Shiny Hunters list 73.2 million user records on the dark web

Group reportedly has ties to hacking group Gnosticplayers

Cyber criminal in a hoodie holding a laptop

Members of the Shiny Hunters hacking group have allegedly compromised 73.2 million user records from over 11 companies worldwide.

These hackers appear to be a part of the same group behind the recent Tokopedia data breach that exposed 91 million user records and listed them for sale at $5,000. 

Emboldened by the profits from the Tokopedia sale, the Shiny Hunters group is now listing the databases of 10 more companies for sale on the dark web.

The 10 databases hold a total of 73.2 million user records. The hacking group has the databases listed for sale at a combined $18,000, though Shiny Hunters is willing to sell them separately for $500-$3,500 each.

The databases include:

  • Zoosk (30 million user records, priced at $500)
  • Chatbooks (15 million user records, priced at $3,500)
  • StyleShare (6 million user records, priced at $2,700)
  • Home Chef (8 million user records, priced at $2,500)
  • Minted (5 million user records, priced at $2,500)
  • Chronicle of Higher Education (3 million user records, priced at $1,500)
  • GGuMim (2 million user records, priced at $1,300)
  • Mindful (2 million user records, priced at $1,300)
  • Bhinneka (1.2 million user records, priced at $1,200)
  • StarTribune (1 million user records, priced at $1,100)

While the authenticity of some of the databases haven’t been verified, sources in the threat intel community believe Shiny Hunters is a legitimate threat actor. Many also believe the group may have ties to Gnosticplayers, which has sold more than 1 billion user credentials on dark web marketplaces and operated in a nearly identical pattern as Shiny Hunters.

Those impacted by Shiny Hunters’ exploits have begun to come forward. Chatbooks recently confirmed the breach on its website, sharing that no financial data was exposed during Shiny Hunters’ exploits, but the stolen information included login information, including names, email addresses and password information. 

There have been several reports of hackers selling stolen information on the dark web in the last few weeks. Security experts from Cyble recently found hackers selling upward of 267 million Facebook records for a paltry $623.

Cyble claims that these records contained information that would allow attackers to perform spear-phishing campaigns to steal user credentials.

Featured Resources

Unleashing the power of AI initiatives with the right infrastructure

What key infrastructure requirements are needed to implement AI effectively?

Download now

Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey

A Veritas webinar on implementing a hybrid multi-cloud strategy

Download now

A buyer’s guide for cloud-based phone solutions

Finding the right phone system for your modern business

Download now

The workers' experience report

How technology can spark motivation, enhance productivity and strengthen security

Download now

Recommended

Global ransom DDoS extortionists are retargeting companies
distributed denial of service (DDOS)

Global ransom DDoS extortionists are retargeting companies

22 Jan 2021
BEC scammers are using Google Forms to identify easy victims
phishing

BEC scammers are using Google Forms to identify easy victims

21 Jan 2021
FBI warns of ongoing corporate vishing attacks
phishing

FBI warns of ongoing corporate vishing attacks

19 Jan 2021
Hackers using COVID vaccine as a lure to spread malware
hacking

Hackers using COVID vaccine as a lure to spread malware

15 Jan 2021

Most Popular

WhatsApp could face €50 million GDPR fine
General Data Protection Regulation (GDPR)

WhatsApp could face €50 million GDPR fine

25 Jan 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
What is a 502 bad gateway and how do you fix it?
web hosting

What is a 502 bad gateway and how do you fix it?

12 Jan 2021