Dalton Hunter
Threat Actor Profile
Dalton Hunter
August 2026
Threat Actor Profile: SaaS Data-Theft & Extortion Collective

ShinyHunters

aka ShinyCorp · UNC6040/UNC6240 · allied as "Scattered Lapsus$ Hunters"

A financially motivated data-theft and extortion collective, active since 2020, now running the largest OAuth and vishing campaign against Salesforce environments on record.

Threat Level: Critical
2020
First observed
400+
Orgs breached, all-time
1,000+
Orgs hit, 2025–26 Salesforce campaign
Oct '25
FBI seizes BreachForums
4
France arrests, Jun 2025
Section 01

Actor Profile

Origin & structure

ShinyHunters surfaced in May 2020 with a two-week breach spree, hitting Tokopedia, Microsoft's GitHub repos, and Wattpad first. It's led by a persona known as ShinyCorp, took over BreachForums after its founder's 2023 arrest, and kept operating after the FBI seized the forum in October 2025.

Targeting philosophy

Early breaches (2020–21) were opportunistic database theft; by 2024 the group had pivoted to supply-chain access brokering (Snowflake/EPAM), and since mid-2025 to Salesforce specifically. One vendor-integration compromise (Drift, Gainsight, Anodot) now routinely nets hundreds of downstream victims in a single move.

Extortion model

Pay-or-leak: a private ransom demand first, then public auction, leak-site posting, DDoS, and harassment if refused. Reporting also points to an emerging ransomware-as-a-service-style structure.

Section 02

Timeline of Activity

May 2020

Public debut

Breach spree hits Tokopedia, Microsoft's GitHub repos, and Wattpad within two weeks.

2022 / 2024

Raoult arrest & sentencing

French national Sébastien Raoult is arrested, then sentenced in 2024, the group's biggest legal setback.

2024

Snowflake supply-chain campaign

A compromised EPAM endpoint cascades into ~160 orgs, including AT&T, Ticketmaster, and Santander.

Jun 2025

Salesforce vishing begins; French arrests

Google tracks the campaign as UNC6040/UNC6240; four suspects are arrested in France.

Aug–Sep 2025

Drift token theft & JLR breach

Stolen Drift tokens expose ~760 orgs; Jaguar Land Rover's shutdown is jointly claimed with Scattered Spider.

Oct–Nov 2025

BreachForums seized; Gainsight abuse

The FBI seizes BreachForums; stolen Gainsight tokens expose 200+ more Salesforce instances.

Dec 2025

Coinbase extortion attempt

An insider-enabled breach leads to a $20M ransom demand, which Coinbase refuses.

Mar–Apr 2026

Experience Cloud campaign & Anodot breach

Automated scanning drives mass extortion; an Anodot breach reaches Rockstar Games and Zara.

Jun–Jul 2026

Klue breach & campaign mapped

A forgotten Klue credential exposes more victims; Microsoft formally maps the year-long campaign.

Section 03

Kill Chain & MITRE ATT&CK Mapping

ShinyHunters' kill chain barely touches malware. The group operates almost entirely inside legitimate SaaS trust relationships, which makes this a harder chain to signature and a more useful one to map behaviorally.

01

Initial Access

Spearphishing Voice

Operators vishing-call employees into authorizing a fraudulent OAuth app spoofing Salesforce's "Data Loader" tool.

Trusted Relationship

Compromises a shared SaaS integration vendor (Drift, Gainsight, Anodot) to inherit access to all its downstream customers.

02

Execution & Persistence

Application Access Token Abuse

Stolen OAuth refresh tokens are reused directly against Salesforce, BigQuery, and Snowflake APIs.

Modify Authentication Process

Operators delete MFA-enrollment alerts in some Okta-linked environments to hide new device registration.

03

Discovery & Defense Evasion

Active Scanning

Automated tooling ("AuraInspector") scans for misconfigured, publicly exposed Salesforce portals at scale.

Valid Cloud Accounts

Legitimate OAuth grants and API tokens let activity blend into normal SaaS traffic by default.

04

Collection & Exfiltration

Data from Information Repositories

Bulk API pulls against Salesforce, SharePoint, and connected data stores extract records straight through sanctioned interfaces, with no separate exfil channel needed.

05

Impact

Financial Theft / Extortion

Standard pay-or-leak pressure: ransom demand, deadline threats, DDoS, and leak-site publication if refused.

Tooling & named artifacts

Fraudulent "Data Loader" OAuth app AuraInspector scanner Stolen Drift / Gainsight / Anodot tokens Device code phishing Telegram ("Sim Land") BreachForums (legacy)
Section 04

Indicators of Compromise

Almost no malware artifacts to hash, since the intrusion path is a phone call and an OAuth consent screen. What follows are the durable, publicly reported patterns instead.

Reported patterns & behavior

Indicator / BehaviorTypeNotes
"Data Loader" (fraudulent)OAuth app nameSpoofs Salesforce's own tool; requests broad, full-access scopes
Typosquat Salesforce domainsDomain patternNaming conventions flagged by ReliaQuest across 2025 phishing infra
New OAuth grant, broad scopeBehaviorEspecially soon after a help-desk interaction
Anomalous Bulk API volumeBehaviorAtypical data pulls outside normal integration patterns
MFA-enrollment suppressionBehaviorMissing new-device alerts in Okta-linked environments
Section 05

Detection & Mitigation Priorities

Ordered by impact-to-effort ratio for a mid-sized enterprise.

  • P1Require admin approval for new OAuth grants in Salesforce and verify any "Data Loader" integration is genuine.
  • P1Harden help-desk identity verification against vishing.
  • P1Enable Salesforce Shield / Real-Time Event Monitoring for anomalous Bulk API activity.
  • P2Inventory and rotate tokens for every third-party SaaS integration; deprovision disused ones.
  • P2Alert on suppressed MFA-enrollment notifications, especially in Okta-linked environments.
  • P3Prepare an extortion response playbook in advance, including legal, comms, and law enforcement contacts.
Section 06

References