Interactive demo

See the whole workflow, end to end

This is the actual Deltabridge product surface. Watch a threat go from a living Brief, to an Athena Thread that researches and cites its work, into the Intel Library, and out across the Graph Explorer. It plays itself — scroll or click in anytime to take over.

app.deltabridge.ai
Search briefs, entities, references…
JD
24 references·Updated August 23, 2026

ShinyHunters Escalates Global Extortion Campaign Across Multiple Sectors

ShinyHunters
Data TheftExtortionSupply ChainCybercrimeInitial Access

A critical, financially-motivated data-extortion campaign with proven supply-chain reach and industrial-scale victim volume — high impact and high actionability given the breadth of exposed sectors.

Summary

ShinyHunters — also tracked as UNC6240 (Mandiant / Google Threat Intelligence) and Bling Libra (Palo Alto Unit 42) — has scaled a long-running data-theft operation into an industrial extortion machine in 2026, breaching over 40 confirmed organisations.

Rather than a single technique, the group has industrialised three campaigns: social-engineering against enterprise SSO, a supply-chain compromise via Anodot token theft, and a mass Instructure (Canvas) breach that escalated to school-by-school extortion.

  1. 23 August 2026
    ShinyHunters escalates extortion across multiple sectors
    Data-theft and double-extortion activity expands sharply across education, healthcare, finance and telecommunications.
  2. 12 August 2026
    Instructure (Canvas) breach reaches school-by-school extortion
    Claimed exfiltration of 3.65 TB across ~275 million records from 8,809 institutions, escalating to a “pay or leak” model.
  3. 18 July 2026
    Anodot supply-chain compromise abuses stolen tokens
    Actors reach at least 13 downstream customers — including Snowflake, Rockstar Games and Canvas Instructure — via harvested auth tokens.
  4. 20 May 2026
    FBI warning after Canvas LMS ransom paid
    A ransom payment for the Canvas LMS breach is confirmed, validating the model and emboldening further attacks.

Brief. A living, cited dossier — expand any section: threat score, timeline, response, IOCs and more.

Ready to run your own intel this way?

Spin up a workspace and point Athena at the threats that matter to you. No credit card required to start.