apposters.com

ShinyHunters Unleashes Global Cyber Onslaught: SoundCloud, Match Group Breached

February 2, 2026, 4:39 am
BleepingComputer
BleepingComputer
ComputerITLearnNewsSecurityTechnology
Location: United States, New York
Employees: 1-10
Founded date: 2004
Okta Ventures
Okta Ventures
Location: United States, California, San Francisco
Employees: 5001-10000
Founded date: 2009
ShinyHunters launched a major cyberattack spree. SoundCloud's 29.8 million accounts were compromised, exposing emails and public profile details. Match Group, including OkCupid, Match, and Hinge, lost 1.7 GB of data via sophisticated voice phishing, revealing personal user information and sensitive internal corporate documents. This prolific hacking collective also targeted single sign-on systems from Okta, Microsoft, and Google, alongside Salesforce CRM clients globally, affecting major corporations. The incidents underscore an escalating threat landscape, demanding immediate, robust security upgrades and vigilant user practices to combat pervasive digital extortion and data theft campaigns impacting critical online services and enterprise operations worldwide.

*
A dangerous cyber threat group is on the offensive. ShinyHunters, a notorious hacking collective, has executed a series of high-profile data breaches. Their latest attacks struck SoundCloud and the Match Group. Millions of user accounts are now exposed.

SoundCloud, a major music streaming platform, confirmed a massive data leak. Nearly 30 million user accounts were compromised. This incident, confirmed in December, exposed critical personal information. Emails, geographic locations, and public profile statistics leaked into the wrong hands. Financial data and passwords remained secure, the company asserts. However, attackers matched emails with public profiles. They then launched extortion attempts against users.

The platform responded swiftly. Incident response procedures activated. Unauthorized activity on an auxiliary service dashboard triggered the alert. SoundCloud's internal investigation concluded quickly. They identified affected data. The breach impacted approximately 20% of all users. ShinyHunters took responsibility for the attack. They also attempted to extort SoundCloud directly. The platform confirmed these demands in a January update. Hackers employed mass email tactics. They harassed users, employees, and partners.

Simultaneously, ShinyHunters targeted the Match Group. This incident involved a 1.7 GB data theft. Dating apps like OkCupid, Match, and Hinge suffered exposure. Tinder, the group's most popular app, remained unaffected. Hackers accessed a limited amount of user data. They stole personal details. Employee records and internal corporate materials also leaked. Login credentials, financial data, and messages appear untouched.

The attack vector was distinct. ShinyHunters employed "vishing." This is voice phishing. Attackers called individuals with access credentials. They manipulated these targets. They convinced them to surrender sensitive information. This social engineering tactic proved effective. It granted access to an Okta account. This initial breach cascaded. It led to access within AppsFlyer. Google Drive and Dropbox cloud storage also became vulnerable.

Match Group acted quickly. They stopped unauthorized access. An investigation is underway. External specialists are assisting. Affected users received notifications. This swift response aims to mitigate damage.

ShinyHunters is not a new threat. They are a prolific cybercriminal organization. Their operations extend far beyond these recent breaches. The group orchestrates broad campaigns. These attacks target single sign-on (SSO) systems. Okta, Microsoft, and Google are frequent targets. Last week, they launched more phishing attacks against these providers.

Their reach is extensive. ShinyHunters has long targeted Salesforce CRM systems. They use social engineering and vishing. This campaign compromised numerous global companies. Adidas, Qantas, Allianz Life, Louis Vuitton, Dior, Tiffany & Co., and Chanel are among the victims. Even Google has been affected. This demonstrates their sophisticated tactics. They exploit human vulnerabilities.

The group launched a darknet data leak site in October. They claimed vast data theft. Billions of records were allegedly stolen from various clients. This underlines their scale and ambition. Previously, ShinyHunters was also linked to extortion involving Pornhub data. Their criminal portfolio is diverse.

These incidents highlight critical cybersecurity challenges. Organizations face constant threats. Sophisticated attack methods evolve rapidly. Vishing and social engineering bypass technical controls. Human error becomes the weakest link. The interconnectedness of digital services amplifies risk. A breach in one system can compromise many others.

Companies must fortify their defenses. Multi-factor authentication is crucial. Employee training is paramount. Staff must recognize phishing attempts. Strong incident response plans are essential. Rapid detection and containment limit damage. Regular security audits identify weaknesses.

Users also bear responsibility. Practice strong password hygiene. Enable multi-factor authentication everywhere. Be wary of unsolicited communications. Verify requests for personal information. Treat all unexpected calls with skepticism. Your data is valuable. Protect it.

The digital landscape is dangerous. ShinyHunters represents a persistent, evolving threat. Their multi-pronged attacks on SoundCloud and Match Group prove this. They target critical infrastructure. They exploit human and technical vulnerabilities. This ongoing cyber war demands unwavering vigilance. It requires robust defenses from every entity online. The future of data security depends on it.