Illustration of a spoofed corporate support call leading to a phishing and data-theft attack on a financial services laptop.

Jack Henry Confirms Vishing Breach as ShinyHunters’ Yearlong Rampage Widens

FinTech firm Jack Henry confirmed Aug. 31 a voice-phishing attack tied to the extortion group and says it won’t pay.

Jack Henry and Associates confirmed on Monday that a voice-phishing attack by the extortion group ShinyHunters compromised part of its internal network. The disclosure comes three days after the group had already listed the company on its leak site and given it until Sept. 1 to pay before it published stolen data, according to a listing tracked by RedPacket Security.

The incident is the latest in a run of attacks the group has claimed since January, when Google’s Threat Intelligence Group/Mandiant reported that ShinyHunters-branded activity compromised more than 100 organizations in a single mid-January stretch alone.

Beyond the Break weekly cybersecurity newsletter — Subscribe

Google tracks the activity across several affiliated clusters that share tactics: UNC6040, the group that pioneered the Salesforce vishing campaigns, and UNC6240, UNC6661 and UNC6671, which have since adopted similar methods. Google cautions that press coverage often treats “ShinyHunters” as a single group when the activity may actually span several of these affiliated groups.

What Jack Henry Actually Disclosed

Jack Henry and Associates said personally identifiable information tied to fewer than 10 of its clients was affected. That figure describes financial institutions, not individual accountholders. Jack Henry serves more than 7,200 banks and credit unions of varying size, and the company has not disclosed how many individual accountholders’ data was exposed at the affected institutions.

In response to Security Point Break’s inquiry, Jack Henry Corporate Communications Director Mark Folk said the company has “determined that the incident is not financially material to the company.” He added, Jack Henry has been focused on notifying clients, working with impacted clients, and working with third-party cybersecurity experts and the FBI.

The company attributed the initial access to a “sophisticated” vishing attack, a phone-based social-engineering technique. It said the intrusion amounted to an extortion attempt.

Jack Henry said it will not pay the threat actor and has determined the incident is not financially material. The company said its security controls detected and contained the activity, and that it is working with an outside forensics firm and federal law enforcement.

Jack Henry has not disclosed a specific date for when the intrusion began, how long ShinyHunters had access, or what volume of data – if any – was exfiltrated beyond the PII tied to the affected clients.

“ShinyHunters has established itself as one of the most prolific data extortion groups operating today,” said Matt Hull, VP of cyber intelligence and response at NCC Group in a statement to SPB regarding a separate ShinyHunters Carhartt breach.   

“Rather than focusing solely on operational disruption, the group’s model centers on stealing large quantities of sensitive information and leveraging the reputational, regulatory and commercial consequences of disclosure to pressure organizations,” he said.

Steal First. Extort Later

Jack Henry’s confirmation comes just days after a larger breach reported by McKesson, the pharmaceutical distribution giant. McKesson disclosed its own incident in an SEC Form 8-K filed Friday. ShinyHunters claims it stole 284 million patient-data records from McKesson’s Oncology and Multispecialty, and Medical-Surgical business units and is demanding $55.2 million by Sept. 1. The group later clarified the 284 million figure describes database rows, not necessarily unique patients.

Both companies avoided the SEC’s toughest disclosure requirements. McKesson filed its incident under Item 7.01 (Regulation FD) rather than Item 1.05 — the category reserved for cybersecurity incidents a company determines to be material.

Jack Henry did file its annual 10-K on Aug. 28, three days before issuing its public statement on the incident. In the filing, Jack Henry said that, as of that date, it had not determined that any known cybersecurity threat or prior incident had materially affected the company or was reasonably likely to do so.

The company confirmed to SPB that Jack Henry knew about the incident before the 10-K filing, and that it’s keeping regulators informed.

ShinyHunters publicly listed Jack Henry as a victim, also on Aug. 28.

The company has not disclosed when the attack occurred or when it was first detected.

Not the Busiest. Just the Loudest

By raw leak-site victim counts, ShinyHunters isn’t 2026’s most prolific actor. BreachSense’s live tracker counted 96 named ShinyHunters victims since it began tracking the group, including 11 in the past 30 days alone. By comparison, Qilin and The Gentlemen have run monthly totals north of 100. But focusing on volume over blast radius misses the point.

ReliaQuest’s Q1 2026 report stated ShinyHunters proves “identity-first intrusions and SaaS-native data theft can deliver major impact without deploying encryptors.”

The point is that Qilin and Akira run ransomware-as-a-service operations that encrypt and extort dozens of victims a month. ShinyHunters, by contrast, vishes a handful of employees into handing over SSO credentials, then pivots into Salesforce, Snowflake, or SharePoint. By targeting credentials instead of a single system, the group can move deeper into a victim’s network than any one ransomware payload, trading victim count for blast radius.

Case in point, McKesson’s claimed 284 million records, or the 700-plus organizations Microsoft says were touched by the group’s Salesloft/Drift OAuth-token campaign, can outweigh what a high-volume crew claims in an entire month.

“This reflects a wider trend across the threat landscape, where data theft has become just as commercially lucrative for attackers as traditional ransomware,” NCC Group’s Hull said.

Why SaaS Became the Target

ShinyHunters’ shift toward Salesforce, Snowflake, and other SaaS platforms isn’t isolated to this week’s victims.

“This incident highlights how SaaS ecosystems have become one of the most overlooked parts of the modern attack surface,” said Dale Hoak, CISO, RegScale in a statement to SPB.

He added, despite rigorous security controls to core infrastructure, cloud platforms are overlooked. “[They] accumulate excessive permissions, legacy integrations, service accounts, and years of sensitive operational data with far less scrutiny.”

Josh Picolet, VP of Detection and Analysis, at Team Cymru told SPB that defenders must stop treating SaaS platforms as someone else’s problem and start protecting them as if they were their own network edge.        

ShinyHunters Misery Index

ShinyHunters isn’t new. Between 2020 and 2021, DOJ prosecutors said, the group hacked more than 60 companies and posted stolen data on dark web forums, sometimes threatening to leak it unless victims paid.

French national Sébastien Raoult, who went by “Sezyo Kaizen,” was arrested in Morocco in 2022 and extradited to the U.S. in January 2023, where he pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. He was sentenced to three years in prison and ordered to pay $5 million in restitution.

The corporate breach numbers understate the human cost. Leaked ShinyHunters data, from Amtrak to Panera Bread, is now fueling a wave of sextortion scams, according to a July Malwarebytes report. It reported scammers are demanding roughly $2,000 in bitcoin from people and falsely claiming to have compromising webcam recordings of targets.

Not every target becomes a headline, though: in August, ReliaQuest caught an almost-identical vishing attempt against its own staff and shut it down before it became the next McKesson.

Total
0
Shares
Previous Article
Close-up of a finger with a small paper cut, resting near a keyboard and printed documents.

CISA Mandates PaperCut Patch After Chained RCE Bugs Hit KEV List

Next Article
Cybernetic cat and rabbit facing off on a circuit board representing PollCat and NodeRabbit malware.

Two New RATs, One Very Bad Coding Interview

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading