Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Leaks » ShinyHunters Escalates Extortion Campaign, Starts Leaking Data From Major Companies

ShinyHunters Escalates Extortion Campaign, Starts Leaking Data From Major Companies

Last updated:September 4, 2026
Human Written
  • ShinyHunters began releasing data linked to four companies after a September 1 deadline passed without payment.

  • McKesson and Jack Henry both confirmed they suffered cyberattacks connected to the hacking group.

  • The exact amount of stolen data claimed by ShinyHunters has not been fully confirmed yet.

ShinyHunters Begins Leaking Data from Companies After Ransom Deadline

A hacking group called ShinyHunters has moved from making threats to actually leaking data. The group had given four companies a deadline to pay up or face exposure.

That deadline passed on September 1. Now, download links for stolen files have started to appear on the group’s leak site. This marks a shift from empty threats to real action, though not every claim the group makes has been proven true.

The Deadline Passes and Files Appear Online

ShinyHunters had named four companies on its leak site weeks earlier. These included McKesson Corporation, Neogen Corporation, Elekta AB, and Jack Henry & Associates. The group told each company to respond before September 1.

If they refused, ShinyHunters said it would release their data to the public. Coverage published before the deadline confirmed these four companies were part of a growing list of targets.

Once the deadline passed, things escalated fast. The group claims it released over 321GB of data tied to McKesson. It also claims to have released more than 313GB linked to Neogen, 17GB connected to Elekta, and 209GB tied to Jack Henry.

ShinyHunters says these files hold huge numbers of private records. However, these numbers come only from the attackers themselves. No outside group has verified them yet, so readers should treat the figures with caution.

ShinyHunters used a similar tactic in the Netherlands earlier this year. After breaching telecom provider Odido in February 2026 and stealing data from 6.2 million customers, the group demanded more than €1 million. When Odido refused, ShinyHunters leaked the data in stages, ultimately exposing information on more than 6.5 million people and 600,000 businesses.

Two Companies Confirm Real Attacks Happened

Out of the four named companies, McKesson has given the clearest confirmation. The healthcare distribution company said an unknown attacker broke into some of its outside software tools. That attacker then stole data linked to a portion of its customers.

This affected two parts of McKesson’s business, one focused on cancer care supplies and another on medical and surgical products. Still, McKesson stated that its delivery operations kept running normally, and it found no signs the attacker was still inside its systems.

ShinyHunters says it caused the McKesson breach. The group told BleepingComputer it used a trick called vishing. This means tricking someone over the phone into handing over login details. Once inside, the attackers reportedly moved into McKesson’s cloud-based tools.

According to research, the group claims it grabbed close to one terabyte of files and 284 million records. Again, these specific numbers have not been proven by anyone outside the group.

Jack Henry also confirmed an attack tied to ShinyHunters. The company said the attackers used the same phone-trick method to get inside. Personal details belonging to fewer than 10 clients were affected.

Jack Henry made clear that its main banking systems stayed untouched. According to the company’s official filing, it will not pay the attackers any money. A separate report added that Jack Henry called the campaign a sophisticated phishing attempt aimed at its staff.

Neogen and Elekta have not confirmed the extent of any leak yet. Until they do, or until outside experts check the files, those specific claims remain unverified.

A Pattern of Tricking People, not Hacking Code

This case shows a bigger trend in how attacks like this happen. ShinyHunters is not breaking through complex computer code. Instead, it tricks real employees into giving up their login information over the phone. Once the attackers have those logins, they walk right into cloud tools such as Salesforce and other business apps.

Health-ISAC has warned healthcare groups about this exact method. The group has reportedly built fake websites and impersonated real companies to fool workers into trusting them.

This kind of attack matters because it skips past many traditional security tools. A firewall cannot stop someone who simply hands over their own password by mistake. Companies need stronger checks on employee identity, better staff training against phone scams, and constant monitoring of their cloud accounts.

For now, the full damage from this leak remains unclear. Neogen and Elekta have not confirmed how much of their data, if any, was truly taken. What is certain is that ShinyHunters followed through on its threat, at least in part, and turned a deadline into a real leak. Whether every claimed file is genuine will likely take more time, and more independent digging, to fully sort out.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.