<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Shinyhunters on CuraSec</title><link>https://curasec.metacog.co.kr/tags/shinyhunters/</link><description>Recent content in Shinyhunters on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 29 Aug 2026 15:36:18 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/shinyhunters/index.xml" rel="self" type="application/rss+xml"/><item><title>McKesson discloses breach; ShinyHunters claims 284M patient records</title><link>https://curasec.metacog.co.kr/insights/2026-08-29-mckesson-discloses-breach-after-shinyhunters-claims-patient/</link><pubDate>Sat, 29 Aug 2026 15:36:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-29-mckesson-discloses-breach-after-shinyhunters-claims-patient/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Breach was via unauthorized access to third-party applications, not a patchable CVE; reinforces the need to audit and restrict third-party SaaS access, but no concrete engineering action is available from this disclosure alone.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters attribution is a useful actor profile update, but no IOCs, TTPs, or detection-relevant technical detail are published yet; monitor for follow-on disclosures that include actionable indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> McKesson is a major healthcare and pharma supply chain vendor — if your organization has a relationship with them, confirm exposure scope this week and request their incident attestation; 284 million claimed patient records puts this in HIPAA notification and board-visibility territory.&lt;/li>
&lt;/ul></description></item><item><title>ShinyHunters publishes Carhartt data on 12.9M accounts</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-carhartt-data-breach-exposes-information-of-12-9-million-acc/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-carhartt-data-breach-exposes-information-of-12-9-million-acc/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters continues active extortion operations; no IOCs or TTPs published from this incident to act on, but useful for tracking the group&amp;rsquo;s targeting patterns.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If Carhartt is a vendor or employee-benefits partner, request their incident report and confirm scope of data shared; separately, brief leadership given the scale (12.9M accounts) in case customers or press ask.&lt;/li>
&lt;/ul></description></item><item><title>ReliaQuest confirms failed ShinyHunters social-engineering attack</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-reliaquest-confirms-failed-data-theft-attack-after-shinyhunt/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-reliaquest-confirms-failed-data-theft-attack-after-shinyhunt/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> ShinyHunters used internal-impersonation social engineering to target a security vendor employee; no software vulnerability involved, but worth reviewing your own internal verification procedures for sensitive access requests from apparent colleagues.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Confirms ShinyHunters is actively targeting security vendor employees via insider-impersonation lures; no IOCs or ATT&amp;amp;CK-mappable TTPs are published here, so no immediate detection work is actionable.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If ReliaQuest is in your vendor stack, formally confirm with them that no client data was at risk during this incident and request a written attestation; the failed outcome reduces urgency but does not eliminate the vendor-risk checkbox.&lt;/li>
&lt;/ul></description></item><item><title>ShinyHunters breach data weaponized in $2,000 sextortion campaign</title><link>https://curasec.metacog.co.kr/insights/2026-07-26-shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/</link><pubDate>Sun, 26 Jul 2026 12:14:17 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-26-shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters-leaked emails are now being used as lures in sextortion campaigns; no novel TTPs or IOCs are provided, but awareness helps triage any related user-reported phishing tickets.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> If your organization&amp;rsquo;s user emails were exposed in ShinyHunters breaches, employees may receive these extortion emails; brief HR and helpdesk on the campaign so they can field employee reports without escalating to a formal incident.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Maps Three Salesforce OAuth Attack Paths Used by ShinyHunters</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-maps-three-salesforce-attack-paths-tied-to-a-year/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-maps-three-salesforce-attack-paths-tied-to-a-year/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> No platform CVE to patch — the attack surface is over-trusted OAuth connections and third-party integrations. Audit all connected apps in your Salesforce org, revoke unused OAuth grants, and review third-party vendor permissions this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft has detailed three concrete attack paths from an active, year-long campaign — hunt for anomalous OAuth authorization events and unusual connected-app activity in Salesforce audit logs going back at least 12 months to check for prior compromise.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> ShinyHunters is an active data-extortion group and this campaign abuses third-party SaaS trust, not software flaws — confirm your organization&amp;rsquo;s Salesforce OAuth integrations are inventoried, brief leadership on third-party SaaS risk exposure, and ask your Salesforce-connected vendors for attestation of their OAuth hygiene.&lt;/li>
&lt;/ul></description></item></channel></rss>