Anyone Can Say They Are ShinyHunters. Vercel's Attacker Did, and ShinyHunters Said It Wasn't Them.
- Patrick Duggan
- 15 minutes ago
- 4 min read
A criminal brand works exactly like a legitimate one. It compresses a reputation into a name, and once the name is worth something, other people wear it.
ShinyHunters is now valuable enough to impersonate. That breaks something defenders quietly rely on: the assumption that a crew claiming a breach is the crew that did it.
The clean case is Vercel
In April 2026, Vercel was breached by an entity that claimed to be ShinyHunters. The leadership associated with the actual ShinyHunters denied involvement.
Set aside whether you believe criminals about anything. The structural point stands regardless of who was telling the truth: the claim and the crew came apart in public, and there was no neutral way to settle it. The press had already attributed it. The victim had already been told who hit them.
Further down the food chain it is cruder. There is a consumer-grade sextortion email circulating that invokes the ShinyHunters name and demands about $2,000 in Bitcoin — generic wording, no victim-specific reference, no proof of anything. It is not a breach. It is a name being rented to make a mass-mailed threat feel researched.
Which is precisely why we are not calling McGraw-Hill or ADT fake
This piece started because someone floated that the recent McGraw-Hill and ADT extortions might be copycats too. We went looking, and they do not appear to be.
McGraw-Hill — extortion demand April 14, breach confirmed, traced to a misconfiguration in the company's Salesforce environment, more than 100GB leaked, data tied to roughly 13.5 million accounts.
ADT — the company disclosed unauthorized access to a subset of customer data; the actor claimed considerably more, north of 10 million records, and the incident became a data-extortion campaign with a subsequent release.
Both are attributed to the real operation, now working inside the Scattered LAPSUS$ Hunters alliance and running concurrent Salesforce OAuth, Canvas, and identity-platform campaigns. We found nothing supporting a copycat on either one, so we are saying so plainly rather than letting a tidier story stand.
That matters more than it looks. The failure mode of "attribution is unreliable" is not only believing a false claim — it is disbelieving a true one. A defender who decides ShinyHunters claims are cheap talk will underweight a campaign that is genuinely coming for their Salesforce tenant. Skepticism applied indiscriminately is just a different way of being wrong.
The uncomfortable structure
Three things are true at once:
Real ShinyHunters activity is ongoing and severe.
The name is being worn by unrelated actors, from Vercel-scale claims down to sextortion spam.
There is no authority that adjudicates which is which, and the only people who could confirm it are criminals with an interest in the answer.
So the industry runs on claims. A crew posts, journalists write it up, and vendors fold the attribution into reports that customers plan against. The attribution frequently originates as a statement by an anonymous party with a motive, and by the third citation it has hardened into a fact with a footnote.
We are not above this. We have written the correction before — earlier this month we published one admitting we had cited our own ingest timestamp as though it were a detection, and claimed a two-month lead we did not have. Same disease: a convenient artifact treated as evidence because nobody made it prove itself.
What to do with an extortion claim
Separate the claim from the intrusion. "Data from our environment is being sold" is verifiable. "ShinyHunters did it" is an assertion. Your response to the first should not depend on the second.
Demand victim-specific proof. The tell that separates the real operation from the rent-a-name crowd is whether the actor can produce something only someone inside your environment would have. Real crews sample. Copycats send templates.
Respond to the vector, not the logo. McGraw-Hill was a Salesforce misconfiguration. That is a finding you can act on tonight, and it is true no matter whose name is on the ransom note. Attribution is interesting. Access path is actionable.
Do not let the brand set your severity. If a scary name makes an incident a board matter and an unknown name makes it a ticket, you have outsourced triage to whoever picks the best handle.
The prediction
Brand impersonation is a maturity signal. It happens to ransomware crews for the same reason it happens to banks and parcel carriers: the name became load-bearing, so forging it became profitable. LockBit went through this. It will keep happening to whoever is on top.
Expect more claims than intrusions, and expect the gap to widen. The name is free to copy. The access is not.
Sources: public reporting on the Vercel, McGraw-Hill, and ADT incidents, and consumer-fraud documentation of ShinyHunters-branded sextortion mail. Attribution statements in this post are reported as claims, including the denial — we have no independent means to adjudicate any of them, and neither does anyone else writing about it.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
