Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Salesforce Attack Wave Widens: ShinyHunters Extorts More and More Corporations

The hacking group ShinyHunters is widening its attacks on Salesforce customers. In recent weeks, Chanel, Pandora and Google, among others, have become known as victims – part of a campaign in which more than a billion records are said to have leaked.

Attacking via Salesforce configuration

The group does not target a flaw in Salesforce itself, but exploits how organizations configure, connect and authenticate their Salesforce environments – for example via abused OAuth connections and the Experience Cloud. Across three campaigns from mid-2025 to early 2026, an estimated 1.5 billion records were exfiltrated from more than 1,000 organizations; confirmed victims include Cloudflare, Zscaler and Palo Alto Networks.

Extortion on a short deadline

The playbook follows a pattern: steal data, prove access, demand ransom with a short deadline – and, if refused, publish or sell the data on a leak site. For organizations that means: regularly review OAuth connections and third-party apps, minimize permissions and consistently secure Salesforce access.


Sources: Salesforce Ben, Infosecurity Magazine.

Mastodon
Scroll to Top