ZeroFox Intelligence Flash Report - ShinyHunters Continues Shift to Encryption-Less Data Theft
|by Alpha Team

ZeroFox Intelligence Flash Report - ShinyHunters Continues Shift to Encryption-Less Data Theft
Product Serial: F-2026-09-16a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on recent activity from threat actor ShinyHunters, which points to a continuing shift away from encryption towards an encryption-less data extortion model. ## Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On September 10, 2026, threat actor group ShinyHunters leaked data from McKesson Corporation (McKesson) on its dark web leak site. The data allegedly came from an August 2026 breach of 6.4 million personally identifiable information (PII) records associated with McKesson.
- Neither the public disclosures nor the ShinyHunters claim mentioned ransomware or encryption, making it very likely the group did not encrypt McKesson data; instead, ShinyHunters very likely extracted the data, issued a ransom demand, and then almost certainly leaked the data when the victim refused to pay.
- ZeroFox assesses that the lack of encryption in the McKesson breach was almost certainly intentional and very likely represents a tactical shift by ShinyHunters from double extortion to encryption-less data theft.
- The ShinyHunters data breach of McKesson and the subsequent release of sensitive data almost certainly reflect the continuation of the shift in the ransomware and digital extortion (R&DE) ecosystem from encryption-based attacks to “encryption optional” data extortion.
Tags: tlp:clear, dark web, threat actor