Most Popular ShinyHunters 2026: Stolen Third-Party Token Cross-Cloud Data Pull into BigQuery (Anodot-Style Token Abuse)
Detects anomalous large-scale data export operations in Google BigQuery (via jobs.insert or jobs.query) performed by identities (service accounts, API keys) not previously observed in the environment. This activity is indicative of credential abuse where stolen third-party analytics or monitoring service tokens are utilized for illicit data exfiltration, a behavior consistent with tactics employed by threat actors such as ShinyHunters.
Microsoft Sentinel (KQL)

