惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
T
Tailwind CSS Blog
博客园_首页
博客园 - 司徒正美
Google DeepMind News
Google DeepMind News
Hugging Face - Blog
Hugging Face - Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
V2EX
J
Java Code Geeks
量子位
D
DataBreaches.Net
MongoDB | Blog
MongoDB | Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Azure Blog
Microsoft Azure Blog
P
Proofpoint News Feed
C
Check Point Blog
V
Visual Studio Blog
H
Help Net Security
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta

Troy Hunt's Blog

Weekly Update 521: Breach Perception v. Reality Weekly Update 520: The Unscripted Edition Weekly Update 519: Breaches & Data Integrity A Cautionary Tale About Data Breach Claims, Verification and Carhartt Weekly Update 518: IoT Doorlock Nirvana with UniFi Welcoming the Sri Lankan Government to Have I Been Pwned Weekly Update 517: Cyber Ransoms Weekly Update 516: Live From Vietnam Welcoming the Nepalese Government to Have I Been Pwned Weekly Update 515 Weekly Update 514: This Week in Data Breaches Weekly Update 513: Clauding The Home Network Weekly Update 512: IoT Lockout Fail Weekly Update 511: Live from my Riad in Marrakech Swimming Pools, Pee, and Trying to Delete Your Data From the Internet Weekly Update 510: Live From Mallorca with Scott Helme Weekly Update 509 Weekly Update 508 Weekly Update 507 Welcoming the Philippine Government to Have I Been Pwned 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever Weekly Update 506 Welcoming the Bhutanese Government to Have I Been Pwned Weekly Update 505 Weekly Update 504 Welcoming the Bahamian Government to Have I Been Pwned Welcoming the Bangladesh Government to Have I Been Pwned Welcoming the Costa Rican Government to Have I Been Pwned Weekly Update 503 Weekly Update 501
Weekly Update 502
Troy Hunt · 2026-05-06 · via Troy Hunt's Blog

It's a fascinating display of leverage: the ShinyHunters folks, with very limited resources and experience (their demographic will be teenagers to their early 20s), consistently gaining access to the data of massive brands. Not through technical ingenuity alone (although I'm sure there's a portion of that), but primarily through good ol' social engineering. That's coming through in the disclosure notices from the impacted companies, and Mandiant has a good write-up of it too:

These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) credentials and multi-factor authentication (MFA) codes

Question now is how long their run will go for. There's a very predictable ending if things keep going in this direction but right now, they show little sign of abating.

Listen on Apple Podcasts

Watch and Listen on YouTube

Download via RSS

Weekly update