Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: ShinyHunters: Timing Tactics & Ransomware Surge

Varonis
07/05/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


at least my hypothesis is around timing. They seem to have really nailed when to attack a company. Now, when we think about the leaks from Zara and Carnival and 7-Eleven, we have ADT, we have Vimeo. These are all deadlines that were given to the companies of, we're going to post the data online or encrypt your systems if you don't pay us by these particular times. And they are, for lack of a better word, hot and heavy right now. They're attacking a lot of different organizations. They're carrying out a lot of attacks. Seems as though their operation is growing based off the use of initial access brokers that we saw earlier.

TL;DR

  • ShinyHunters is currently executing a high-volume attack campaign against major organizations across multiple industries, including retail, entertainment, and infrastructure.
  • The group's defining tactic is deadline-driven extortion — threatening to leak data or encrypt systems by a specific date if ransom is not paid.
  • Their operation appears to be scaling through the use of initial access brokers, enabling faster and broader targeting of new victims.

Summary

This short clip offers an analyst's perspective on the ShinyHunters threat group and what makes their current wave of attacks particularly notable. The speaker's central hypothesis centers on timing: ShinyHunters has demonstrated a sophisticated ability to identify precisely when to pressure a target organization, issuing hard deadlines that threaten either public data exposure or system encryption if ransom demands go unmet. Victims in this surge include well-known brands such as Zara, Carnival, 7-Eleven, ADT, and Vimeo — a cross-industry spread that signals the group is not narrowly focused on a single sector. The speaker characterizes the group as aggressively active right now, describing their pace as 'hot and heavy' and noting that the volume and frequency of attacks suggest a scaling operation. A key structural observation is that ShinyHunters appears to be leveraging initial access brokers to expand its reach, a tactic that allows the group to outsource the initial compromise phase and focus resources on extortion. For security teams, this clip serves as a timely warning that ShinyHunters is operationally mature, growing, and applying deliberate psychological pressure through deadline-driven extortion.

Chapters

0:00 - Timing as a Weapon
0:11 - Recent High-Profile Victims
0:27 - Growing Scale & Access Brokers

Key Quotes

0:04 "... at least my hypothesis is around timing."
0:07 "They seem to have really nailed when to attack a company."
0:27 "They are, for lack of a better word, hot and heavy right now."

FAQ

What makes ShinyHunters' current attack wave different from previous activity?

According to the speaker, the current surge is distinguished by the group's precise timing of attacks and their use of hard deadlines to pressure victims, combined with a growing operational scale enabled by initial access brokers.

Which organizations have been targeted by ShinyHunters recently?

The clip references Zara, Carnival, 7-Eleven, ADT, and Vimeo as recent victims, each given deadlines to pay before data was posted or systems were encrypted.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Security Operations
  • Short Form
  • ShinyHunters threat group
  • Ransomware extortion tactics
  • Initial access brokers
  • Data breach deadline pressure
  • Threat actor profiling
  • Cybercrime operations
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: ShinyHunters: Timing Tactics & Ransomware Surge

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Ensuring Compliance Through Audit Evidence: From CJIS to FERPA

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Ensuring Compliance Through Audit Evidence: From CJIS to FERPA
                      https://www.truthinit.com/index.php/channel/2159/ensuring-compliance-through-audit-evidence-from-cjis-to-ferpa/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version