Threat group ShinyHunters continues its incessant campaign to torture companies trying to provide products and services to consumers, with no indication of letting up.

One of its latest victims, Medtronic, the manufacturer of medical devices, healthcare technologies, and therapies, confirmed that it was the victim of an April cyberattack where over nine million records from the company were stolen. ShinyHunters claimed responsibility. Medtronic recently notified affected customers, informing them that the data exposed during the attack included some customers’ names, contact information, dates of birth, Social Security numbers, and health-related information.

Although the data was compromised during the attack, Medtronic has confirmed that the attack did not impact its medical devices, and they remain safe to use.

Medtronic is offering affected customers 24 months of credit monitoring and identity theft protection services. If you receive a letter from Medtronic, it is important to follow the instructions provided.

While recent arrests and extraditions of individuals linked to Scattered Spider (another notoriously active threat actor group) are a positive development, I’m hopeful that similar law enforcement progress against ShinyHunters associates will follow soon.

Researchers from Mandiant and Google Threat Intelligence Group are warning the higher education sector, including universities, that ShinyHunters has exploited an Oracle PeopleSoft zero-day vulnerability and has “potentially infiltrated the networks of more than 100 organizations in an attack spree that largely impacted higher education.” ShinyHunters has reportedly started publishing the names of the compromised victims and stolen data.

The vulnerability (CVE-2026-35273) “allows unauthorized attackers to execute remote code and takeover affected servers.” Oracle has published mitigation steps, but a patch has not yet been released. According to Mandiant, “This campaign is still active.” Google adds that “most of the potential victim pool is based in the United States and 68% are in the higher education sector.” If you are in the higher education sector, implement Oracle’s mitigation steps  as soon as possible, and look out for a released patch.

Another recent victim of ShinyHunters is Instructure, the supplier of the Canvas learning management system, which disrupted the login portals of 330 colleges and universities during the critical college exam schedule.

According to Dataminr, ShinyHunters “claimed to have stolen 3.654TB of data affecting about 275 million individuals and 9,000 institutions worldwide.” The stolen data included names, email addresses, student ID numbers and messages, but not passwords, government IDs, birth dates, or financial data. The company admitted that the threat actors obtained access on April 29, 2026. After remediation and revoking the threat actors’ access, it identified additional unauthorized activity on May 7, 2026. The incident caused Instructure to take Canvas offline, affecting its 8,800 customers during exam season.

This is a repeated attack by ShinyHunters against Instructure. Not only did it maintain persistence in April and May, but ShinyHunters also attacked Instructure by  in September 2025, in a social engineering attack that provided the threat actors with access to its Salesforce instance.

Instructure confirmed on May 11, 2026, that it has “reached an agreement with the unauthorized actor involved in this incident” and had “received digital confirmation of data destruction (shred logs)” and that “no Instructure customers will be extorted as a result of this incident, publicly or otherwise.” The Cybersecurity & Infrastructure Security Agency issued an alert on the incident, and Congress started an inquiry. In addition, the Federal Trade Commission (FTC) warns consumers to be cautious about texts or emails pretending to be from Canvas “to trick you into giving them your information,” and providing tips about responding to any messages related to the Canvas hack. Importantly, the FTC advises to alert children to be cautious about texts and emails. It’s a good reminder to discuss with your children how threat actors launch social engineering campaigns using the data stolen from an incident such as this one.

According to HaveIBeenPwned, ShinyHunters targeted fashion brand Zara in a cyber-attack  and claimed that it had stolen 197,000 unique email addresses, product SKUs, order IDs, and the originating market. The incident involved a former technology provider (AI analytics platform Anodot) for Zara’s parent company, Inditex, which resulted in the exposure of the personal information. ShinyHunters claimed to have leaked 140GB of data, which is reported to have included compromised authentication tokens for Anodot users.

