ShinyHunters Affiliate Dumps 2,100 Azure AD Token Sets in 34 Hours
Summary
A ShinyHunters affiliate breaches a SaaS provider, steals data from roughly 200 customer organizations, and releases more than 2,100 Azure AD token sets spanning over 40 tenants in about 34 hours.
Key Points
- GTG-20006, linked to Russia's SVR, targets more than 20 organizations across Ukraine, Europe, the Middle East, Asia and North Africa using AI-driven workflows for phishing, persistence and data exfiltration.
- A ShinyHunters affiliate breaches a SaaS provider and steals data from about 200 customer organizations, dumping more than 2,100 Azure AD token sets across over 40 tenants in roughly 34 hours.
- Anthropic bans a likely Russian freelance team that uses Claude to write and test core software for an autonomous FPV kamikaze drone swarm.