ShinyHunters was able to breach FBI data by hacking into an Oracle PeopleSoft server used to manage human resources and recruitment, TechCrunch reported. The group said it stole terabytes of information from an Amazon-hosted government cloud, where FBI data on agents and applicants are stored. ShinyHunters has said there is no financial motive behind the attack, demanding the FBI to take down a report which the group said includes inaccurate allegations against it.
What is ShinyHunters?
According to the FBI, ShinyHunters is a cybercriminal group “specializing in large-scale data breaches and extortion.” The group is known for attacking major companies across domains including technology, finance, and retail, often stealing millions of records in one go.
When did ShinyHunters originate?
ShinyHunters first came into the limelight in 2020 and claims to have successfully attacked dozens of victims so far. The group is mainly after money, but has also been causing reputational damage to its victims. Researchers believe the group may have originated either in 2019 or 2020.
Who have been victims of ShinyHunters?
In the past, ShinyHunters has targeted companies through vulnerabilities within cloud applications and website databases. By targeting customer management providers such as Salesforce, cybercriminal groups such as ShinyHunters can gain access to rich data sets from several clients in a single attack. Some of the biggest companies that have been affected in attacks by ShinyHunters are Ticketmaster, Wattpad, Tokopedia, BigBasket, and AT&T.
Who are members of ShinyHunters?
According to a report by The Conversation, there might be a significant overlap of membership between ShinyHunters and other cybercriminal groups such as Scattered Spider and Lapsus$. All these groups are international, and their members operate on the dark web from various parts of the world. Experts believe that ShinyHunters operates as a loose network of cybercriminals rather than a tightly-organised gang.
Click Here For The Original Source.
