CARDS
CARDS
ShinyHunters is a financially motivated cybercrime and extortion group that emerged in 2019, gaining public notoriety in May 2020 through selling stolen user records on dark web forums. The group operates under a "pay or leak" model, exfiltrating vast amounts of data and threatening to publish or sell it if ransom demands are not met. While having no single confirmed country of origin, ShinyHunters is believed to be a decentralized and internationally distributed collective, with law enforcement actions suggesting European ties through arrested affiliates. The group distinguishes itself by its strategic focus on cloud and software-as-a-service (SaaS) environments, leveraging sophisticated social engineering tactics, particularly voice phishing (vishing), and the abuse of OAuth tokens to bypass traditional authentication methods. ShinyHunters is known for high-volume data breaches, often targeting a single vendor or integration to compromise numerous downstream customers, as seen in their campaigns against Salesforce and Snowflake customers. The group is closely associated with "The Com" cybercrime network and has overlapping membership or collaboration with other groups like Scattered Spider and Lapsus$ under the "Scattered Lapsus$ Hunters" banner, and has also been tracked under aliases such as UNC6040, UNC6240, UNC6661, UNC6671, ShinyCorp, and Sp1d3rhunters.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Targeting
Campaign Context
No source-backed campaign or named operation association is currently retained for this actor card. Related campaign rows will appear here when SOCRadar, MITRE ATT&CK Campaigns, Microsoft, Google/Mandiant, CrowdStrike, CISA, or another retained public source ties the actor to a named campaign or operation.
Indicators
SOCRadar reports 969 IOCs for this profile. IntelliOS currently retains 100 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 5 source groups tracked; 4 currently contribute retained observable or context rows.
Retained Observables
Showing 60 of 100
| Type | Value | Source |
|---|---|---|
| Tool / Process | Malicious Salesforce connected app3 | MITRE |
| Tool / Process | OAuth token abuse3 | MITRE |
| Tool / Process | Python automation3 | MITRE |
| Tool / Process | Salesforce API bulk queries3 | MITRE |
| Tool / Process | Salesforce Data Loader abuse3 | MITRE |
| Tool / Process | Voice phishing3 | MITRE |
| Network Indicator | 91.199.42.164/login5 | FBI FLASH-20250912-001 |
| Network Indicator | http://64.95.11[.]112/hello.php5 | FBI FLASH-20250912-001 |
| Network Indicator | https://login[.]salesforce[.]com/setup/connect5 | FBI FLASH-20250912-001 |
| Network Indicator | Login.salesforce.com/setup/connect?user_code=8KCQGTVU5 | FBI FLASH-20250912-001 |
| Network Indicator | Login[.]salesforce[.]com/setup/connect?user_code=aKYF7V5N5 | FBI FLASH-20250912-001 |
| Network Indicator | 104.193.135.2215 | FBI FLASH-20250912-001 |
| Network Indicator | 104.223.118.625 | FBI FLASH-20250912-001 |
| Network Indicator | 141.98.252.1895 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.165.475 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.168.2395 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.173.605 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.185.475 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.189.1115 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.189.475 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.198.1125 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.211.1195 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.211.1835 | FBI FLASH-20250912-001 |
| Network Indicator | 146.70.211.555 | FBI FLASH-20250912-001 |
| Network Indicator | 147.161.173.905 | FBI FLASH-20250912-001 |
