Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Talk:ShinyHunters

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 2 months ago by Dwmalone in topic Website

Canvas.

[edit]

Canvas domain just recently just got hacked by the shiny hunters at 904 utc today

Also got hacked for Katy ISD users on May 7th  Preceding unsigned comment added by Wilywings (talkcontribs) 20:19, 7 May 2026 (UTC)Reply

It is across all of the united states, i believe. This is unconfirmed but someone said that they know a person that works at cyber security and that Instructure has been talking to the hackers and negotiating since Saturday. The Unapologetic Spagetii (talk) 20:44, 7 May 2026 (UTC)Reply
i got hacked this very day ~2026-27663-76 (talk) 21:27, 7 May 2026 (UTC)Reply
For me it happened today at around 3:25 PM at my school, O. Henry MS in Austin, Texas, AISD. AISD blocked the site of blend itself within about 15 minutes of the hacked page popup ~2026-27777-56 (talk) 22:13, 7 May 2026 (UTC)Reply


The Unapologetic Spagetii (talk) 20:07, 7 May 2026 (UTC)Reply

It's global, I believe the countries affected were
United States
Canada
Australia
United Kingdom
Netherlands
Sweden
New Zealand
Singapore ~2026-28413-59 (talk) 01:47, 11 May 2026 (UTC)Reply

Protect somehow?

[edit]

It would probably be pertinent to semi-protect the page (or enact some other form of protection, not sure which). This is because it is currently being repeatedly vandalized by high school and college students affected by ShinyHunters' ongoing Canvas/Instructure breach. Blue :) (talk) 20:34, 7 May 2026 (UTC)Reply

Done! The article was semi-protected about one minute before you posted this, good call. Tessaract2 (hello) 20:35, 7 May 2026 (UTC)Reply
Good timing you guys, very fast response, well done. The Unapologetic Spagetii (talk) 20:47, 7 May 2026 (UTC)Reply

Make page protected

[edit]

New traffic is causing a bunch of vandalism. Article should be edit-protected. Naautilus0 (talk) 20:34, 7 May 2026 (UTC)Reply

Already done basically right before you posted this. It timed out weirdly, twas a good suggestion. Tessaract2 (hello) 20:39, 7 May 2026 (UTC)Reply

Semi-protected edit request on 7 May 2026

[edit]

Remove the "i dont like this guy" text. 1onewoof (talk) 20:35, 7 May 2026 (UTC)Reply

Already done, good spotting. Tessaract2 (hello) 20:37, 7 May 2026 (UTC)Reply

Semi-protected edit request on 7 May 2026 (2)

[edit]

I was in class when this happened and it showed up then, Ik its just 20 minutes but its more accurate Change On May 7th, 2026, Around 2:40 (CDT, UTC-5) to On May 7th, 2026, Around 3:00 (CDT, UTC-5) DInosaur10a (talk) 20:52, 7 May 2026 (UTC)Reply

 Not done. "Because I said so" is not a reliable source. Deacon Vorbis (carbon  videos) 21:20, 7 May 2026 (UTC)Reply
https://www.oudaily.com/news/canvas-hack-data-breach-ou-criminal-extortion-security/article_358fb651-5b28-4c87-8a61-e59f34c67015.html
I think this may be the source you are looking for. ~2026-27674-90 (talk) 22:10, 7 May 2026 (UTC)Reply

Semi-protected edit request on 8 May 2026

[edit]

I think shinyhunters was an openly lgbtq+ group. I saw this earlier on the wiki. ~2026-27816-13 (talk) 02:45, 8 May 2026 (UTC)Reply

 Not done: please provide reliable sources that support the change you want made. I wasn't able to find an edit before the current flurry of activity that includes this info. Umby 🌕🐶 (talk) 03:04, 8 May 2026 (UTC)Reply
Yes, an editor removed that line from the first sentence of the page last Thursday (5/7/26). ~2026-28683-24 (talk) 15:48, 12 May 2026 (UTC)Reply

Claims of reputability and non-neutral language

[edit]

The (Top) section of the main page says "The group has built a strong reputation of "pay or leak";...". Maybe this just needs some clearing up, but, at least to me, it seems to imply that the group is somewhat trustworthy in their claim of "if you pay us, we won't leak your data". A bit of sleuthing, with some help from WikiBlame, points to this edit by user ~2026-12411-74, as the origination --- see too this later edit which introduced an amount of non-neutral language like "notorious", "massively [significant]", and "strong [reputation]" by a different anonymous user ~2026-20778-96; that last being a revision back from an intermittent neutralizing edit by user DrOrinScrivello. As noted by a previous topic on this talk page, it appears that ShinyHunters/a member thereof is making minor edits to boost their own notoriety and reputation through anonymous accounts.

