Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Shinyhunters extorts Red Hat over stolen CER data

Red Hat faces extortion after 570GB of internal data and 800 customer reports were stolen, with ShinyHunters setting an October 10 ransom deadline.

byAytun Çelebi
October 7, 2025
in Cybersecurity
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail

Enterprise software company Red Hat is the target of an extortion campaign by the ShinyHunters group following a data breach. The incident, first claimed by a group called the Crimson Collective, involves stolen customer reports and has led to a new collaboration between the hacking organizations.

The initial breach and stolen data

The breach was announced last week when the Crimson Collective claimed it had stolen nearly 570 gigabytes of compressed data from 28,000 of Red Hat’s internal development repositories. A key part of the stolen data is said to be approximately 800 Customer Engagement Reports (CERs). These documents are highly sensitive as they can contain specific details about a customer’s network architecture, IT infrastructure, and operational platforms.

The attackers stated they attempted to contact Red Hat for a ransom payment but received no response. Red Hat later confirmed it had experienced a security incident, specifying that the breach was limited to a GitLab instance used by its consulting division for customer engagement work.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Escalation through a new alliance

The situation escalated when Crimson Collective announced a partnership with another group, Scattered Lapsus$ Hunters, to leverage the newly launched ShinyHunters data leak site for their extortion efforts. In a post on its Telegram channel, Crimson Collective hinted at the alliance.

“What if, Crimson’s shininess extends even further away?”

The group later confirmed the collaboration, stating they would work with ShinyHunters on future attacks and data releases.

Following this, an entry for Red Hat appeared on the ShinyHunters data leak and extortion website. The post serves as a public warning, setting a deadline of October 10th for a ransom to be negotiated directly with ShinyHunters. To prove their claims, the attackers released samples of the stolen Customer Engagement Reports, which included documents related to major corporations and government bodies, including Walmart, HSBC, the Bank of Canada, the Department of Defence, and American Express.

ShinyHunters’ extortion-as-a-service model confirmed

The incident confirms long-held speculation that ShinyHunters operates as an extortion-as-a-service (EaaS) platform. This model functions like ransomware-as-a-service, where the platform’s operators work with different hacking groups to conduct extortion and take a percentage of any ransom payments.

ShinyHunters has now confirmed it operates this model, detailing the revenue split. The group stated that the hackers they work with typically take 70-75% of the payment, while ShinyHunters receives a 25-30% cut. The launch of the public data leak site marks a shift from a private to a public-facing extortion service.

Other targets on the ShinyHunters platform

The ShinyHunters site is also being used to extort the financial information and analytics company S&P Global on behalf of a different attacker. That group claimed to have breached S&P Global in February 2025, a claim the company denied at the time. Data samples asserted to be from the attack have now been posted on the ShinyHunters site with the same October 10th deadline. When contacted again, a representative for S&P Global declined to address the claims directly, stating, “as a US listed company, we are required to publicly disclose material cybersecurity incidents.”


Featured image credit

Tags: Red HatShinyHunters

Related Posts

Why that harmless looking desktop icon might actually be a weapon

Why that harmless looking desktop icon might actually be a weapon

November 24, 2025
This Netflix notification is actually a malware

This Netflix notification is actually a malware

November 24, 2025
Your antivirus missed this malware for three years straight

Your antivirus missed this malware for three years straight

November 21, 2025
Cloudflare admits a bot filter bug caused its worst outage since 2019

Cloudflare admits a bot filter bug caused its worst outage since 2019

November 19, 2025
Cloudflare is down worldwide: Internal server error explained

Cloudflare is down worldwide: Internal server error explained

November 18, 2025
Chinese hackers use Claude to run large scale cyberespionage

Chinese hackers use Claude to run large scale cyberespionage

November 14, 2025

LATEST NEWS

Why that harmless looking desktop icon might actually be a weapon

This Netflix notification is actually a malware

Facebook Groups finally lets you use nicknames

Nothing OS 4.0 brings Android 16 to the Phone 3 starting today

iPhone 17e will launch in February with a flagship camera

Apple’s latest limited-edition accessory is a sculptural stand

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.