Very happy to announce that I’ve just earned my Permis d’OSINTer certification !
Another step forward in my OSINT journey, with still plenty to learn and explore.
#OSINT#CyberSecurity#Certification
👀 NEW OSINT TOOL: Map an organization's public ecosystem from a single domain.
Corrects multiple public signals (DNS, certificates, RDAP, HTTP, subdomains, IP addresses, etc.) and then builds a graph to visualize relationships, their trust level, and their origin.
It also maintains a history of scans to detect new assets, infrastructure changes, and other developments over time.
curl -o https://t.co/njGPjAsetT https://t.co/m3LK2dJhTt
Hackuten is now on Telegram.
We're launching our official channel so you can easily stay up-to-date with Hackuten news: new challenges, events, platform updates, and important announcements.
- Join the official channel : https://t.co/1V0srgADIF
Investigation: 18 Days Inside the ShinyHunters Group
I’m going to clearly address the leak of Telegram conversations linked to ShinyHunters that was published in April 2026, because a lot of accurate, inaccurate, and incomplete information has circulated since then.
The goal is to explain why it was done, how the information was obtained and published, what it actually contained, and what happened afterward.
I will not publish any civilian identities, addresses, or personal information that could be used to target anyone.
Why ?
At first, it was just an investigation like any other.
But during the investigation, some members attempted to dox a friend. From that point on, the investigation naturally intensified: more research, more cross-checking, and a much deeper analysis of their conversations, aliases, and organization.
That is what eventually led to the conversations being published.
How ?
The content did indeed come from a Telegram export of the private group, not from a reconstruction based on screenshots found on Twitter.
The archive covered approximately 18 days of conversations, from April 5 to April 22, 2026.
The “how” mainly involved a social engineering approach: gradually getting in contact with them, entering their environment, and gaining enough of their trust to be accepted into the private chat.
Once inside, the goal was not to leak everything immediately.
The idea was to let some time pass, maintain that level of trust, and observe anything that could be useful to the investigation: exchanges between the different aliases, their roles, their relationships, recurring habits, the times they were active or connected, as well as information they shared voluntarily within the group.
The point was to have enough perspective to understand how they operated rather than simply collecting a few isolated messages.
Once enough information had been gathered and the investigation had reached its conclusion, an export of the group was preserved.
On April 24, 2026, I then made the archive public across several forums.
I deliberately will not go into further detail regarding the techniques used to gain their trust or access that environment. The purpose here is to explain how the investigation unfolded, not to provide a reproducible method.
What was published ?
Analyses conducted after the publication refer to approximately:
• 660 messages
• 11 participants/aliases
• 18 days of activity
• period covered: April 5 → April 22, 2026
• Telegram HTML exports
• photos
• videos
• voice/audio messages
• screenshots
• documents and other attachments
CCITIC also documented a collection of 341 files totaling approximately 182.5 MB compressed.
I am specifically attributing that figure to CCITIC, because different analysts later used slightly different counting methods depending on what they considered a “message” or a “file.”
What could be learned from the conversations ?
The most interesting part was not just the content of the messages themselves.
With enough conversations, it was possible to reconstruct part of:
• the relationships between the different aliases;
• their alleged roles;
• internal conflicts;
• their activity patterns;
• certain linguistic habits;
• the channels and infrastructure they used;
• operations or victims they discussed;
• certain financial information visible in screenshots they shared themselves;
• and, above all, numerous OPSEC mistakes.
CTI researchers later turned the archive into interaction graphs, timelines, and activity profiles.
This is also why I now want to provide the authorities with the original material that is still available, along with its context, rather than allowing only second- or third-hand interpretations to continue circulating.
What did the leak actually lead to ?
What can be publicly observed:
• exposure of approximately 18 days of internal conversations;
• exposure of relationships between several aliases;
• documentation of technical and administrative roles;
• exposure of numerous OPSEC mistakes;
• publication of media and documents originating from the channel;
• detailed CTI analysis of the group’s habits and interactions;
• significant media attention around certain actors;
• gradual clarification regarding what was connected to the real ShinyHunters, affiliates, or impostors.
What cannot be claimed without evidence:
• that every participant belonged to the historical ShinyHunters group;
• that every claim made in the Telegram conversations was true;
• that an article repeating another article should be treated as a separate independent confirmation.
If there is still information that could be useful to a judicial investigation, my intention now is to preserve the original material, its dates, and its context, and provide it to the relevant authorities if necessary, rather than publishing additional sensitive information publicly.
I am mainly making this post to leave behind a clear and verifiable account of what actually happened.
Not to glorify what was done.
And not to turn assumptions into facts.
Timestamps and sources matter more than the stories people build around them.