Sunday, 16 August 2026
The Verified Journalism Press

Journalism with its sources attached.

Sections
WORLD
AUSTRALIA
INDIA
BUSINESS
TECHNOLOGY
SCIENCE
SOCIETY
RIGHTS
CORRUPTION
CULTURE
OPINION
FAMOUS
The Press
Latest
Brussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached AustraliaBrussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached Australia
Markets
ASX 200
S&P 500
Nasdaq
FTSE 100
Nikkei
Gold
Brent
AUD / USD
AUD / EUR
AUD / GBP
AUD / JPY
Bitcoin
Ethereum
Yahoo · ECB · CoinGecko

Front page / Technology

Security

ShinyHunters is named in Canvas, Carnival, Medtronic and RingCentral, and Google says it was not a vendor flaw

Four breaches reported as separate corporate failures between April and August 2026 share an attributed crew. Google Threat Intelligence has said the activity is not the result of a vulnerability in vendors' products. Published victim counts for the same events differ by millions.

Holland America Line cruise ship viewed from A'DAM Tower
Holland America Line cruise ship viewed from A'DAM Tower. Photograph: APK, CC BY-SA 4.0

Between April and August 2026, four organisations with almost nothing in common disclosed data breaches: a learning management platform used by schools, a cruise operator, a medical device maker and a business telephony provider. Instructure, Carnival Corporation, Medtronic and RingCentral were covered largely as separate corporate accidents. In each case the extortion group named is ShinyHunters.

The common thread is not a shared product. Google Threat Intelligence, quoted in a breach tracker maintained by State of Surveillance, has assessed that this activity is not the result of a security vulnerability in vendors' products or infrastructure and that it continues to highlight the effectiveness of social engineering. A technical analysis published by the vendor Push Security on 8 May 2026 sets out the mechanics: voice phishing calls impersonating IT support, often citing a mandatory passkey rollout or a security compliance update; adversary in the middle phishing pages that relay credentials and multi factor codes to the legitimate identity provider as they are entered, capturing the resulting session token; and device code phishing that abuses the OAuth 2.0 device authorisation grant. Push Security's argument is that device code phishing defeats all multi factor authentication including passkeys because the attack does not target the login, it targets the authorisation layer. A third pattern, OAuth supply chain compromise, uses tokens stolen from an integration vendor to query the tenancies of everyone that vendor serves. The 2025 Salesloft and Drift compromise worked that way, and Push Security records a comparable Anodot compromise in April 2026.

The individual incidents are documented, but the numbers attached to them are not stable. Instructure, which operates Canvas, was accessed in late April 2026. UpGuard dates initial access to 29 April 2026, initial disclosure to 1 May 2026 and containment to 6 May 2026. The Hacker News reported a second wave of activity detected on 7 May 2026 involving defacement of login portals at roughly 330 institutions, and a ransom agreement the company confirmed in reporting dated 12 May 2026. The stolen volume is put at 3.65 terabytes and roughly 275 million records across close to 9,000 institutions, covering usernames, email addresses, course names, enrolment information and messages, with course content, submissions and credentials said not to have been compromised. Instructure has stated it reached an agreement with the unauthorised actor and that the data was returned to it along with digital confirmation of destruction, a claim the company makes about itself and which no third party can verify. The State of Surveillance tracker notes the company paid despite standing FBI advice against it and that companies in this position cannot verify whether stolen data was actually destroyed or already copied elsewhere.

Carnival is the clearest example of the counting problem. Have I Been Pwned added a Carnival breach on 24 April 2026 covering 7.5 million unique email addresses within 8.7 million records, and attributes the data to the Mariner Society loyalty programme run by Holland America, a Carnival brand. UpGuard records a different figure, 5,995,277 people, drawn from Carnival's filing with the Maine Attorney General, for a breach it dates to 10 April 2026 and a disclosure in May 2026. Security Boulevard's summary reconciles the spread: roughly 6 million individuals notified by Carnival, 8.7 million records claimed by the attackers, and about 7.5 million loyalty accounts identified by Have I Been Pwned. These are not the same measurement. Carnival has acknowledged, per that summary, a social engineering attack against a single employee account that opened a path into its IT systems.

Medtronic's timeline is tight. The company has said it became aware of unusual activity on certain corporate IT systems on 15 April 2026, with unauthorised access running from 13 to 19 April 2026. BleepingComputer reported that ShinyHunters listed Medtronic on its dark web portal on 18 April 2026 with a ransom deadline of 21 April 2026, that the listing was later removed and the data was not exposed online, and that customer notifications went out around 2 July 2026. Roughly 9 million records are involved, including names, contact details, dates of birth, Social Security numbers and health related information. Medtronic states that all its devices remain safe to use and are not affected by the incident, which is the company's own assessment. Medtronic has not disclosed how the intruder got in, and this masthead could not verify the widely repeated claim that it filed a Form 8-K on 24 April 2026.

RingCentral is the most recent. The Register reports the breach was disclosed on 28 July 2026, that the attackers set an extortion deadline of 30 July 2026, and that the data was dumped publicly on 3 August 2026 after RingCentral did not pay. The confirmed scope is about 1.6 million unique email addresses, with names, physical addresses and phone numbers. ShinyHunters claims far more: 623 gigabytes, 30 million rows of customer information, more than 1 million Social Security numbers, and more than 22 million rows of client notes containing confidential doctor and patient conversations. Those are the attackers' claims and are unverified. RingCentral says it has not seen any new unauthorised activity since taking remediation steps. The Register reports that entry was gained by voice phishing an employee into handing over a password.

What remains unresolved is whether these are one campaign or a brand. ShinyHunters is described by Push Security as the product of a merger of Scattered Spider, Lapsus$ and ShinyHunters within the Com, a broader community of English speaking cybercriminals. Attribution to a name in that setting does not establish that the same people ran all four operations. What the evidence does support is narrower and more useful to defenders: in the three cases where an entry vector has been disclosed, Instructure, Carnival and RingCentral, it was the credential and authorisation layer, and on Google's assessment no vendor patch would have closed it.

Sources

Every factual claim above rests on the 9 published sources below. They are listed so you can check the reporting rather than take it on trust.

  1. Push SecurityAnalyzing the Instructure breach
  2. The Hacker NewsInstructure reaches ransom agreement after Canvas data theft
  3. Have I Been PwnedCarnival breach
  4. BleepingComputerMedtronic notifies customers impacted by ShinyHunters data breach
  5. The Register1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
  6. State of SurveillanceShinyHunters 2026 breach tracker: Salesforce, Carnival, Canvas campaign
  7. UpGuardThe biggest data breaches in US history
  8. Security Boulevard2026 data breaches and cybersecurity incidents explained
  9. Tech.coData breaches: an updated list

The Verified Briefing

One email each morning. Every story in it carries its sources, so you can check the reporting before you repeat it.

No tracking pixels. One click to leave.