Inditex has confirmed that no customer names, passwords, phone numbers, addresses, or payment information (bank cards) were compromised in the incident. Inditex has also confirmed that its core operations and systems were not impacted.

ShinyHunters continues to wreak havoc in all industries, and its techniques of compromising authentication tokens is a warning to organizations to prioritize prevention of authentication token incidents. Obsidian has provided a basic summary of how token-based attacks work, and tips on how to prevent them.

Global medical device company Medtronic recently confirmed that it had been attacked by the threat actor group, ShinyHunters. According to Bleeping Computer, Medtronic is “the largest medical device maker in the world by revenue ($33.5 billion) and also develops healthcare technologies and therapies.”

ShinyHunters alleges that it has stolen over nine million Medtronic records containing personal information, and “terabytes of internal corporate data”.

Medtronic acknowledged the incident but confirmed that its customers, products, and operations have not been affected, and that “hospital customer networks remain separate from Medtronic IT networks and are secured and managed by customers’ IT teams.”

Medtronic is investigating the incident.

ShinyHunters continues to wreak havoc against well-known brands; most recently, Wynn Resorts. Wynn Resorts has confirmed that “an unauthorized third party acquired certain employee data.” It is believed that the threat actor was ShinyHunters. Fortunately for Wynn, the incident is not affecting its operations, and its resorts remain fully functional.

ShinyHunters announced it was the culprit on its leak site on February 20, 2026. It alleges that it stole more than 800,000 records, including Social Security numbers. Wynn was removed from the site four days later, and reported that “the unauthorized third party has stated that the stolen data has been deleted.”

Wynn has confirmed that it will be offering credit monitoring and identity protection services to affected employees.

Wynn is not alone in being a target of ShinyHunters. It is reported that over 100 organizations have been successfully attacked through vishing attacks and compromised single sign on credentials by ShinyHunters.

The techniques used by ShinyHunters and other threat actors using vishing campaigns are relevant and provide strong current scenarios to warn employees through education and training, and to use for cybersecurity tabletop exercises.

Security professionals rely on the implementation of multifactor authentication (MFA) to defend against phishing attacks and intrusions. Unfortunately, we can’t completely rely on MFA to protect us as threat actors (more specifically, ShinyHunters) are now targeting companies in technology, financial services, real estate, energy, healthcare, logistics, and retail with synchronized vishing-phishing attacks.

The newest attacks involve the threat actors pretending to be IT staff who called employees to tell them that the company was updating MFA settings. While on the phone with the employee, the threat actor directed them to a malicious credential harvesting site that spoofed the company to capture the employees’ single sign on credentials and MFA codes, then registered their device for the MFA push.

The threat actors cover their tracks and bypass security notices. Once they gain access to the company system, they download sensitive data and extort ransoms from companies and harass employees.

It is crucial that companies continue to educate employees on the newest cybersecurity threats and schemes so they can identify them and prevent themselves from becoming victims. The use of sophisticated vishing and phishing schemes like the one described above are unusual and many users don’t understand how combining vishing and phishing can be very powerful and successful. Incorporate these recent threats into your next cybersecurity training or company-wide cyber tip.

I apologize that this post is not light reading. It’s critically important to know what the threats are so you can avoid becoming a victim.

Although disconcerting, it is crucial to know what has happened in the first half of this year. TechCrunch recently issued a report outlining the worst breaches of 2026—so far:

  • DOGE’s massive swipe of Social Security data (I’ve discussed this  in numerous posts)
  • Hackers increased targeting of water systems and energy grids (discussed here)
  • Iranian government hackers attacking Stryker with a destructive device hack (ditto)
  • ShinyHunters’ disruptive hacking campaign against Instructure, among other targets (ShinyHunters has been a frequent subject of our posts)
  • The supply chain under attack, targeting open-source projects and big tech companies
  • FBI’s surveillance system breach, sparking a “major cyber incident“
  • Hasbro’s hack leading to weeks of downtime
  • Exposure of millions of passports and driver licenses

What can we learn from these trends?

