence team is more cautious. It now tracks recent ShinyHunters-branded activity under three separate labels, partly to follow shifting partnerships and partly, in its own words, to "account for potential impersonation activity."

In May, Google documented one of those cases. It found that a separate crew it tracks as UNC6671 had used the ShinyHunters name at least once to make its own threats more credible. Google assesses that the two operations are independent, on the basis of different negotiation channels, different domain registration habits, and UNC6671's own leak site.

It often starts with a phone call

For the cloud-account campaigns that put this name in so many breach stories this year, the entry point has been ordinary. Someone at the company gets a call from a person claiming to be IT support. The caller sends them to a login page built to look like the company's own, at an address like companyname-sso.com, and talks them through signing in. The page captures the password and the multi-factor code. Google says none of that comes from a security hole in the vendors' products.

You have met this call. It is the fake fraud department or the fake tech-support call, directed at somebody's work account instead of their bank account. We wrote about the phone call itself back in June.

Not every attack under this name works that way. In June, Google's Mandiant team tied a separate campaign to a previously unknown flaw in Oracle PeopleSoft, the software many universities run their student, payroll and finance records on. Oracle put out an emergency patch after the attacks had already started. No phone call in that one, and universities took the worst of it.

Your information ends up in a dump because a company you dealt with kept it. The person who answered the phone may never have touched your account.

The email that follows is its own scam

The FBI put out an advisory about this group in May. Two things in it should stay with you.

The first is the wording. It says these actors use "real or exaggerated claims" about the sensitive information they hold to pressure people into paying. A sender can have real stolen data and still exaggerate what it proves.

A laptop screen showing a Gmail inbox with 152 unread messages
Photo: Justin Morgan via Unsplash

The second is what else has been happening. The FBI has seen threatening texts and calls aimed at victims and their families, fake emergency calls sent to their homes, and claims about compromising photos or videos that in many cases never existed. There is a whole side industry of scammers sending extortion emails under this brand, quoting a real leaked email address as their proof.

What you can do

Once your information is in a breach, what matters is what somebody can do with it next.

  • Turn on breach notifications at Have I Been Pwned. It is free, and it tells you when your address turns up in a dataset somebody has actually processed, rather than one somebody has advertised.
  • Freeze your credit if a breach you were caught in exposed your Social Security number or similar identity details. It blocks new accounts in your name and does nothing else, which is exactly what it is for.
  • Expect the follow-up. A leaked phone number, address or old password is what makes the next approach convincing. Our guides on spotting a phishing email and what to do after a scam both apply.
  • Use a different password everywhere and turn on multi-factor. A password manager handles the first part. For the second, read the prompt before you approve it, because approving one push notification is how a security company got broken into this month.
  • Do not treat an email address or an old password as proof that somebody has photos, video or access to your computer. If an extortion message knows your address, your phone number or an old password, those details may already be circulating from an earlier breach.

If you are in one of these

Look past the group name and the first big number, and find out which fields were exposed next to your account. A leaked email address is a different problem than a leaked password, and both are a different problem than a leaked Social Security number. What was exposed next to your name decides what you do today.

Sources:

[ Free every Tuesday, plus the Cache ]
Tech news without having to be tech savvy.
Subscribe ×