| Network Indicator | 149.22.81.2015 | FBI FLASH-20250912-001 |
| Network Indicator | 151.242.41.1825 | FBI FLASH-20250912-001 |
| Network Indicator | 151.242.58.765 | FBI FLASH-20250912-001 |
| Network Indicator | 163.5.149.1525 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1365 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1385 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1515 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1665 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1685 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1815 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1845 | FBI FLASH-20250912-001 |
| Network Indicator | 185.141.119.1855 | FBI FLASH-20250912-001 |
| Network Indicator | 185.209.199.565 | FBI FLASH-20250912-001 |
| Network Indicator | 191.96.207.2015 | FBI FLASH-20250912-001 |
| Network Indicator | 195.54.130.1005 | FBI FLASH-20250912-001 |
| Network Indicator | 196.251.83.1625 | FBI FLASH-20250912-001 |
| Network Indicator | 198.244.224.2005 | FBI FLASH-20250912-001 |
| Network Indicator | 198.44.129.565 | FBI FLASH-20250912-001 |
| Network Indicator | 198.44.129.885 | FBI FLASH-20250912-001 |
| Network Indicator | 198.54.130.1005 | FBI FLASH-20250912-001 |
| Network Indicator | 198.54.130.1085 | FBI FLASH-20250912-001 |
| Network Indicator | 198.54.133.1235 | FBI FLASH-20250912-001 |
| Network Indicator | 205.234.181.145 | FBI FLASH-20250912-001 |
| Network Indicator | 206.217.206.1045 | FBI FLASH-20250912-001 |
| Network Indicator | 206.217.206.1245 | FBI FLASH-20250912-001 |
| Network Indicator | 206.217.206.145 | FBI FLASH-20250912-001 |
| Network Indicator | 206.217.206.255 | FBI FLASH-20250912-001 |
| Network Indicator | 206.217.206.265 | FBI FLASH-20250912-001 |
| Network Indicator | 206.217.206.645 | FBI FLASH-20250912-001 |
| Network Indicator | 206.217.206.845 | FBI FLASH-20250912-001 |
| Network Indicator | 208.131.130.535 | FBI FLASH-20250912-001 |
| Network Indicator | 208.131.130.715 | FBI FLASH-20250912-001 |
| Network Indicator | 208.131.130.915 | FBI FLASH-20250912-001 |
| Network Indicator | 23.162.8.665 | FBI FLASH-20250912-001 |
| Network Indicator | 23.234.69.1675 | FBI FLASH-20250912-001 |
| Network Indicator | 23.94.126.635 | FBI FLASH-20250912-001 |
| Network Indicator | 31.58.169.855 | FBI FLASH-20250912-001 |
| Network Indicator | 31.58.169.925 | FBI FLASH-20250912-001 |
| Network Indicator | 31.58.169.965 | FBI FLASH-20250912-001 |
| Network Indicator | 34.86.51.1285 | FBI FLASH-20250912-001 |
| Network Indicator | 35.186.181.15 | FBI FLASH-20250912-001 |
| Network Indicator | 37.19.200.1325 | FBI FLASH-20250912-001 |
| Network Indicator | 37.19.200.1415 | FBI FLASH-20250912-001 |
| Network Indicator | 37.19.200.1545 | FBI FLASH-20250912-001 |
| Network Indicator | 37.19.200.1675 | FBI FLASH-20250912-001 |
| Network Indicator | 37.19.221.1795 | FBI FLASH-20250912-001 |
| Network Indicator | 38.22.104.2265 | FBI FLASH-20250912-001 |
| Network Indicator | 45.83.220.2065 | FBI FLASH-20250912-001 |
| Network Indicator | 51.89.240.105 | FBI FLASH-20250912-001 |
| Network Indicator | 64.94.84.785 | FBI FLASH-20250912-001 |
| Network Indicator | 64.95.11.2255 | FBI FLASH-20250912-001 |
| Network Indicator | 64.95.84.1595 | FBI FLASH-20250912-001 |
| Network Indicator | 66.63.167.1225 | FBI FLASH-20250912-001 |
| Network Indicator | 67.217.228.2165 | FBI FLASH-20250912-001 |
| Network Indicator | 68.235.43.2025 | FBI FLASH-20250912-001 |
| Network Indicator | 68.235.46.1515 | FBI FLASH-20250912-001 |
| Network Indicator | 68.235.46.2025 | FBI FLASH-20250912-001 |
| Network Indicator | 68.235.46.2085 | FBI FLASH-20250912-001 |
| Network Indicator | 68.235.46.225 | FBI FLASH-20250912-001 |
| Network Indicator | 68.63.167.1225 | FBI FLASH-20250912-001 |
