Yesterday, 11:47 PM
(07-25-2026, 03:42 AM)aqua Wrote: Some of the links I posted from ShinyHunters like Lacoste, Zara, Amazon Owned One Medical and others are dead due to ShinyHunters download server automatically changing IP's.woah this is crazy if this is like fr fr
Here's a link to their website and backup mirrors included for each leak on their site. I'm not affilated with ShinyHunters or any activity related to them. Everything I post on Spear is public information that anyone can find.
About: ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. ShinyHunters has breached 132 companies and counting.
Vulnerabilities Exploited (3):
Oracle
Oracle E-Business Suite (EBS)
CVE-2025-61882
Cisco
Cisco Unified Communications
CVE-2026-20045
Snowflake
Snowflake (credential stuffing / no MFA)
OAuth Abuse
TTPs Matrix:
Unsecured Credentials: Private Keys
Use Alternate Authentication Material: Application Access Token
Data from Information Repositories
Exfiltration Over Web Service
Data Encrypted for Impact
Phishing for Information: Spearphishing Attachment
Phishing: Spearphishing Voice (Vishing)
ShinyHunters Leaks Site: