The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Federal records document that ShinyHunters posted stolen data from more than 60 companies for sale on dark-web forums between April 2020 and July 2021. A separate, later FBI alert describes alleged ShinyHunters activity involving a learning management system and warns that stolen information could be used for impersonation. Those records concern different events; they do not establish that every later use of the ShinyHunters name involves the same people or a continuous group.
What does it mean that ShinyHunters offers stolen data on the dark web?
In its January 9, 2024 sentencing announcement, the U.S. Department of Justice (DOJ) said ShinyHunters posted data from more than 60 companies for sale on dark-web forums between April 2020 and July 2021. DOJ named RaidForums, EmpireMarket, and Exploit. These are historical sales postings documented in the case—not evidence of what is currently available in any marketplace.
The announcement followed the sentencing of Sebastien Raoult, who received three years in prison and was ordered to pay more than $5 million in restitution. DOJ attributed hundreds of millions of stolen customer records and company losses estimated to exceed $6 million to the conspirators’ activity. Those figures describe the Raoult case, not a total for all ShinyHunters activity or all dark-web listings. DOJ’s sentencing announcement does not provide an overall count of ShinyHunters listings or measure the full current market for stolen data.
What data did ShinyHunters steal, and how was it used?
DOJ says the data in the Raoult case included personal and financial information. The announcement describes a method in which conspirators used phishing pages to capture login credentials, then used those stolen credentials to access company and third-party data.
#1 Best Overall
Some victims also faced extortion threats: DOJ says ShinyHunters sometimes threatened to leak or sell sensitive files if a victim did not pay. That description applies to the historical case; it should not be treated as proof that every incident associated with the name followed the same pattern.
Sarah Vogel, Criminal Chief for the U.S. Attorney’s Office for the Western District of Washington, said: “For over two years, Mr. Raoult participated in extensive computer hacking that caused millions of dollars in losses to victim companies and unmeasurable additional losses to hundreds of millions of individuals whose data was sold to other criminals.”
What does the FBI say about later alleged ShinyHunters activity?
The FBI’s May 15, 2026 alert concerns an incident involving a learning management system (LMS), a distinct matter from the Raoult prosecution. The FBI says information stolen in that incident could be sold or reused to impersonate school faculty, IT support, or financial-aid offices. The alert warns about possible misuse; it does not mean every person contacted by someone claiming to represent a school is part of the incident.
A separate FBI arrest announcement says Dutch police arrested an alleged leader and describes alleged activity by the suspect and co-conspirators involving breaches at more than 140 organizations and at least $70 million in extortion payments since the previous year. The announcement page’s captured text does not state its publication date, so the phrase “since the previous year” cannot be converted here into a reliable calendar-year range. These are allegations described by the FBI, not findings from the Raoult case.
FBI Cyber Division Assistant Director Brett Leatherman said: “They often target third-party vendors in cloud-based platforms, stealing sensitive data and extorting victims with threats to publish it.” The FBI’s descriptions of later alleged activity should not be read as proof that every person or incident using the ShinyHunters name is part of one continuous group. The FBI arrest announcement and transcript provide the agency’s account.
Was your information affected?
A sale listing or an attacker’s claim does not, by itself, establish that a particular person’s data is in the material or that it is accurate. For the LMS incident, the FBI advises people to wait for formal guidance from their educational institution about the incident’s scope and which data may have been affected. Follow official notices from the institution rather than assuming that a message, post, or offer for sale proves your information was exposed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should you do after a data breach or suspicious contact?
The FBI’s May 15, 2026 LMS advisory recommends these steps for potentially affected individuals:
- Wait for your educational institution’s formal guidance about the incident and potentially affected information.
- Verify urgent or unusual requests that claim to involve your personal data through a separate, known communication channel. Do not reply to the message or use contact details supplied in it to verify the claim.
- Be cautious with unsolicited emails, calls, and texts. Avoid suspicious links and unexpected attachments, and verify contacts through channels you already trust.
- Do not pay or respond to demands.
- Contact the providers of accounts that may be affected to regain control, change passwords, and set alerts for suspicious logins or transactions.
- Report suspected intrusions to the FBI’s Internet Crime Complaint Center (IC3).
The FBI says it does not endorse commercial entities, products, or services. No service can be assumed to undo a breach or remove every copy of stolen information.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsQuick Recap
Best Value
What the public record does—and does not—establish
- Established in the Raoult case: DOJ documented historical sales postings, credential theft, stolen personal and financial information, and extortion threats tied to the conduct described in its 2024 sentencing announcement.
- Described as alleged by the FBI: The later arrest announcement reports alleged breaches and extortion payments attributed to a suspect and co-conspirators.
- Not established by these sources: A complete count of ShinyHunters listings, a measure of the current dark-web market, or proof that every later actor using the name is the same person or group.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

