Between September 19 and 21, the ShinyHunters extortion group infiltrated the Clop ransomware operation's data leak site, defacing it and allegedly stealing server data, source code, and Tor private keys. The defacement was confirmed; the broader theft claims remain unverified.
Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign - SecurityWeek https://www.
Threat actor group ShinyHunters claimed responsibility for a Federal Bureau of Investigation breach on 22 September 2026 and stated the attack was not financially motivated. The group demanded a retraction of the threat report by 24 September.
The hacker group ShinyHunters claimed a breach of cybersecurity firm ReliaQuest after using social engineering to compromise an employee's Okta dashboard session. ReliaQuest confirmed the incident was contained, stating that no internal systems or customer data were accessed during the brief security event.
Incoherent collection of separate ransomware incidents from seven distinct groups (incransom, nova, securotrop, dragonforce, akira, pear, chaos) each announcing different victims in healthcare and construction sectors. No single coordinated incident or story.
Multiple unrelated cybersecurity threats were reported this week including malware campaigns impersonating Windows apps, hidden iOS tracking data streams, Iranian state-sponsored industrial system interference, and an API vulnerability in the Vatican's mobile app. Additional coverage addressed AI security concerns and emerging shadow AI agent threats.
This cluster aggregates distinct security incidents including ChatGPT agent deployment flaws, critical vBulletin PHP execution vulnerabilities, Coca-Cola ransomware data theft, GitHub malware removal, and Dysphoria IoT botnet blockchain command infrastructure. These represent separate news items rather than coverage of a single story.
The ShinyHunters extortion gang claimed on September 8–10, 2026 to have breached an online platform tied to Florida's Driver and Vehicle Information Database (DAVID) and stolen more than 200,000 driver records, according to reports from cybersecurity outlets.
The ShinyHunters extortion gang exploited a URL-encoding technique to bypass web application firewall protections against CVE-2026-35273 in Oracle PeopleSoft, resuming attacks as of September 28, 2026. Security experts urged organizations to apply available patches.
Healthcare and pharmaceutical distribution giant McKesson on 2026-08-28 disclosed a cybersecurity incident involving unauthorized access and data theft, with the ShinyHunters extortion group claiming on 2026-08-30 to have exfiltrated 284 million healthcare records via vishing attacks on third-party applications. The breach represented one of the largest healthcare data exposures.
Cyber extortion war: ShinyHunters holds rival Cl0p to ransom https://www.
Between 22 and 25 September, cybercriminal group ShinyHunters claimed it exploited a zero-day vulnerability in Oracle PeopleSoft software to breach FBI recruitment systems (FBIJobs.gov), stealing 2–3 terabytes of sensitive employee data and information on job applicants and relatives. The FBI confirmed investigation on 23 September.
This cluster aggregates unrelated security news: DCSync attacks, Operation STANDOFF malware, a Houston City College breach of 831,642 records, FFmpeg vulnerabilities, and PortSwigger's Burp AI tool announcement. No single narrative unifies these disparate incidents.
A Dutch man known for his high-profile transformation from cybercriminal to reformed security professional was arrested on 2026-09-28 as part of the ShinyHunters hacking investigation. His 2023 convictions for data theft and extortion and subsequent disavowal of cybercrime had received international media attention.
On 22 September 2026, the ShinyHunters hacking group claimed responsibility for breaching Federal Bureau of Investigation systems. The FBI did not immediately respond to requests for comment on the alleged intrusion.
Hacking group ShinyHunters compromised and defaced the data leak site of the Clop ransomware gang on September 25 via an unpatched Grav CMS path traversal vulnerability. Clop relocated to a new Tor address after confirming the breach.
The hacking group ShinyHunters exploited CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, using URL-encoding tricks to bypass web application firewalls. By 2026-09-28, ShinyHunters claimed responsibility for breaching the FBI.
Dutch authorities arrested a 24-year-old Amsterdam man on 2026-09-28 as part of an investigation into the ShinyHunters hacking group. The suspect was detained earlier in September and has been confirmed by police to be connected to the cybercriminal organization.
The UCI Road World Championships took place in Montreal, Canada, with races occurring on September 26–27, 2026. The elite men's road race was contested on September 27.
The ShinyHunters extortion gang claimed responsibility for Ernst & Young's data breach, stating they obtained credentials through a supply-chain attack via a compromised third party. Attackers gained access to EY's Jira, GitHub, and Azure environments.
A wave of critical security vulnerabilities were disclosed and patched in July 2026: Node.js fixed 11 flaws (server crashes, filesystem bypass), GitLab 13 flaws (data leaks, pipeline tampering), Home Assistant FFmpeg plugin (file theft, root execution), and Cisco Secure Firewall (0-day actively exploited). A Brinks Home data breach was also claimed by ShinyHunters group.
Threat actors are using email addresses from data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The scam campaign targets victims whose information was previously exposed in security breaches.
Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.
Six unrelated social media posts link to Dutch news teletekst pages covering an arrest (ShinyHunters suspect), deaths off Puerto Rico, Spanish property ruling, RAF base suspects released, station evacuations, and highway closure. The posts contain only headlines and links, no substantive reporting.