| Network Indicator | 69.246.124.2045 | FBI FLASH-20250912-001 |
| Network Indicator | 72.5.42.725 | FBI FLASH-20250912-001 |
| Network Indicator | 79.127.217.445 | FBI FLASH-20250912-001 |
| Network Indicator | 83.147.52.415 | FBI FLASH-20250912-001 |
| Network Indicator | 87.120.112.1345 | FBI FLASH-20250912-001 |
| Network Indicator | 94.156.167.2375 | FBI FLASH-20250912-001 |
| Network Indicator | 96.44.189.1095 | FBI FLASH-20250912-001 |
| Network Indicator | 96.44.191.1415 | FBI FLASH-20250912-001 |
| Network Indicator | 96.44.191.1575 | FBI FLASH-20250912-001 |
| Email Address | shinycorp@tuta[.]com3 | MITRE |
| Email Address | shinygroup@tuta[.]com3 | MITRE |
| Campaign Context | FBI FLASH-20250912-001 released TLP:CLEAR UNC6040 IOCs for Salesforce data theft and extortion; UNC6395 indicators are treated as a separate campaign boundary, not merged into this ShinyHunters/UNC6040 card.5 | FBI FLASH-20250912-001 |
| Campaign Context | Google GTIG tracks UNC6040 as a financially motivated cluster using vishing to induce Salesforce connected-app authorization and large-scale data theft; Google separately noted ShinyHunters-branded extortion claims.4 | Mandiant |
| Campaign Context | MITRE tracks Salesforce Data Exfiltration as campaign C0059: UNC6040 voice phishing compromised Salesforce instances, while UNC6240 later claimed ShinyHunters-branded extortion in some cases.3 | MITRE |
| Campaign Context | Varonis describes the Salesforce vishing pattern as social engineering plus OAuth/connected-app abuse rather than a Salesforce platform vulnerability.6 | Varonis |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 969 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| MITRE ATT&CK3 | N/A | 9 | Public observables or source-context rows retained and displayed. |
| Google Threat Intelligence4 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| FBI IC35 | N/A | 89 | Public observables or source-context rows retained and displayed. |
| Varonis6 | N/A | 1 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Shinyhunters | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Shinyhunters | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/shinyhunters | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | MITRE ATT&CK https://attack.mitre.org/campaigns/C0059/ | Canonical ATT&CK group, campaign, software, aliases, and technique mapping source where matched. |
| 4 | Google GTIG: Voice Phishing Data Extortion Campaigns https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion | Vendor Research |
| 5 | FBI FLASH-20250912-001: UNC6040 and UNC6395 Salesforce Data Theft https://www.ic3.gov/CSA/2025/250912.pdf | Government Advisory |
| 6 | Varonis: Salesforce Organizations Need to Know About ShinyHunters and Vishing https://www.varonis.com/blog/salesforce-vishing-threat-unc604 | Defensive Guidance |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Shinyhunters, then compares naming and aliases against SOCRadar Actor Alias Index where collision checks exist.
The retained collision rows point to possible boundary questions involving shinyhunters / ShinySp1d3r; shinyhunters / UNC6040 based on shared evidence such as Scattered Lapsus$ Hunters (SLH); UNC6040. These notes preserve reader context; IntelliOS does not automatically merge actor records.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| SOCRadar Actor Alias Index possible same actor | shinyhunters / ShinySp1d3r | Scattered Lapsus$ Hunters (SLH) | Retain as a source-boundary note; do not merge automatically. |
| SOCRadar Actor Alias Index possible same actor | shinyhunters / UNC6040 | UNC6040 | Retain as a source-boundary note; do not merge automatically. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |