07-25-2026, 03:42 AM
Some of the links I posted from ShinyHunters like Lacoste, Zara, Amazon Owned One Medical and others are dead due to ShinyHunters download server automatically changing IP's.
Here's a link to their website and backup mirrors included for each leak on their site. I'm not affilated with ShinyHunters or any activity related to them. Everything I post on Spear is public information that anyone can find.
About: ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. ShinyHunters has breached 132 companies and counting.
Vulnerabilities Exploited (3):
Oracle
Oracle E-Business Suite (EBS)
CVE-2025-61882
Cisco
Cisco Unified Communications
CVE-2026-20045
Snowflake
Snowflake (credential stuffing / no MFA)
OAuth Abuse
TTPs Matrix:
Unsecured Credentials: Private Keys
Use Alternate Authentication Material: Application Access Token
Data from Information Repositories
Exfiltration Over Web Service
Data Encrypted for Impact
Phishing for Information: Spearphishing Attachment
Phishing: Spearphishing Voice (Vishing)
ShinyHunters Leaks Site: Hidden Content
Here's a link to their website and backup mirrors included for each leak on their site. I'm not affilated with ShinyHunters or any activity related to them. Everything I post on Spear is public information that anyone can find.
About: ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. ShinyHunters has breached 132 companies and counting.
Vulnerabilities Exploited (3):
Oracle
Oracle E-Business Suite (EBS)
CVE-2025-61882
Cisco
Cisco Unified Communications
CVE-2026-20045
Snowflake
Snowflake (credential stuffing / no MFA)
OAuth Abuse
TTPs Matrix:
Unsecured Credentials: Private Keys
Use Alternate Authentication Material: Application Access Token
Data from Information Repositories
Exfiltration Over Web Service
Data Encrypted for Impact
Phishing for Information: Spearphishing Attachment
Phishing: Spearphishing Voice (Vishing)
ShinyHunters Leaks Site: Hidden Content