Home  

Random  

Nearby  



Log in  



Settings  



Donate  



About Wikipedia  

Disclaimers  



Wikipedia





ShinyHunters





Article  

Talk  



Language  

Watch  

Edit  





ShinyHunters is a black-hat criminal hacker group that is believed to have formed in 2020 and is said to have been involved in numerous data breaches. The stolen information is often sold on the dark web.[1][2]

Name and alias

edit

The name of the group is believed to be derived from shiny Pokémon, a mechanic in the Pokémon video game franchise where Pokémon have a rare chance of being encountered in an alternate, "shiny" color scheme, with such Pokémon considered elusive to players.[3] The avatar of a Twitter profile tied to the group contains a picture of a shiny Pokémon.[3]

Notable data breaches

edit

Other data breaches

edit

The following are other hacks that have been credited to or allegedly done by ShinyHunters. The estimated impacts of user records affected are also given.[23][24][25]

  • Zoosk - 30 million user records[27]
  • Chatbooks -15 million user records[27]
  • SocialShare - 6 million user records[27]
  • Home Chef - 8 million user records[27]
  • Minted - 5 million user records[27]
  • Chronicle of Higher Education - 3 million user records[27]
  • GuMim - 2 million user records[27]
  • Mindful - 2 million user records[27]
  • Bhinneka - 1.2 million user records[27]
  • StarTribune - 1 million user records[27]
  • Dave.com- 7.5 million users[28]
  • Drizly.com - 2.4 million user records[29]
  • Havenly - 1.3 million user records[29]
  • Hurb.com - 20 million user records[30]
  • Indabamusic - 475,000 user records[30]
  • Ivoy.mx - 127,000 user records[30]
  • Mathway - 25.8 million user records[30]
  • Proctoru - 444,000 user records[29]
  • Promo.com - 22 million user records[31]
  • Rewards1- 3 million user records[30]
  • Scentbird - 5.8 million user records[29]
  • Swvl - 4 million user records[30]
  • Glofox - Unknown[32]
  • Truefire - 602,000 user records[29]
  • Vakinha - 4.8 million user records[29]
  • Appen.com - 5.8 million user records[29]
  • Styleshare - 6 million user records[30]
  • Bhinneka - 1.2 million user records[30]
  • Unacademy - 22 million user records[33][34]
  • Upstox - 111,000 user records[35]
  • Aditya Birla Fashion and Retail - 5.4 million user records[30]
  • Lawsuits

    edit

    ShinyHunters group is under investigation by the FBI, the Indonesian police, and the Indian police for the Tokopedia breach. Tokopedia's CEO and founder also confirmed this claim via a statement on Twitter.[36][37]

    Minted company reported the group's hack to US federal law enforcement authorities; the investigation is underway.[38]

    Administrative documents from California reveal how ShinyHunters' hack has led to Mammoth Media, the creator of the app Wishbone, getting hit with a class-action lawsuit.[39]

    Animal Jam stated that they are preparing to report ShinyHunters to the FBI Cyber Task Force and notify all affected emails. They have also created a 'Data Breach Alert' on their site to answer questions related to the breach.[40]

    BigBasket filed a First Information Report (FIR) on November 6, 2020, to the Bengaluru Police to investigate the incident.[41]

    Dave also initiated an investigation against the group for the company's security breach. The investigation is ongoing and the company is coordinating with local law enforcement and the FBI.[42]

    Wattpad stated that they reported the incident to law enforcement and engaged third-party security experts to assist them in an investigation.[43]

    Arrests

    edit

    In May 2022, Sébastien Raoult, a French programmer suspected of belonging to the group, was arrested in Morocco and extradited to the United States. He faced 20 to 116 years in prison.[44][45]

    In January 2024 Raoult was sentenced to three years in prison and ordered to return five million dollars.[46] Twelve months of the sentence are for conspiracy to commit wire fraud and the remainder for aggravated identity theft.[46] He will face 36 months of supervised release afterwards.[46] Raoult had worked for the group for more than two years according to the US Attorney's Office for the Western District of Washington.[46]

    References

    edit
    1. ^ a b "ShinyHunters Is a Hacking Group on a Data Breach Spree". Wired. ISSN 1059-1028. Retrieved 2021-01-25.
  • ^ Cimpanu, Catalin. "A hacker group is selling more than 100 billion user records on the dark web". ZDNet. Retrieved 2021-01-25.
  • ^ a b Hernandez, Patricia (2 February 2016). "One Man's Five-Year Quest To Find A Shiny Pokémon". Kotaku. Archived from the original on 16 December 2017. Retrieved 15 December 2017.
  • ^ "A Notorious Hacker Gang Claims to Be Selling Data on 70 Million AT&T Subscribers". GIzmodo. 21 August 2021. Retrieved 26 August 2023.
  • ^ "AT&T finally acknowledged the data breach". Bleeping Computer. Retrieved 26 August 2023.
  • ^ "AT&T acknowledges data breach affecting 51 million people - Panda Security". 12 April 2024.
  • ^ Cimpanu, Catalin. "Hacker leaks 40 million user records from popular Wishbone app". ZDNet. Retrieved 2021-01-25.
  • ^ "Microsoft's GitHub account breached by threat actors Shiny Hunters". TechGenix. May 21, 2020.
  • ^ "'Shiny Hunters' bursts onto dark web scene following spate of breaches". SC Media. May 8, 2020.
  • ^ "Microsoft's GitHub account hacked, private repositories stolen". BleepingComputer.
  • ^ Deschamps, Tara (2020-07-21). "Wattpad storytelling platform says hackers had access to user email addresses". CTVNews. Retrieved 2021-01-25.
  • ^ "Wattpad warns of data breach that stole user info | CBC News". CBC. Retrieved 2021-01-25.
  • ^ "Wattpad data breach exposes account info for millions of users". BleepingComputer. Retrieved 2021-01-25.
  • ^ "ShinyHunters hacked Pluto TV service, 3.2M accounts exposed". Security Affairs. 2020-11-15. Retrieved 2021-01-25.
  • ^ "3 Million Pluto TV Users' Data Was Hacked, But the Company Isn't Telling Them". www.vice.com. 4 December 2020. Retrieved 2021-01-25.
  • ^ "Animal Jam was hacked, and data stolen; here's what parents need to know". TechCrunch. 16 November 2020. Retrieved 2021-01-25.
  • ^ "Animal Jam kids' virtual world hit by data breach, impacts 46M accounts". BleepingComputer. Retrieved 2021-01-25.
  • ^ "ShinyHunters hacker leaks 5.22GB worth of Mashable.com database". 5 November 2020. Retrieved 27 May 2023.
  • ^ Service, Tribune News. "Hacker leaks 1.9 million user records of photo editing app Pixlr". Tribuneindia News Service. Retrieved 2021-01-25.
  • ^ "Hacker leaks full database of 77 million Nitro PDF user records". BleepingComputer. Retrieved 2021-01-25.
  • ^ "Bonobos clothing store suffers a data breach, hacker leaks 70GB database". BleepingComputer. Retrieved 2021-01-25.
  • ^ "Bonobos clothing store suffers a data breach, hacker leaks 70GB database". RestorePrivacy. 11 January 2022. Retrieved 2022-01-11.
  • ^ May 2020, Jitendra Soni 11 (11 May 2020). "ShinyHunters leak millions of user details". TechRadar. Retrieved 2021-01-25.{{cite web}}: CS1 maint: numeric names: authors list (link)
  • ^ July 2020, Nicholas Fearn 29 (29 July 2020). "386 million user records stolen in data breaches — and they're being given away for free". Tom's Guide. Retrieved 2021-01-25.{{cite web}}: CS1 maint: numeric names: authors list (link)
  • ^ ""Shiny Hunters" Hacker Group Keep 73 Mn User Records on Darknet". CISO MAG | Cyber Security Magazine. 2020-05-11. Retrieved 2021-01-25.
  • ^ "Amazon, Swiggy's payment processor hit by data breach". The Times of India. Retrieved 2021-01-05.
  • ^ a b c d e f g h i j Cimpanu, Catalin. "A hacker group is selling more than 73 million user records on the dark web". ZDNet.
  • ^ "ShinyHunters Offers Stolen Data on Dark Web". Dark Reading. 28 July 2020. Retrieved 2021-01-25.
  • ^ a b c d e f g "ShinyHunters Offers Stolen Data on Dark Web". Dark Reading. 28 July 2020.
  • ^ a b c d e f g h i "ShinyHunters leaked over 386 million user records from 18 companies". Security Affairs. July 28, 2020.
  • ^ "Promo.com data breach impacts 23 million content creators". The Daily Swig | Cybersecurity news and views. July 28, 2020.
  • ^ Taylor, Charlie. "Irish start-up Glofox investigates possible data breach". The Irish Times. Retrieved 2021-01-25.
  • ^ Defense, Binary. "Shiny Hunters Group Selling Data Stolen From 11 Different Companies". Retrieved 27 May 2023.
  • ^ "Shiny Hunters hackers try to sell a host of user records from breaches". MalwareTips Community.
  • ^ "ShinyHunters dump partial database of broker firm Upstox". hackread.com. 12 April 2021.
  • ^ "Who are Shiny Hunters?". AndroidRookies. May 21, 2020.
  • ^ @UnderTheBreach (May 13, 2020). "Twitter post" (Tweet) – via Twitter. [dead link]
  • ^ "Minted confirms data breach as Shiny Hunters sell its database". 29 May 2020.
  • ^ "Wishbone App Maker Mammoth Media Hit with Class Action Over Data Breach Affecting 40 Million Users". www.classaction.org. 4 June 2020.
  • ^ "Animal Jam kids' virtual world hit by data breach, impacts 46M accounts". BleepingComputer.
  • ^ "BIGBASKET, INDIA'S LEADING ONLINE SUPERMARKET SHOPPING, ALLEGEDLY BREACHED. PERSONAL DETAILS OF OVER 20 MILLION PEOPLE SOLD IN DARKWEB | Cyble". cybleinc.com. 7 November 2020.
  • ^ "Security incident at Dave". A Banking Blog for Humans. July 25, 2020.
  • ^ "FAQs on the Recent Wattpad Security Incident". Help Center.
  • ^ "Sébastien Raoult, Français incarcéré au Maroc, menacé d'extradition aux Etats-Unis où il risque une lourde peine". lemonde.fr (in French). August 3, 2022.
  • ^ "Cybercriminalité: Détenu aux Etats-Unis, le Français Sébastien Raoult espère toujours un "retour en France"". 31 May 2023.
  • ^ a b c d Jones, Connor (2024-01-10). "ShinyHunters chief phisherman gets 3 years, must cough up $5M". The Register. Retrieved 2024-01-12.

  • Retrieved from "https://en.wikipedia.org/w/index.php?title=ShinyHunters&oldid=1235547873"
     



    Last edited on 19 July 2024, at 21:27  





    Languages

     


    Français
    Oʻzbekcha / ўзбекча
     

    Wikipedia


    This page was last edited on 19 July 2024, at 21:27 (UTC).

    Content is available under CC BY-SA 4.0 unless otherwise noted.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Terms of Use

    Desktop