The hacking group ShinyHunters is widening its attacks on Salesforce customers. In recent weeks, Chanel, Pandora and Google, among others, have become known as victims – part of a campaign in which more than a billion records are said to have leaked.
Attacking via Salesforce configuration
The group does not target a flaw in Salesforce itself, but exploits how organizations configure, connect and authenticate their Salesforce environments – for example via abused OAuth connections and the Experience Cloud. Across three campaigns from mid-2025 to early 2026, an estimated 1.5 billion records were exfiltrated from more than 1,000 organizations; confirmed victims include Cloudflare, Zscaler and Palo Alto Networks.
Extortion on a short deadline
The playbook follows a pattern: steal data, prove access, demand ransom with a short deadline – and, if refused, publish or sell the data on a leak site. For organizations that means: regularly review OAuth connections and third-party apps, minimize permissions and consistently secure Salesforce access.
Sources: Salesforce Ben, Infosecurity Magazine.



















