FBI vs ShinyHunters: A Cat-and-Mouse Game Over Stolen Data
ShinyHunters has been selling and leaking stolen data for years while law enforcement keeps chasing it. Here is how the story has gone and what it means for everyday defenders.
On this page · 6 sections
Who is ShinyHunters?
ShinyHunters is a name tied to a long-running data-theft and extortion scene. Since about 2020, accounts using this name have sold or leaked stolen databases from many companies on underground forums. The name has also been used as a brand by losing groups over time, so "ShinyHunters" does not always refer to the same people.
A short timeline
- 2020–2021: The name appears on forums selling large databases from many online services.
- 2022–2024: A French national, Sébastien Raoult, was arrested in Morocco, extradited to the US, pleaded guilty, and was sentenced in 2024 to a prison term and restitution.
- 2025: French authorities reported arrests of several people linked to BreachForums and ShinyHunters-related aliases.
- 2025: Campaigns targeting cloud and CRM customers (notably Salesforce-connected data) were linked by researchers to a collective sometimes called "Scattered LAPSUS$ Hunters." The FBI was reported to have seized a related leak-site domain.
Why don't arrests end the story?
- The brand outlives the people. Names are cheap to reuse, and forums come back under new domains.
- The crews are loose. Teenagers, brokers, and more experienced intruders often work together across borders, which slows cases.
- Leaks keep circulating. Once data is posted, an arrest cannot take it back.
What this means for defenders
Most of these breaches do not need clever exploits. They tend to rely on:
- Social engineering, such as phishing and phone calls to help desks.
- Stolen credentials and tokens that were never rotated.
- Over-permissive third-party apps connected to cloud platforms.
Practical steps:
- Use phishing-resistant MFA (passkeys or security keys) for staff and admins.
- Review which third-party apps and API tokens can reach your CRM and cloud data, and remove what you don't need.
- Train help desks to verify identity before resetting access.
- Log and alert on unusual bulk data exports.
- Plan for a breach: know who you call and what you tell customers.
Takeaway
Law enforcement pressure raises the cost for these groups, but it does not remove the risk. Treat any single arrest as good news, not as a reason to relax your defenses.
Enjoyed this? Get the next post by email
One email when something new is up. No spam, and you can unsubscribe anytime.

Comments
No comments yet. Start the conversation.