SYS::ONLINE
Wasteland.
Briefs2196
Issues24
SinceFeb 2026
LIVE
▣ Breach BOK-FINANCIAL-SHIN 2026-08-23

BOK Financial: ShinyHunters Data Extortion Deadline

"BOK Financial, the roughly $50 billion-asset US regional bank, was added to the ShinyHunters extortion leak site on August 22, 2026, alongside a countdown expiring at end of day August 24. The listing carries a short…"

BOK Financial, the roughly $50 billion-asset US regional bank, was added to the ShinyHunters extortion leak site on August 22, 2026, alongside a countdown expiring at end of day August 24. The listing carries a short, characteristically blunt note: "This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline." That text is reproduced identically by Malware News and HookPhish, both working from the same public leak-site scrape. As of this writing BOK Financial has issued no public statement, no regulatory filing has surfaced, and no established security outlet has independently confirmed an intrusion. Everything below about BOK Financial specifically rests on OTHER-tier threat-feed monitoring, and should be read that way.

What Happened

Threat-monitoring feeds picked up the BOK Financial entry on August 22. UNDERCODE NEWS, citing the ThreatMon team, places the sighting at approximately 17:13 UTC+3 on August 22, and reports that a second victim, the healthcare and oncology device firm NovoCure Limited, was posted within seconds of it. HookPhish independently logs its discovery timestamp as 14:13:39 UTC on August 22, which is the same moment in a different timezone, so at minimum two monitoring services observed the same posting event. HookPhish additionally records a "date of breach" of 11:10 UTC on August 22, but that field almost certainly reflects feed ingestion or listing metadata rather than the date of actual intrusion; ShinyHunters typically lists victims weeks to months after the underlying access. No source in this set establishes when BOK Financial was actually compromised.

The near-simultaneous BOK Financial and NovoCure posts fit the group's documented pattern of publishing victims in coordinated bursts rather than one at a time, which is consistent with a batch of intrusions that reached the end of a negotiation window together.

One framing correction worth making up front: both Malware News and HookPhish file this under "ransomware." Nothing in the available reporting indicates encryption, and every well-sourced ShinyHunters case in this campaign has been theft-and-extortion with no encryptor deployed. The leverage is publication, not downtime.

What Was Taken

Unknown. This is the single most important gap in the story. Not one of the eight sources states a record count, a data category, or a system of origin for BOK Financial. Any figure circulating for this victim is not supported by the reporting available here.

What the campaign's earlier victims establish is what a ShinyHunters haul of this type usually looks like. For Brinks Home, BleepingComputer reported the group's own claim of more than 4.9 million Salesforce records containing PII, broken down as more than 1.1 million rows from the Salesforce "Contacts" object, more than 4,000 rows of employee PII including full names, email addresses, job titles and phone numbers, and more than 3.8 million customer support chat logs from a Brinks Care Cresta instance. Persprotect's tracker, by contrast, lists the Brinks Home set that actually reached public breach databases at 732,162 records covering dates of birth, email addresses, names and partial credit card data. Those two numbers are not reconcilable as stated, and the gap is instructive: attacker-claimed volume of roughly 4.9 million (ShinyHunters, via BleepingComputer) versus indexed published records of 732,162 (Persprotect) is close to a sevenfold difference. Treat any attacker-stated volume for BOK Financial, if one appears, as an unverified ceiling.

Persprotect further reports that 33 companies have had records published in this campaign to date, holding roughly 72 million email addresses between them across indexed sets, with recent additions including Exact Sciences at 10.9 million email addresses, Houston City College at 831,642 records, Inter-Con Security at 276,114, and Alcon at 218,395. That figure is single-source and OTHER-tier, so treat it as directional scale rather than a confirmed total.

What Remains Unconfirmed

Accounts here do not conflict so much as thin out. The four sources touching BOK Financial (two UNDERCODE NEWS pieces, Malware News, HookPhish) all derive from leak-site monitoring, largely from the same ThreatMon observation, and none of them reflects contact with the bank, a breach notification, an SEC filing, or a state attorney general disclosure. There is no independent confirmation that BOK Financial data was actually exfiltrated, and leak-site listings have historically included claims that were exaggerated, recycled from other breaches, or withdrawn.

What is well established is the campaign around it. Microsoft's July 13 research, the strongest source in this set, documents sustained ShinyHunters-associated activity from mid-2025 through mid-2026. BleepingComputer has separately confirmed two named victims with company acknowledgment: Ernst & Young, which disclosed a compromised third-party IT service management platform, and Brinks Home, which confirmed an intrusion identified on July 20 and engaged outside forensics. The pattern is real; BOK Financial's place in it is claimed.

