# ShinyHunters lists Logitech, Streamlabs for extortion

Published: 2026-08-18 · Severity: high · Sectors: technology, manufacturing
Canonical: https://vorant.io/reports/15de5a3c-8359-5d15-819e-d5b13129a836/shinyhunters-lists-logitech-streamlabs-for-extortion

> ShinyHunters threatens to leak data from Logitech and Streamlabs unless a ransom is paid by 21 Aug 2026.

The extortion group ShinyHunters added Logitech and Streamlabs to its leak-site listing, issuing a final payment deadline of 21 August 2026 before threatening to publish stolen data. The listing claims compromise of 19 employees, over 37,000 users, and 23 third-party employee credentials, along with an external attack surface of 123 exposed assets and extensive DNS/WHOIS reconnaissance data for the victim's domain, including SPF records, third-party SaaS integrations (Google Workspace, Microsoft 365, Atlassian, Dropbox, Stripe, DocuSign, Zendesk, TeamViewer, Twilio, and others), and domain verification tokens for numerous cloud services.

No malware payload or ransomware encryption is described; this appears to be a data-extortion (leak-and-shame) operation rather than a classic ransomware deployment. The extensive listing of SaaS/DNS metadata suggests the actor performed broad reconnaissance of the victim's external attack surface and third-party service integrations, likely to support the extortion narrative or facilitate further compromise. No technical IOCs (malware hashes, C2 infrastructure) are provided in the posting.

## Mentioned in this report

- Threat actors: ShinyHunters

1 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://www.ransomware.live/id/TG9naXRlY2gvIFN0cmVhbWxhYnNAc2hpbnlodW50ZXJz

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/15de5a3c-8359-5d15-819e-d5b13129a836/shinyhunters-lists-logitech-streamlabs-for-extortion.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
