Cybercrime update graphic showing ShinyHunters and criminal forums trends.

Cybercriminals Create New Forums and Interrupt School Finals

Table of Contents

Check your exposure

With summer basically upon us, it seems bad actors have also been counting down the days until the end of the school year. In this month’s cybercrime update, we dig into:

Let’s dig in.

ShinyHunters hacks Canvas during finals season

In early May, ShinyHunters (a data-theft extortion group linked to the COM), claimed responsibility for a breach of Instructure, the parent company of Canvas. Instructure confirmed the incident and disclosed that the exposed data included names, email addresses, student ID numbers, and messages among users, while stating it found no evidence that passwords, birth dates, government IDs, or financial information were involved. Canvas is the most widely used learning management system in US higher education, where roughly 41% of institutions run it.

ShinyHunters also used their access to push pop-up messages to Canvas users that pressured individual schools to negotiate directly with the criminal group to prevent the release of their data. They leveraged their access to Canvas’ central infrastructure as a means of directly communicating with students and teachers, echoing the scare tactics of more traditional ransom notes, which are frequently deployed across every endpoint in a corporate network by ransomware actors. Days earlier, ShinyHunters had published a list of over 8,000 educational institutions that they claimed to have stolen from using their access to Canvas.

Cybersecurity alert about data breach and security patches from SpyCloud.

Pop-up message displayed to students on Canvas. Screenshot was posted by a student to the University of Washington subreddit (r/udub) on May 7.

Instructure announced that they had “reached an agreement” with ShinyHunters before any data was released publicly. The company also stated that the hackers returned the data and provided deletion confirmation, that the agreement covers all impacted customers, and that no Instructure customer will be separately extorted as a result. This incident highlights a few key tactics which enhanced ShinyHunters’ extortion attempts:

BlavoForums employs guerrilla marketing tactics

The owner of a new data breach forum called “BlavoForums” (seemingly a misspelling of Bravo) is aggressively promoting their new forum by posting about breached datasets to other forums. When users use their forum credits on third-party forums like DarkForums to unlock a hidden link to the dataset (which is generally populated with a file download link), they instead find a link to a post on BlavoForums. This second post then requires users to make a new BlavoForums account and acquire BlavoForums tokens to unlock an actual link to the promised data.

SpyCloud cybersecurity platform displaying data breach monitoring and threat detection tools.

Post on DarkForums with a blavo[.]is link in the hidden content area.

Cybersecurity breach at Keybase AI Platform exposing sensitive customer data and credentials.

Post on BlavoForums about the same breached database. It requires BlavoForum credits (here called “tokens”) to unlock the actual download link for the full leak.

Only time will tell whether this somewhat annoying traffic generation tactic will prove effective in funneling new users to Blavo. In the meantime, we will keep an eye out for posts on third party forums that state they are “By BlavoForums” – we anticipate future posts will likely follow this pattern

Another update in the Forum Wars

A schism in Hasan’s BreachForums

On May 20, some of the forum administrators on Hasan’s BreachForums took control of the forum and moved the backend over to another domain: breached[.]su. In an announcement on Hasan’s BreachForums (breached[.]st), one of these administrators – diencracked – claimed that Hasan acted abusively towards other forum staff and consistently took credit for their work. As of the time of this writing, the forum appears to be live at the new .su domain, while the old .st domain appears to have been reclaimed by Hasan and now redirects to https[:]//t[.]me/breaches, one of Hasan’s Telegram channels.
SpyCloud cybersecurity platform for data breach prevention and threat detection.

Announcement from May 20 directing forum members to a new domain and “exiling” Hasan from the forum.

SpyCloud cybersecurity platform for data breach detection and threat prevention.

List of staff members on  breached[.]su. Hasan and many other administrators, like VECT, were removed.

On breached[.]su, old posts made by Hasan’s profile label his account as “exiled.” Hasan responded to the coup in posts across Telegram and X/Twitter, stating that he had been “betrayed” by the other forum staff while he was “on a trip.” In further posts, he stated that the offending staff members were “all basically sewer rats who came out of nothing” and owed their “entire careers” to Hasan.

