Companies

ShinyHunters

Follow the latest coverage, related explainers and connected technology stories.

Latest coverage

CN
FBI Urges ShinyHunters Members to Turn Themselves In After Suspect Arrested in the Netherlands

FBI Urges ShinyHunters Members to Turn Themselves In After Suspect Arrested in the Netherlands

The FBI urged members of the ShinyHunters group to turn themselves in after the arrest of a 24-year-old Dutch man suspected of holding a leadership role within the group. The bureau says the group and its partners breached more than 140 organizations and obtained at least $70 million in extortion payments.

CN
ShinyHunters Bypasses Firewalls to Exploit Oracle PeopleSoft Vulnerability

ShinyHunters Bypasses Firewalls to Exploit Oracle PeopleSoft Vulnerability

The ShinyHunters group used special URL encoding to bypass web application firewall rules blocking the path affected by the Oracle PeopleSoft CVE-2026-35273 vulnerability. Mandiant warns that the temporary protection is no substitute for installing the security update and examining logs for indicators of exploitation.

CN
Exploiting a Grav CMS Vulnerability Takes Down Clop’s Leak Site

Exploiting a Grav CMS Vulnerability Takes Down Clop’s Leak Site

The ShinyHunters group exploited a previously undocumented vulnerability in Grav CMS to breach and deface Clop’s leak site, prompting the group to move its site to a new Tor address. Grav confirmed that the flaw exists in the core and released version 1.7.53.4 to address it in the Grav 1.7 branch.

CN
ShinyHunters Claims to Have Breached FBI Systems Through a PeopleSoft Zero-Day Vulnerability

ShinyHunters Claims to Have Breached FBI Systems Through a PeopleSoft Zero-Day Vulnerability

The ShinyHunters group claims it exploited a previously unknown vulnerability in Oracle PeopleSoft to access systems belonging to the Federal Bureau of Investigation and steal data belonging to employees and job applicants. The FBI has not confirmed the breach or data theft and said it is investigating claims related to FBIjobs.gov.

CN
ShinyHunters Hacks Clop Leak Site and Threatens to Extort the Group

ShinyHunters Hacks Clop Leak Site and Threatens to Extort the Group

BleepingComputer confirmed that ShinyHunters hacked a leak site operated by the Clop gang after exploiting a vulnerability allegedly allowing unauthenticated file uploads. ShinyHunters says it stole the site’s server data and Tor service keys, but these claims have not been independently verified.