Quick Summary
AllegedExecutive Summary
Shinyhunters has listed Kimberly-Clark as an alleged victim on its dark web portal as of September 13, 2026. Kimberly-Clark is a major US-based global manufacturer and one of 26 organizations the group has claimed in the past 60 days. The listing was identified through SOCRadar’s Dark Web Monitoring service. Shinyhunters claimed 25 other victims in the past 60 days, mostly in Healthcare, Technology, and Financial Services, across the United States, Switzerland, and Israel. Other recent US or manufacturing-sector listings include State of Florida DMV, Neogen Corporation, Jack Henry & Associates, and McKesson Corporation — a breadth that spans sectors without a clear manufacturing focus.
Technical Analysis
Stealer-log telemetry returned no records for kimberly-clark[.]com in the queried slice, but that finding is less diagnostic for this actor. Shinyhunters doesn’t consistently rely on infostealer-sourced credentials; its playbook is more closely associated with large-scale credential abuse, social engineering, and direct exploitation of cloud environments. The null result reflects Shinyhunters’ access profile as much as it reflects Kimberly-Clark’s exposure posture.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.