ShinyHunters: The Cyber Crime Group Behind Google's Recent Security Alert

2 Sources

Share

ShinyHunters, a notorious cyber crime group, has gained global attention after a data breach via Salesforce prompted Google to urge 2.5 billion users to enhance their security measures. This article explores the group's tactics, recent activities, and ways to protect against their attacks.

ShinyHunters: A Rising Threat in Cybercrime

The cybersecurity world has been rattled by the recent activities of ShinyHunters, a notorious cyber crime group that has gained global attention. Google's urgent advisory to 2.5 billion users to strengthen their security measures came in the wake of a data breach via Salesforce, a customer management platform, orchestrated by this group

1

2

.

Evolution of ShinyHunters

ShinyHunters emerged in 2020 and has since claimed successful attacks on 91 victims. Initially targeting companies through vulnerabilities in cloud applications and website databases, the group has recently shifted its tactics to include voice-based social engineering, also known as "vishing"

1

2

.

This change in approach has been linked to their collaborations with other threat actors such as Scattered Spider and Lapsus$. In a bold move, ShinyHunters announced on Telegram their joint efforts to target companies like Salesforce and Allianz Life, though the channel was quickly taken down

1

2

.

Vishing: The New Frontier of Social Engineering

Unlike traditional data breaches, vishing involves criminals posing as IT helpdesk members to manipulate employees into sharing sensitive information. The use of deepfakes and generative AI to clone voices has made these attacks increasingly sophisticated and hard to detect

1

2

.

High-Profile Targets and Tactics

ShinyHunters' list of victims includes major corporations such as Qantas, Pandora, Adidas, Chanel, Tiffany & Co., and Cisco. In 2021, they claimed to be selling data stolen from 73 million AT&T customers

1

2

.

Source: Tech Xplore

Source: Tech Xplore

The group's strategy of targeting customer management providers like Salesforce allows them to access rich data sets from multiple clients in a single attack. Recently, they publicly released Allianz Life's Salesforce data, comprising 2.8 million customer and corporate partner records

1

2

.

The Cyber Crime Ecosystem

There's likely significant overlap between ShinyHunters, Scattered Spider, and Lapsus$. These international groups operate on the dark web and are known by multiple aliases, adding to the complexity of tracking their activities

1

2

.

The newly rebranded Scattered Lapsus$ Hunters have started offering ransomware as a service, claiming superiority over other cyber crime groups like LockBit and Dragonforce

1

2

.

Protecting Against Vishing Attacks

While individual users have limited options against organized cyber crime, vigilance is key. For organizations, proactive measures include:

  1. Implementing scenario-based training for employees

    1

    2

  2. Using additional verification methods like on-camera ID checks

    1

    2

  3. Strengthening security with phishing-resistant multi-factor authentication, such as number matching or geo-verification

    1

    2

As cyber threats evolve, the importance of robust security measures and ongoing education cannot be overstated. The rise of groups like ShinyHunters underscores the need for constant vigilance in our increasingly digital world.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo