Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
█ Ransomware KIMBERLY-CLARK-SHI 2026-09-13

Kimberly-Clark: ShinyHunters Extortion Listing and Ransomware Claim

"On September 13, 2026, the data-theft and extortion group ShinyHunters named Kimberly-Clark Corporation (Nasdaq: KMB) on its leak site, according to a report by threat-monitoring vendor DeXpose, which logged the listing…"

On September 13, 2026, the data-theft and extortion group ShinyHunters named Kimberly-Clark Corporation (Nasdaq: KMB) on its leak site, according to a report by threat-monitoring vendor DeXpose, which logged the listing the same day. The post carries a three-day ultimatum: "This is a final warning to reach out by 16 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline." As of this writing, the claim rests on the group's own post and a single OTHER-tier report. Kimberly-Clark has not issued a public statement, no Form 8-K addressing a cybersecurity incident has surfaced, and no independent researcher has published sample data. Readers should treat the listing as an unverified extortion claim against a Fortune 500 consumer-goods manufacturer, and read the group's recent track record as the best available guide to what happens next.

What Happened

The only direct account of the Kimberly-Clark event comes from DeXpose (S1), which records the target as kimberly-clark.com, the country as the United States, the attacking group as ShinyHunters, and the date reported as September 13, 2026. DeXpose characterises the event as a ransomware attack; the quoted threat language, however, describes leaking data rather than decrypting it, which matches ShinyHunters' established extortion-only model rather than classic encryption ransomware. That distinction matters for defenders sizing their response, and the available sourcing does not resolve it.

The "final warning" phrasing implies the group believes it has already made contact and been ignored, a sequence consistent with its handling of other victims. It also closely echoes the language BreachNews reported when ShinyHunters added McKesson, Neogen, Jack Henry & Associates and Elekta AB to the same leak site on August 29, 2026, threatening "additional digital disruption" if those four companies did not engage by September 1 (S6). Same template, same compressed deadline, new name at the top.

For scale context on the target: Kimberly-Clark reported second-quarter and first-half 2026 results on August 4, 2026, with CEO Mike Hsu describing an in-progress "Powering Care" transformation, the newly launched Arbex joint venture with Suzano, and a pending acquisition of Kenvue expected to close by year end (S8). A company mid-transaction and mid-restructuring is an attractive extortion target precisely because disclosure timing is awkward. Notably, that same release attributed part of the quarter's weakness to "a discrete disruption stemming from false allegations regarding the quality of" its products, evidence that the company has already been managing reputational shocks this year.

What Was Taken

Nothing has been established. Unlike the McKesson listing, where ShinyHunters attached a specific figure and a data-type description, the Kimberly-Clark post as reported contains no record count, no volume in gigabytes, no named systems and no data categories. BreachNews observed the same asymmetry in the August 29 batch: McKesson drew a detailed allegation of "hundreds of millions of records or database rows" containing PII and PHI, while Neogen, Jack Henry and Elekta got no comparable description (S6). Absence of a number in the initial post is normal for this group and should not be read either as reassurance or as confirmation of a large haul.

The group's own counts also require heavy discounting. ShinyHunters claimed 284 million records from McKesson; the company confirmed a cybersecurity incident involving unauthorized access to and exfiltration from third-party applications, discovered August 25, 2026, while stating its investigation remained in early stages and that it had not determined the incident to be material (S2, S7). ShinyHunters itself told BleepingComputer that 284 million is a raw count of database lines, not unique individuals, and that it had not finished processing the data (S2, S5). TechNewsHub reports the group additionally claimed roughly 1 terabyte exfiltrated from a Snowflake warehouse and a $55.2 million ransom demand with a 72-hour deadline; those specifics come from the group's communications, not from McKesson (S7).

The Carhartt case shows how far initial numbers drift. ShinyHunters listed Carhartt on August 13, 2026, claiming more than 50 GB; Carhartt did not pay and the data was published. Troy Hunt's extraction over the dump produced 24,876,077 unique email addresses, a machine count of every address in the files rather than a count of affected customers, and freshfromcache reports that a large share of those addresses did not represent what the headline figure implied (S5). Where the same group's claims have been tested, the first big number has consistently been a row count, not a people count.

Why It Matters

Baxter International is the closest analogue for what the next week may look like. Baxter issued a statement on August 13, 2026, describing unauthorized activity within certain third-party applications; ShinyHunters added it to the leak site on August 14 with an August 17 deadline, and published roughly 7.1 million records on August 19 when no payment materialised (S3). The compressed cycle from listing to publication was six days. Applied to Kimberly-Clark, a September 16 deadline implies any leak decision lands within days, not months.

The broader pattern is that this campaign is not sector-bound. ThreatPaper documents ShinyHunters and associated clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661 and UNC6671 running a sustained multi-vector campaign against Salesforce customer data across hundreds of organizations from mid-2025 into August 2026, hitting technology vendors, industrial firms, healthcare providers and consumer brands alike (S4). A tissue-and-hygiene manufacturer has no PHI, but it has CRM data, retail-partner records, supplier contracts and employee data, and that is sufficient inventory for this group's business model. Consumer-goods security teams who filed the McKesson and Baxter headlines under "healthcare problem" should refile them.

Finally, the verification gap is itself the story. A Fortune 500 listing that draws one vendor blog post and no press pickup, no filing and no victim statement is the normal opening state of these incidents. Baxter and McKesson both became confirmed only after the companies chose to speak. Defenders and investors should expect the information picture here to change materially, in either direction.

The Attack Technique

No initial-access vector has been reported for Kimberly-Clark. What the sources establish is the group's repertoire elsewhere.

ThreatPaper describes three primary techniques across the campaign: OAuth-token supply-chain compromise, including harvesting Salesloft Drift tokens from source-code repositories with automated secret-scanning tools, which reportedly granted access to roughly 760 tenant organizations; voice phishing of administrative staff; and exploitation of overly permissive Salesforce Experience Cloud guest-user permissions, queried via customized variants of open-source tooling. The common thread is access that looks legitimate and therefore does not trip login-anomaly detection (S4).

For McKesson specifically, TechNewsHub reports that the group claimed it vished multiple employees, captured Okta single sign-on credentials, and used that access to pull data from corporate Salesforce and Snowflake environments between August 21 and August 25, 2026 (S7). Those specifics are the attacker's account; McKesson has confirmed only that third-party applications were involved (S2). Both Baxter and McKesson independently described the intrusion surface as "third-party applications" rather than their own perimeter (S2, S3), and freshfromcache notes the blunt operational reality that most of these break-ins begin with a phone call to somebody at work (S5).

What Organizations Should Do

Sources: ShinyHunters Targets Kimberly-Clark in Ransomware Assault - DeXpose | McKesson discloses breach after ShinyHunters claims patient data theft | ShinyHunters Leaks 7.1 Million Baxter International Records | ShinyHunters Salesforce Data Extortion and SaaS Supply-Chain Campai... | Who is ShinyHunters? The name in your breach letters | ShinyHunters Adds McKesson, Neogen, Jack Henry, Elekta to DLS | Healthcare giant McKesson confirms data breach following ShinyHunte... | Kimberly-Clark Corporation: Kimberly-Clark Announces Second Quarter...