As the page has been semi-protected, I image such edits will decrease, but the page should probably be scoured of non-neutral language. I have neither the time nor particular know-how of Wikipedia's policies thereof to be doing it right now though. Velloxen (talk) 02:53, 8 May 2026 (UTC)Reply

I removed the phrasing that you identified because it is challenged, unsourced, and not entirely neutral.
Interestingly, ShinyHunters is described by "notorious" by at least two sources, The Register and Gizmodo (who also describe them as "well-known"), though my gut reaction is that an encyclopedia should not describe them as notorious in its own voice. nomen alternativum (he/himtalkcontribs) 06:58, 8 May 2026 (UTC)Reply

Edit proposal: change "significant amount" to "significant number" in first sentence of article.

[edit]

"data breaches" is a countable unit, so it should be described in terms of "number," not "amount." The article looks to be semi-protected so I can't change it, but somebody should. ~2026-27821-44 (talk) 12:12, 8 May 2026 (UTC)Reply

I've changed the wording. Hacked (Talk|Contribs) 13:29, 8 May 2026 (UTC)Reply


Edit proposal

[edit]

change "claimed responsibility of" to "claimed responsibility for" in the first and third sentences of the Instructure bullet-entry under the 2026 heading. "For" is the standard term in this phrase, not "of."  Preceding unsigned comment added by Velloxen (talkcontribs) 02:53, 8 May 2026 (UTC)Reply

I've changed it now. Global-banana (talk) 18:34, 8 May 2026 (UTC)Reply

Semi-protected edit request on 8 May 2026 (2)

[edit]

ShinyHunters was indeed formed in 2019. Someone changed it to 2020. They were initially known as GnosticPlayers back then and then rebranded to ShinyHunters in 2019. Google it.

ShinyHunters is not associated nor affiliated with "The Com". That is misinformation spread by industry 'experts' who have a misunderstanding regarding the group. Please remove "The Com" as affiliations. They are a small closed-knit group based out of France and have always been. They are their own entity and not under an ecosystem known as the "The Com"

ShinyHunters does not solely use social engineering tactics or voice phishing a/k/a vishing. In one case, the Instructure Canvas breach they exploited unknown vulnerabilities on the platform according to industry outlets such as BleepingComputer, TechCrunch, and others. They have been known to utilize 0days and other exploits. In another case please view:

- https://www.bleepingcomputer.com/news/security/oracle-silently-fixes-zero-day-exploit-leaked-by-shinyhunters/ - https://www.bleepingcomputer.com/news/security/oracle-patches-ebs-zero-day-exploited-in-clop-data-theft-attacks/

They are also widely known to pull off supply chain attacks via integration companies like Salesloft, Gainsight, and Anodot. Which is already written in the ShinyHunters Wikipedia in a detailed and documented manner. Vishing and/or social engineering is not their primary nor only skills/tactics.

I kindly request to please grant my account access to edit the ShinyHunters Wikipedia page as there is a lot of misinformation or things not well thought out. I have been tracking them for a long time and have a great understanding of the group. A lot of the newer information added on this page is misleading and the original things that were written are the most accurate. Accuratereporter593 (talk) 21:33, 8 May 2026 (UTC)Reply

 Not done: this is not the right page to request additional user rights. You may reopen this request with the specific changes to be made and someone may add them for you, or if you have an account, you can wait until you are autoconfirmed and edit the page yourself. Please use a "change x to y" format to show exactly what changes you want made to the article. Day Creature (talk) 02:04, 9 May 2026 (UTC)Reply

Edit proposal: Updated info

[edit]

Short one, but as of Monday 11 may, 11:45am AEST, can confirm ransom has still not been paid ~2026-28413-59 (talk) 01:45, 11 May 2026 (UTC)Reply

Source for countries affected by Canvas outage

[edit]

There are many more countries that were affected by the outage. I understand that this is a pointless observation if I can't attribute it to a source, but this press release from PUC Minas, a university in Brazil, not only mentions that the university itself was affected (therefore confirming that Brazil was among the affected countries) but also mentions that "the [outage] affects all of [Instructure's] clients worldwide."

The notice page that went up when they hacked Canvas included a list of affected schools/universities/school districts, which includes many more countries than both this article and 2026 Canvas security incident, though I'm not sure whether this could be used as a source either, seeing as the original text file is no longer up and remains only as reuploads on cybersecurity websites. Kalio2048 (talk) 03:32, 14 May 2026 (UTC)Reply

Website

[edit]

This is probably not the right place to ask this question, but if people are aware of the website, then why is it not being taken down? It contains personal info that should not be made available to others. I am fairly certain this is illegal. 🍁EFOSERVETY🍁 11:28, 16 May 2026 (UTC)Reply

We are not the legal team. If WP:OVERSIGHT or WP:LEGAL want to take it down they can do that. Otherwise wikipedia is WP:NOTCENSORED Czarking0 (talk) 01:36, 18 May 2026 (UTC)Reply
I would assume that they use Bulletproof hosting to place data where it will not easily be subject to legal takedown requests. David Malone (talk) 08:49, 18 May 2026 (UTC)Reply