According to TechCrunch, “the attacks are getting bolder, more destructive, and harder to contain.” The trends confirm that as technology advances, so must defenses equally. Cybersecurity measures must be sophisticated enough to block attackers so they will move on to the next victim. A mature cybersecurity posture, both personally and professionally, must be a priority to prevent becoming victimized. In a world of geopolitical discontent, cyber attackers serve as warriors for nation states, and at the same time, our own government is failing to protect our data and our warriors’ data. Unfortunately, the Cybersecurity and Infrastructure Security Agency’s funding has been decimated, so we are left to our own devices (pardon the pun).

We need to take greater responsibility for protecting our own information while demanding stronger safeguards from our government, especially for the sensitive data of current and veteran military personnel. Additionally, private companies must also do more to prevent exposure. Robust cybersecurity programs across individuals, government, and the private sector are essential. This is no longer a future concern; it is reality. Without collective action, the second half of 2026 will bring more of the same.

Sophisticated vishing (voice phishing) attacks continue to target and victimize company call centers and help desks. Recently, a large ad tech company reported that customer information had been compromised as a result of a vishing attack. The company warns that the information obtained in the incident can be used by threat actors to conduct phishing and vishing attacks against customers through the use of emails, texts or telephone numbers.

The attackers, believed to be ShinyHunters (again), use similar tactics in their attacks against companies in all industries. The threat actor, impersonating a company’s information technology employee, calls company employees, (often a help desk or call center), and tricks them into entering credentials and multifactor authentication (MFA) codes on phishing sites that mimic the company’s portal, or asks them to assist the “employee” with changing his or her credentials to access the company network. They also use device code vishing to bypass MFA defenses. Once they have access to the company network, and access to the data the impersonated employee had access to, they often escalate privileges and exfiltrate data to use against the company in an extortion campaign.

These attacks continue to escalate and call centers and help desks are central to thwarting them. Companies may wish to consider immediate additional training and education for in-house call center and help desk personnel, update processes for employees to change credentials through voice requests, implement more robust identification requirements (including using internal company information that only employees would have access to), and conducting tabletop exercises on how to respond to them.

A newly filed putative class action in the Western District of Texas targets Bumble, Inc., over an alleged “massive and preventable” cyberattack in or around January 2026, in which attackers allegedly accessed highly sensitive user data stored in Bumble’s systems. The complaint alleges the compromised information included names, dates of birth, addresses, telephone numbers, Social Security numbers, and account numbers, as well as highly sensitive, context-rich dating data such as chat history and dating history, the kind of data combination that can heighten identity-theft risk and privacy harms. The named plaintiff alleges time loss, anxiety, and increased risk of fraud and identity theft, and seeks damages and injunctive relief on behalf of the individuals whose information was stored and/or exposed in the breach. 

For companies watching this case, the “what went wrong” allegations read like a checklist of avoidable security and communications failures. The complaint claims Bumble promised “appropriate and reasonable security measures” (including secured servers and firewalls) in its public-facing privacy policy but allegedly did not adhere to those claims. The complaint further alleges the breach occurred through a phishing attack attributed to the “ShinyHunters” threat actor group, and argues that the fact of a successful phishing compromise suggests inadequate security controls pointing to measures like organization-wide two-factor authentication and adequate employee cybersecurity training as known safeguards. The complaint also alleges that Bumble failed to properly secure and encrypt data, failed to implement timely breach detection, and failed to provide prompt and accurate notice.

The takeaway is that privacy policy statements, phishing training failures, encryption decisions, breach detection, and notification practices can quickly become central allegations in a class action when a security incident occurs. Even at this stage, this lawsuit is a reminder that aligning written privacy and security commitments with day-to-day implementation, and documenting those efforts, can be just as important as the technical controls themselves when an incident triggers litigation.