Kodak Breached by ShinyHunters: The Extortion Group That Won't Stop Until Every Enterprise Platform Is Hit
ShinyHunters claimed 2.2M Kodak records with a June 18 leak deadline. The group has breached Snowflake, Salesforce, Canvas, PeopleSoft, and now Kodak.

ShinyHunters claimed to have stolen 2.2 million customer and corporate records from Eastman Kodak in June 2026. The group listed Kodak on its dark web leak site on June 15, set a June 18 deadline, and threatened to publish the data if no payment was received. Kodak confirmed that an unauthorized third party temporarily accessed a limited amount of company data, engaged external cybersecurity experts, and stated there was no ongoing threat to its systems.
By itself, the Kodak breach is a mid-size corporate data theft. In context, it is another entry in ShinyHunters' 2026 campaign that has become the most prolific mass-exploitation operation in recent cybercrime history.
The ShinyHunters 2026 Scorecard
The operational tempo is staggering. In eighteen months, ShinyHunters has executed mass exploitation campaigns against Snowflake-connected environments (2024, breaching Ticketmaster, Santander, and dozens of others), Salesforce Experience Cloud (March 2026, hundreds of organizations via misconfigured Aura endpoints), Canvas LMS (May 2026, 275 million student records), Oracle PeopleSoft (June 2026, 100+ organizations via CVE-2026-35273), and individual targets including Kodak, the Vercel listing, and numerous others.
The pattern has matured into a repeatable playbook. Identify a vulnerability in a widely deployed enterprise platform. Automate exploitation at scale. Exfiltrate data from dozens or hundreds of victims simultaneously. Set short deadlines for ransom payment. Publish data from non-paying victims.
What makes ShinyHunters particularly effective is their willingness to target platforms rather than individual organizations. By finding a single vulnerability in Oracle PeopleSoft, they compromised 100+ organizations. By targeting Snowflake-connected environments, they breached companies across every industry. The economics favor the attacker: one vulnerability, hundreds of victims, hundreds of ransom demands.
What Organizations Should Learn
Assume your platforms are targets. Every enterprise SaaS platform, ERP system, and cloud environment in your stack is a potential ShinyHunters target. Review the security of each platform, the exposure of each deployment, and the access controls protecting each one.
Prepare for extortion as a business process. ShinyHunters' short deadlines are designed to force rushed decisions. Organizations should have pre-established positions on ransom payment, legal counsel on retainer, and communication plans ready before the demand arrives. The Canvas LMS breach demonstrated that paying the ransom does not protect the data.
Invest in detection that catches mass exploitation. ShinyHunters' automation produces distinctive patterns: rapid scanning, bulk data access, and exfiltration from multiple systems simultaneously. Security monitoring tuned for these patterns can detect campaigns in progress, even when the specific vulnerability is unknown.
Prioritize credential hygiene across every platform. Multiple ShinyHunters campaigns have exploited credential issues: stolen credentials (Snowflake), misconfigured authentication (Salesforce), and unauthenticated access (PeopleSoft). Enforcing phishing-resistant MFA across every enterprise platform eliminates the credential-based attack paths that ShinyHunters frequently exploits.
Key Takeaways
- ShinyHunters claimed 2.2 million Kodak customer and corporate records in June 2026, with a June 18 leak deadline
- This is part of ShinyHunters' 18-month campaign that has hit Snowflake, Salesforce, Canvas LMS, Oracle PeopleSoft, and dozens of individual targets
- ShinyHunters' playbook targets widely deployed platforms rather than individual organizations, achieving massive scale from single vulnerabilities
- The group has demonstrated consistent operational capability across cloud environments, SaaS platforms, and on-premises ERP systems
- Organizations should prepare for extortion as a business process and invest in detection that catches mass exploitation patterns
Deepak Gupta is the co-founder and CEO of GrackerAI. He previously founded a CIAM platform that scaled to serve over 1B+ users globally. He writes about AI, cybersecurity, and digital identity at guptadeepak.com.
Get the newsletter
New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.