The ShinyHunters extortion collective added Kimberly-Clark, the Texas-based Fortune 500 maker of Kleenex and Huggies, to its leak site on September 13, 2026. The listing was labelled a "final warning" and gave the company until September 16 to make contact before the group would leak data and cause "several annoying (digital) problems." Nobody has confirmed a breach. Kimberly-Clark has made no public statement. BreachNews and Shieldworkz (cited by DataBreach.com) found no Form 8-K cybersecurity disclosure. All eight sources behind this brief are third-tier: leak-site trackers, aggregators and vendor blogs. Most of them repeat the same leak-site post. A web search on October 4 found only more reposts of that listing (for example hendryadrian.com and DeXpose). It found no statement from the company, no regulator filing and no outlet confirmation. One breach indexer, DataBreach.com, now lists a dataset of about 649,000 rows that it links to the claim. We treat that as unverified until Kimberly-Clark or a primary source confirms it.
What Happened
Most trackers agree on the timeline:
- September 13, 2026: ShinyHunters posted Kimberly-Clark (kimberly-clark.com) to its leak site, according to Yazoul, DeXpose, Undercode News and Ransomware.live (as cited by DataBreach.com). BreachNews says the listing was "updated Sept. 13," so it may have existed in an earlier form.
- The demand: DeXpose quotes the post in full: "This is a final warning to reach out by 16 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline."
- September 14: BreachNews reported that Kimberly-Clark had made no statement and found no evidence of operational disruption.
- September 16: The deadline passed. None of the sources reports a confirmed leak or any disruption on or after that date.
- September 29 to 30: DataBreach.com added a dataset it says is linked to Kimberly-Clark, with an attack date of September 13.
Sources describe the incident differently. Breachwire and DeXpose call it a "ransomware" attack, and Breachwire's October 4 post lists a "confirmed impact." Yazoul, BreachNews and ProvenData describe ShinyHunters as a data-theft and pay-or-leak group, not a group that encrypts files. Nothing in the sources shows that any Kimberly-Clark systems were encrypted. Breachwire's use of "confirmed" refers to the threat of a leak, not a verified compromise. Yazoul goes further: it notes that no proof of access came with the listing and warns that the ShinyHunters name is sometimes borrowed by copycat operators.
What Was Taken
When the listing went up, ShinyHunters gave no data volume, file tree, sample or proof of access. BreachNews and Yazoul both noted this.
The only figures come from DataBreach.com, and they differ even within its own page:
- 649,558 rows in its summary field
- About 648,820 records / individuals in its write-up, including full names for 648,820 people and street addresses for 476,025
- Other listed fields: phone numbers and vehicle licence plates
The fields look like consumer or customer contact records, not corporate or operational data. That would fit ShinyHunters' recent habit of stealing CRM and SaaS data, but nobody has independently matched the dataset to Kimberly-Clark systems. DataBreach.com itself says public reporting is "limited." Until Kimberly-Clark confirms it or sends breach notifications, the record count and data types are one indexer's claim.
Why It Matters
- ShinyHunters is a credible, active brand. ProvenData and Mitiga document campaigns since 2020 against Salesforce, Okta, Snowflake, Microsoft 365, Google Workspace, PeopleSoft and Canvas. Mitiga tracks the group as UNC6040; ProvenData cites MITRE's mapping to UNC6240 and Bling Libra. ProvenData also reports that the group claimed in September 2026 to have breached the FBI's FBIJobs.gov portal, which the FBI says it is investigating.
- A named listing is not proof. In this case the listing came with no data sample. Defenders and reporters should not treat leak-site posts as confirmed breaches, and should watch for copycats using the name.
- The threat of disruption is new and vague. ProvenData says the group's ShinySp1d3r encryptor is still in development and has not been seen in a documented attack. The "digital problems" warning could mean DDoS, harassment, or pressure on executives and customers, rather than encryption.
- Consumer goods companies hold large customer datasets. Loyalty programmes, rebates, sample requests and support records sit in SaaS CRMs, which are the platforms this group targets most.
The Attack Technique
None of the sources says how anyone got into Kimberly-Clark, if anyone did. Breachwire maps the claim to MITRE ATT&CK TA0040 (Impact) and TA0005 (Defense Evasion), but that is a general mapping, not forensic evidence. No CVEs or IOCs have been published.
ShinyHunters' known methods, documented by ProvenData and Mitiga, include:
- Vishing for SSO credentials and MFA codes, with callers posing as IT support
- Abuse of the OAuth device flow. A victim is talked into entering an 8-character code on Salesforce's verification page, which gives an attacker-controlled Data Loader a valid access token. Data is then exfiltrated slowly.
- Stolen OAuth tokens from third-party integrations. Mitiga separately attributes the Salesloft/Drift token theft to UNC6395.
- Exploits in applications such as PeopleSoft and Canvas, and overly permissive guest access on Salesforce Experience Cloud
Any of these could explain a consumer-record dataset like the one DataBreach.com describes. Nothing published so far ties a specific method to Kimberly-Clark.
What Organizations Should Do
- Lock down connected apps in your SaaS tenants. Audit OAuth-connected apps in Salesforce, M365 and Google Workspace. Restrict or disable the device-code flow, and alert on Data Loader or API access from new IPs, Tor exit nodes or unusual user agents.
- Harden the help desk against vishing. Require out-of-band identity checks before MFA resets or verification-code requests. Train staff that IT will never ask them to enter a code on a vendor page.
- Use phishing-resistant MFA, such as FIDO2 or passkeys, for SSO and admin roles, so stolen one-time codes are useless.
- Watch for large exports. Baseline normal CRM query and report volumes, and alert on bulk exports of contact, address or vehicle fields.
- Prepare to verify extortion claims. Before a leak-site listing appears, plan how you would quickly confirm or rule out exfiltration, draft disclosure wording that meets SEC 8-K and state notification rules, and agree who handles contact from extortionists.
- Monitor indexers and leak sites for your brand. Check any dataset that surfaces against your own schemas instead of assuming it is genuine.
Sources: Kimberly-Clark Ransomware: ShinyHunters... breachwire | ShinyHunters Targets Kimberly-Clark in Breach Claim | Kimberly-Clark Ransomware Claim by ShinyHunters (Sep 2026) | ShinyHunters Targets Kimberly-Clark in Ransomware Assault - DeXpose | ShinyHunters Threatens Kimberly-Clark as Vexy Strikes Strad Solutio... | Kimberly-Clark Search the Data Breach | ShinyHunters: Attack Lifecycle, IOCs, and Incident Response Guide | ShinyHunters and UNC6395: Inside the Salesforce ...