Cybersecurity platform logo with SpyCloud branding and character illustration.
Hasan’s profile on breached[.]su, showing his account status as “exiled.”

Hasan doubles down on doxxing

Hasan also appears to be expanding more heavily into doxxing, creating a new doxbin called DoxByte alongside another actor with the moniker Jayze. Hasan also declared that the jacuzzi telegram channel was now “the main chat for BREDOX [ Breached and DoxByte Coalition ].” (Note: Doxbin was originally the name of a specific website focused on doxxing, but now the term broadly refers to any forum, chat, or channel devoted to doxxing.)
Cybersecurity platform showcasing SpyCloud's data security solutions and threat intelligence.

Homepage of the new DoxByte website recently launched by Hasan and Jayze.

Cybersecurity coalition BREDOX logo representing collaboration and security.

Telegram message from Hasan regarding “PROJECT BREDOX.”

New research and insights from SpyCloud

Attackers are finding new ways to make MFA irrelevant, and device code phishing is their latest weapon. This adversary-in-the-middle (AiTM) technique exploits the legitimate OAuth 2.0 Device Authorization Grant flow, tricking users into entering an attacker-generated code that issues active session tokens directly to the attacker’s device. Refresh tokens remain valid for up to 90 days and survive password resets, meaning explicit token revocation is the only true remediation, but it’s a step most IR playbooks don’t yet account for. Here’s what you need to know.

Google’s Device Bound Session Credentials (DBSC) is now generally available in Chrome on Windows, marking a meaningful step forward in the fight against session hijacking. It’s a welcome one, especially given the scale at which we recapture stolen cookie and token records from the criminal underground. But DBSC does not protect refresh tokens, nor does it address device code phishing. It also doesn’t yet cover macOS, mobile, or non-Chrome browsers, and requires server-side implementation by website owners. Long story short, security teams still need visibility into stolen refresh tokens, infostealer-exfiltrated auth data, and phished data. Get the full scoop.

The newly-released 2026 Verizon Data Breach Investigations Report reinforces that identity is the throughline of every major attack pattern. Stolen credentials appear in 39% of all breaches, and 73% of ransomware victims had an infostealer infection or credential leak in the year before their attack, with half of those occurring within 95 days of the ransomware incident. Third-party breaches jumped 60% year over year, driven largely by authentication failures like missing or misconfigured MFA. Read the full recap.

Recaptured data numbers for May 2026

May monthly total

Total New Recaptured Data Records for May:
2,997,408,282

New third-party breach data this month

Third-Party Breaches Parsed and Ingested:
2,810
New Data Records from Third-Party Breaches:
1,934,475,834

New recaptured phished data this month

New Phished Data Records:
4,259,096

New infostealer malware data this month

Stealer Logs Parsed and Ingested:
7,094,453
New Data Records from Stealer Infections:
139,170,101
New Stolen Cookie Records:
923,762,347

Discover what cybercriminals know about your business and your customers – and how to prevent targeted attacks with SpyCloud.

Keep reading

Illustration of device code phishing attack bypassing multi-factor authentication.
Device Code Phishing: The AiTM Attack That Bypasses MFA
Device code phishing is a fast-growing adversary-in-the-middle (AiTM) attack that exploits OAuth 2.0 device flow to harvest access and refresh tokens — bypassing MFA. SpyCloud Labs researchers break down how it works, what attackers do with stolen tokens, and how to detect and shut down compromised sessions.
Cybercrime update graphic showing ShinyHunters and criminal forums trends.
ShinyHunters, Supply CHAINS$ & Sketchy New Criminal Forums
Read on for the latest in supply chain compromises, cloud account takeovers, and breach forum shake-ups as we break down the biggest cybercrime trends of the month, including attacks by TeamPCP and ShinyHunters.
Cybercrime update graphic showing SpyCloud data security and threat trends.
March Cybercrime Update: RATs, Ransomware & Arrests
This month's cybercrime update covers a forum takedown, ransomware-style extortion from unexpected threat actors, and a state-sponsored campaign hitting close to home.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.

Going passwordless changes your attack surface. Explore session hijacking prevention

X