ThreatPaper
Assessed, Not Confirmed

UNC6240 is ShinyHunters

Assessment

Google's Threat Intelligence Group tracks this campaign as the activity cluster UNC6240 and links it to ShinyHunters, whose established pattern is data-theft extortion. This is a well-supported vendor assessment, but two caveats keep it short of a definitive identification. First, 'UNC' designations are by definition uncategorised, provisional clusters that GTIG has not fully graduated to a named group. Second, 'ShinyHunters' is itself a loose, overlapping label used across a shifting set of actors and aliases rather than a single fixed organisation. So 'ShinyHunters did this' is an accurate shorthand for GTIG's assessment, but a reader should understand it as an attribution of behaviour to a fuzzy-edged label, not a precise, courtroom-grade identification of specific individuals.

Where this claim appeared

BleepingComputer · 2026-09-26

https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

ShinyHunters (UNC6240) bypass a WAF with one URL-encoded character to mass-exploit PeopleSoft CVE-2026-35273

Think this assessment is wrong? Report an error.