Why It Matters

The deadline structure is the product. As UNDERCODE NEWS frames it, a public countdown converts an incident into a countdown, applying pressure simultaneously to executives, incident responders, customers, investors, regulators and partners. The Ernst & Young listing used the same mechanic with a July 31 deadline; BOK Financial's is August 24. The interval between listing and deadline is short by design, compressing the window in which a victim can verify the attacker's claims before deciding whether to engage.

For a bank, the calculus is worse than for most sectors. A regional institution of BOK Financial's size sits under GLBA safeguards obligations, FFIEC examination, SEC Item 1.05 materiality disclosure requirements, and a patchwork of state notification laws with clocks that start on determination rather than on a leak. Customer contact data from a bank's CRM is also unusually weaponizable: a caller who knows your banker's name, your branch and your recent service ticket clears the credibility bar for a bank-impersonation call almost automatically. Persprotect makes this point well for the campaign generally, noting that what leaks is identity rather than logins, so the downstream risk is a convincing contact rather than an account takeover.

The broader signal for defenders is that the highest-value data in this campaign has not lived in the core banking platform. It has lived in Salesforce, in support-ticket systems, and in chat transcript stores, none of which typically receive core-system monitoring or retention discipline.

The Attack Technique

Microsoft's research is the authoritative account of how this group operates, and it identifies two primary intrusion paths. The first is vishing aimed at OAuth consent: a phone call that walks an employee through authorizing a malicious connected application or completing an authentication flow. The second is supply chain compromise through trusted workflows and integrations, with Salesloft and Gainsight named explicitly. Both paths yield inherited user and application privileges, letting the actor enumerate and query CRM records while evading conventional authentication detections, because from the platform's perspective the access is an authorized integration behaving normally. Microsoft is unambiguous that this was not a Salesforce vulnerability but abuse of trusted OAuth relationships, and notes the activity spanned tenants in retail, education and manufacturing.

The confirmed victims map cleanly onto those two paths. ShinyHunters told BleepingComputer they breached Brinks Home on July 13 via a Microsoft Entra vishing attack, calling an employee and walking them through an Entra authentication or registration process to capture account access. For Ernst & Young, the group claimed to BleepingComputer that credentials came from a supply-chain attack on an unnamed third party and were used to reach EY's Jira, GitHub and Azure environments; EY's own notification says it detected unusual activity on April 23 and determined the attacker had access to a third-party IT service management platform between March 28 and April 12, downloading multiple documents. Note the dwell profile: roughly two weeks of access, detected eleven days after it ended, publicly extorted three months later.

No intrusion vector has been reported for BOK Financial. Given the campaign profile, OAuth consent abuse and third-party integration compromise are the hypotheses worth testing first, but that is inference, not reporting.

What Organizations Should Do

  1. Inventory and prune connected OAuth applications in Salesforce, Microsoft Entra and every major SaaS tenant. Pull the full list of authorized apps, their scopes, their consent dates and who granted them. Anything with broad API read scope that no one can attribute to a business owner should be revoked now, not after review.

  2. Disable user-level app consent. Route all OAuth grants through an admin consent workflow. The vishing path Microsoft documents fails outright if a called employee lacks the authority to authorize an application.

  3. Turn on Salesforce Event Monitoring and alert on bulk query behavior. Microsoft states it worked with Salesforce to improve telemetry granularity for Defender for Cloud Apps, including near-real-time detection with connected-application attribution and expanded permission insights. Baseline normal API record volume per integration and alert on deviation; mass enumeration of the Contacts object is the signature to catch.

  4. Extend third-party risk review to integration vendors, not just data processors. Salesloft, Gainsight and ITSM ticketing platforms were the entry points in confirmed cases. Ask each vendor what tenant access their integration holds, whether their tokens can be rotated on demand, and how they would notify you of a compromise.

  5. Harden the helpdesk against voice social engineering. Require callback verification on a known-good number for any MFA reset, device registration or authentication assistance request. Run vishing simulations, not just email phishing tests, because the observed tradecraft is telephonic.

  6. Treat support tickets and chat transcripts as regulated data. The EY case turned on tax documents attached to IT tickets; the Brinks case included 3.8 million chat logs per the group's own claim. Apply retention limits, redaction and access controls to these stores at the same level as your customer database.

  7. For financial institutions specifically, pre-stage the disclosure decision. Have counsel, forensics and communications aligned on what evidence would constitute confirmation of exfiltration and what would trigger materiality determination, before a 48-hour countdown starts.

Sources: ShinyHunters Gives BOK Financial Until August 24: A Ransomware Dead... | Defending SaaS-based applications against ShinyHunters ... | Ernst & Young data breach claimed by ShinyHunters extortion gang | ShinyHunters claims Brinks Home breach, threatens to leak stolen data | ShinyHunters Targets BOK Financial and NovoCure in New Dark Web Lis... | ShinyHunters Breaches BOK Financial - Malware News | Ransomware Group shinyhunters Hits: BOK Financial | The ShinyHunters “Pay or Leak” Breaches: Every Company Named (2026)