ShinyHunters claims release of files from four dating apps

THE BRIEF
CSO Online reports that extortion group ShinyHunters has released tens of gigabytes of files it claims were stolen from dating services Hinge, Match, OkCupid, and Bumble. The report says there is no official confirmation of how the companies were breached. Researchers cited by CSO believe the group’s activity may have contributed to a recent Okta advisory describing a rise in voice-based social-engineering attacks supported by automated phishing kits. The report places the dating-service disclosures alongside earlier posts claiming data from SoundCloud, Crunchbase, Betterment, CarMax, Edmunds.com, and Panera Bread, and says the list of alleged victims could grow. ShinyHunters, also tracked as UNC6040, has operated since 2020 and is described as having stolen data from many well-known brands and organizations. Its known techniques include impersonating IT staff to compromise employee accounts. The report does not establish that any named company was breached or confirm the authenticity, scope, or contents of the released files.
WHY IT MATTERS
The report connects alleged data releases at several services with a warning about voice-based social engineering. Even without official confirmation of the breach paths or the files’ authenticity, the account-compromise technique described—impersonating IT staff—illustrates why employees can be targeted through trusted support channels. Organizations should treat the report as an unverified signal to reassess how voice requests, phishing kits, employee identities, and third-party access are handled, while avoiding assumptions about which companies or records were affected.
WHO SHOULD CARE
Security leaders, identity and access teams, help desks, fraud teams, and privacy professionals at organizations using employee phone or voice support channels should care. The named organizations should follow official disclosures rather than rely on claims alone.
WHAT TO DO NOW
- Review the recent Okta advisory and compare its voice-based social-engineering scenarios with current controls.
- Require independent verification for callers claiming to be IT staff before account or access changes.
- Audit employee-account protections and monitor for unusual support-driven login or recovery activity.
- Track official statements from the named companies and preserve relevant records without treating the reported file release as verified.