Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Shinyhunters extorts Red Hat over stolen CER data

Red Hat faces extortion after 570GB of internal data and 800 customer reports were stolen, with ShinyHunters setting an October 10 ransom deadline.

byAytun Çelebi
October 7, 2025
in Cybersecurity

Enterprise software company Red Hat is the target of an extortion campaign by the ShinyHunters group following a data breach. The incident, first claimed by a group called the Crimson Collective, involves stolen customer reports and has led to a new collaboration between the hacking organizations.

The initial breach and stolen data

The breach was announced last week when the Crimson Collective claimed it had stolen nearly 570 gigabytes of compressed data from 28,000 of Red Hat’s internal development repositories. A key part of the stolen data is said to be approximately 800 Customer Engagement Reports (CERs). These documents are highly sensitive as they can contain specific details about a customer’s network architecture, IT infrastructure, and operational platforms.

The attackers stated they attempted to contact Red Hat for a ransom payment but received no response. Red Hat later confirmed it had experienced a security incident, specifying that the breach was limited to a GitLab instance used by its consulting division for customer engagement work.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Escalation through a new alliance

The situation escalated when Crimson Collective announced a partnership with another group, Scattered Lapsus$ Hunters, to leverage the newly launched ShinyHunters data leak site for their extortion efforts. In a post on its Telegram channel, Crimson Collective hinted at the alliance.

“What if, Crimson’s shininess extends even further away?”

The group later confirmed the collaboration, stating they would work with ShinyHunters on future attacks and data releases.

Following this, an entry for Red Hat appeared on the ShinyHunters data leak and extortion website. The post serves as a public warning, setting a deadline of October 10th for a ransom to be negotiated directly with ShinyHunters. To prove their claims, the attackers released samples of the stolen Customer Engagement Reports, which included documents related to major corporations and government bodies, including Walmart, HSBC, the Bank of Canada, the Department of Defence, and American Express.

ShinyHunters’ extortion-as-a-service model confirmed

The incident confirms long-held speculation that ShinyHunters operates as an extortion-as-a-service (EaaS) platform. This model functions like ransomware-as-a-service, where the platform’s operators work with different hacking groups to conduct extortion and take a percentage of any ransom payments.

ShinyHunters has now confirmed it operates this model, detailing the revenue split. The group stated that the hackers they work with typically take 70-75% of the payment, while ShinyHunters receives a 25-30% cut. The launch of the public data leak site marks a shift from a private to a public-facing extortion service.

Other targets on the ShinyHunters platform

The ShinyHunters site is also being used to extort the financial information and analytics company S&P Global on behalf of a different attacker. That group claimed to have breached S&P Global in February 2025, a claim the company denied at the time. Data samples asserted to be from the attack have now been posted on the ShinyHunters site with the same October 10th deadline. When contacted again, a representative for S&P Global declined to address the claims directly, stating, “as a US listed company, we are required to publicly disclose material cybersecurity incidents.”


Featured image credit

Tags: Red HatShinyHunters

Related Posts

Chinese hackers use Claude to run large scale cyberespionage

Chinese hackers use Claude to run large scale cyberespionage

November 14, 2025
Hackers exploit Cisco and Citrix zero days to gain admin access

Hackers exploit Cisco and Citrix zero days to gain admin access

November 13, 2025
Microsoft uncovers Whisper Leak: A flaw that lets spies your AI chats

Microsoft uncovers Whisper Leak: A flaw that lets spies your AI chats

November 10, 2025
Google urges Gmail users to abandon passwords for passkeys

Google urges Gmail users to abandon passwords for passkeys

November 10, 2025
This Samsung Galaxy phone needs and immediate update

This Samsung Galaxy phone needs and immediate update

November 7, 2025
AMD confirms critical RDSEED flaw in Zen 5 CPUs

AMD confirms critical RDSEED flaw in Zen 5 CPUs

November 4, 2025

LATEST NEWS

Waterfall 2.0: AI brings back structured software development

Chinese hackers use Claude to run large scale cyberespionage

Google expands Pixel call recording to global users

Facebook levels up Marketplace with social features and AI support

NotebookLM gains automated research and wider file support

Tesla is reportedly testing Apple CarPlay integration

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.