---
title: "ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications"
metaTitle: "Data Extortion Group Targeting Cloud Apps"
description: Several well-known cybercrime groups with different areas of specialization are collaborating on the ‘shinysp1d3r’ ransomware-as-a-service (RaaS) network.
slug: extortion-group-targeting-enterprise-cloud-apps
date: "2025-09-22T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/financially-motivated-data-extortion-group.webp"
  alt: A spider drawn from glowing computer code.
sourcePublisher:
  name: EclecticIQ
  url: "https://www.eclecticiq.com/"
sourceArticle:
  url: "https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications"
tags: [Vishing, Insider Attack, Data Extortion]
status: published
---

EclecticIQ analysts assess with high confidence that ShinyHunters is expanding its operations by combining AI-enabled voice phishing, supply chain compromises, and leveraging malicious insiders, such as employees or contractors, who can provide direct access to enterprise networks.

ShinyHunters is very likely relying on members of Scattered Spider and The Com to conduct voice phishing attacks that provide unauthorized access to single sign-on (SSO) platforms used by retail, airline, and telecom companies. The group uses this access to exfiltrate large volumes of customer data and extort victim organizations.

Analysts observed that ShinyHunters leader, ShinyCorp, is actively selling stolen datasets with ransomware affiliates and other eCrime actors, at prices exceeding $1M per company...
