Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: ShinyHunters: Timing Tactics & Ransomware Surge

Varonis
07/05/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


at least my hypothesis is around timing. They seem to have really nailed when to attack a company. Now, when we think about the leaks from Zara and Carnival and 7-Eleven, we have ADT, we have Vimeo. These are all deadlines that were given to the companies of, we're going to post the data online or encrypt your systems if you don't pay us by these particular times. And they are, for lack of a better word, hot and heavy right now. They're attacking a lot of different organizations. They're carrying out a lot of attacks. Seems as though their operation is growing based off the use of initial access brokers that we saw earlier.

TL;DR

  • ShinyHunters is currently executing a high-volume attack campaign against major organizations across multiple industries, including retail, entertainment, and infrastructure.
  • The group's defining tactic is deadline-driven extortion — threatening to leak data or encrypt systems by a specific date if ransom is not paid.
  • Their operation appears to be scaling through the use of initial access brokers, enabling faster and broader targeting of new victims.

Summary

This short clip offers an analyst's perspective on the ShinyHunters threat group and what makes their current wave of attacks particularly notable. The speaker's central hypothesis centers on timing: ShinyHunters has demonstrated a sophisticated ability to identify precisely when to pressure a target organization, issuing hard deadlines that threaten either public data exposure or system encryption if ransom demands go unmet. Victims in this surge include well-known brands such as Zara, Carnival, 7-Eleven, ADT, and Vimeo — a cross-industry spread that signals the group is not narrowly focused on a single sector. The speaker characterizes the group as aggressively active right now, describing their pace as 'hot and heavy' and noting that the volume and frequency of attacks suggest a scaling operation. A key structural observation is that ShinyHunters appears to be leveraging initial access brokers to expand its reach, a tactic that allows the group to outsource the initial compromise phase and focus resources on extortion. For security teams, this clip serves as a timely warning that ShinyHunters is operationally mature, growing, and applying deliberate psychological pressure through deadline-driven extortion.

Chapters

0:00 - Timing as a Weapon
0:11 - Recent High-Profile Victims
0:27 - Growing Scale & Access Brokers

Key Quotes

0:04 "... at least my hypothesis is around timing."
0:07 "They seem to have really nailed when to attack a company."
0:27 "They are, for lack of a better word, hot and heavy right now."

FAQ

What makes ShinyHunters' current attack wave different from previous activity?

According to the speaker, the current surge is distinguished by the group's precise timing of attacks and their use of hard deadlines to pressure victims, combined with a growing operational scale enabled by initial access brokers.

Which organizations have been targeted by ShinyHunters recently?

The clip references Zara, Carnival, 7-Eleven, ADT, and Vimeo as recent victims, each given deadlines to pay before data was posted or systems were encrypted.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Security Operations
  • Short Form
  • ShinyHunters threat group
  • Ransomware extortion tactics
  • Initial access brokers
  • Data breach deadline pressure
  • Threat actor profiling
  • Cybercrime operations
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: ShinyHunters: Timing Tactics & Ransomware Surge

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Understanding Invisible Data Risks and Enhancing Your Protection Strategies

                      09/23/202601:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Becoming Agent Ready with Cyera: Essential Strategies and Insights
                        https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                        https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/03/2026
                        01:00 PM
                        09/03/2026
                        Verge.io: Can You Afford Your Next Storage Refresh?
                        https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                      • 09/23/2026
                        01:00 PM
                        09/23/2026
                        Understanding Invisible Data Risks and Enhancing Your Protection Strategies
                        https://www.truthinit.com/index.php/channel/2087/understanding-invisible-data-risks-and-enhancing-your-protection-strategies/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      • 11/19/2026
                        01:00 PM
                        11/19/2026
                        360View: Govern, Secure & Recover Your Microsoft 365 Environment
                        https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version