Hacker group ShinyHunters claims it has breached ten companies, including dating app Zoosk, and is selling their 73M+ user records on a dark web marketplace
Hacker group “ShinyHunters” is selling the data of 10 companies on a dark web cybercrime marketplace.
Context & Ripple Effects
ShinyHunters' May 2020 spree starts here: ten claimed breaches, Zoosk named, and 73M+ user records listed for sale rather than dumped free — a monetization choice that defines the group. Within two weeks, researchers had tallied what the group claimed was roughly 200M stolen records across at least 13 companies, confirming this was a campaign, not a one-off.
The throughline matters because the same brand resurfaces four years later at far larger scale, offering alleged Santander customer data for sale after Santander itself confirmed a compromised database and claiming 560M Ticketmaster records with an asking price of $500K. This early marketplace listing is the template those later sales follow.
First-order effects
- Zoosk and the nine other named companies face immediate breach-notification obligations and credential-exposure risk for tens of millions of users whose emails and passwords are now purchasable.
- Dark web buyers gain cheap bulk access to consumer credentials, with dating-app accounts among the most valuable for follow-on fraud and account takeover.
Second-order effects
- Every consumer app in adjacent categories gets pushed toward forced password resets and credential-stuffing defenses as purchased records are tested against other services.
- The sell-don't-leak pricing model established here becomes the negotiating posture the group later uses against enterprises like Ticketmaster, where stolen data is quoted at a dollar figure instead of released.
Third-order effects
- If the pattern holds from 2020's bulk listings to 2024's targeted corporate extortion, breach-and-auction hardens into a repeatable business model, shifting attacker incentives from disruption toward inventory management of stolen data.
- Regulators and enterprise buyers respond by treating third-party cloud and SaaS databases — Salesforce instances, staff directories — as primary breach surfaces, since the group's later targets were reached through such systems.
The trend: Data theft is consolidating around branded groups that treat stolen records as priced inventory, evolving from bulk marketplace dumps to negotiated enterprise extortion.