ShinyHunters Salesforce Data Extortion and SaaS Supply-Chain Campaign (2025–2026)
By Sethu Satheesh · 28 Aug 2026 · 14 min read
Threat Actor: ShinyHunters · Target: Salesforce
Source: sharkstriker.com
Executive Summary
Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and UNC6671—conducted a sustained, multi-vector data theft and extortion campaign targeting Salesforce customer data across hundreds of organizations. The campaign combined OAuth-token supply-chain compromises, voice-phishing (vishing) of administrative personnel, and the exploitation of overly permissive Salesforce Experience Cloud guest-user permissions to extract customer relationship management (CRM) records without triggering standard login anomalies.
The threat actors leveraged several high-profile integration compromises, most notably extracting Salesloft Drift OAuth tokens from source code repositories using automated secret-scanning tools, which granted unauthorized access to roughly 760 tenant organizations. Additionally, attackers abused Gainsight and Klue integrations and deployed customized variants of open-source security tools like Mandiant's AuraInspector to systematically query exposed Experience Cloud endpoints. This multi-pronged approach resulted in claims of billions of exfiltrated records, targeting major technology vendors, industrial firms, healthcare providers, and consumer brands with aggressive extortion demands and public data leak publications.
The campaign highlights systemic risks inherent in modern Software-as-a-Service (SaaS) architectures, particularly concerning non-human identity management, third-party API trust, and cloud misconfigurations. In response, platform providers and regulatory bodies issued urgent advisories, forcing sweeping architectural updates such as mandatory Proof Key for Code Exchange (PKCE), refresh token rotation, and tightened Experience Cloud guest user defaults. The operations underscore an ongoing convergence between identity-based social engineering and automated cloud API abuse.
Verification of Claims
-
Claim: A zero-day vulnerability inherent to the Salesforce platform facilitated the mass exfiltration of data across customer environments. → Unverified / Refuted → Salesforce Security Operations Center and independent forensic analyses explicitly confirmed that the platform contained no underlying vulnerability; incidents stemmed from customer-configured guest user settings and third-party OAuth integrations.
-
Claim: ShinyHunters and Scattered Spider collaborated or operated under a unified supergroup alias. → Partially verified → ReliaQuest Threat Intelligence and Microsoft Threat Intelligence reported tactical overlaps, shared infrastructure, and synchronized targeting timelines, though definitive organizational unity remains a hypothesis.
-
Claim: Attackers bypassed Salesforce's standard 2,000-record query limit to extract data in bulk. → Verified → Salesforce Advisory and security researchers confirmed that attackers manipulated sorting parameters and utilized the aura://RecordUiController/ACTION$executeGraphQL controller with Base64-encoded cursors to bypass pagination limits.
-
Claim: Threat actors utilized a modified version of Mandiant's AuraInspector tool to automate data extraction. → Verified → Mandiant and Salesforce CSOC confirmed the deployment of a weaponized variant of AuraInspector to scan /s/sfsites/aura endpoints and harvest CRM objects.
-
Claim: ShinyHunters compromised roughly 1.5 billion records from 760 companies via Salesloft Drift OAuth tokens. → Verified → BleepingComputer and threat intelligence reports confirmed the discovery of hardcoded tokens in GitHub repositories via TruffleHog, granting access to 760 Salesforce organizations in August 2025.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| May 31, 2022 | Law Enforcement | Core ShinyHunters affiliate Sebastien Raoult is arrested in Morocco attempting to board a flight to Brussels. | Tripwire Security |
| January 2023 | Law Enforcement | Sebastien Raoult is extradited from Morocco to the United States to face federal wire fraud and identity theft charges. | Flashpoint Intelligence |
| June 4, 2025 | Google Threat Intelligence | Google officially attributes a widespread wave of Salesforce vishing attacks to ShinyHunters (UNC6040). | Google Threat Intelligence |
| August 8, 2025 | ShinyHunters (UNC6395) | Attackers exploit hardcoded OAuth tokens in Salesloft Drift repositories, extracting records across 760 organizations over 10 days. | BleepingComputer |
| September 15, 2025 | Federal Bureau of Investigation | FBI issues an urgent flash notice warning of ongoing Salesforce data theft campaigns by ShinyHunters and associated actors. | The Record |
| November 2025 | ShinyHunters | Attackers compromise OAuth tokens from Gainsight Salesforce integrations, affecting roughly 285 tenant instances. | Huntress Threat Library |
| March 7, 2026 | Salesforce Security | Salesforce publishes an urgent security advisory warning of active scanning and exploitation of permissive Experience Cloud guest user configurations. | Salesforce CSOC |
| June 17, 2026 | Storm-3138 / Icarus | Attackers access Klue systems, reusing Salesforce credentials to query and exfiltrate customer data via platform integrations. | ReliaQuest |
| July 13, 2026 | Microsoft Threat Intelligence | Microsoft publishes detailed mapping of three primary ShinyHunters Salesforce attack vectors: vishing, third-party SaaS integrations, and Experience Cloud misconfigurations. | Microsoft Security Blog |
| August 2026 | ShinyHunters | The group executes ransomware and extortion operations against Questel, Alcon, Lumenis, Baxter International, and Brinks Home. | SharkStriker |
Attack Anatomy
Initial Access: Threat actors initiated intrusions using targeted voice phishing (vishing), impersonating corporate IT support to manipulate employees into divulging SSO credentials or approving malicious OAuth Connected Apps. Alternatively, attackers exploited misconfigured Salesforce Experience Cloud portals with overly permissive guest user profiles or harvested hardcoded OAuth tokens from external source code repositories using tools like TruffleHog.
Execution: Attackers leveraged legitimate SaaS functionality by initiating OAuth 2.0 Device Flows using tools like the Salesforce Data Loader. In Experience Cloud environments, they deployed customized variants of Mandiant's open-source AuraInspector tool to automate endpoint enumeration across public-facing Aura and GraphQL interfaces.
Persistence: To maintain long-term access, attackers registered rogue Multi-Factor Authentication (MFA) devices (often named "Passkey") to compromised user profiles. They also authorized Google Workspace add-ons such as ToogleBox Recall to programmatically search inboxes and permanently delete Okta security notification emails, blinding administrators to the account compromise.
Privilege Escalation: Attackers exploited overly permissive Guest User Profiles that possessed "View All" or "Modify All" permissions on critical CRM objects, effectively elevating unauthenticated web visitors to high-privilege data access.
Lateral Movement: Utilizing compromised vendor OAuth tokens (from Salesloft Drift, Gainsight, or Klue), attackers moved laterally across hundreds of downstream customer Salesforce tenants that trusted these third-party integrations, bypassing perimeter MFA and SSO controls entirely.
Collection: Threat actors extracted bulk CRM records from standard objects including Accounts, Contacts, Leads, Cases, and Opportunities. They bypassed Salesforce's standard 2,000-record query limit by manipulating sorting flags or executing continuous pagination via the GraphQL executeGraphQL controller.
Exfiltration: Data was exfiltrated via legitimate Salesforce API calls utilizing boxcar bundling—grouping up to 250 distinct backend actions into a single HTTP POST request to evade volume-based anomaly detection. Exfiltrated datasets were subsequently uploaded to Tor-hosted data leak sites.
Impact: Compromised organizations faced severe extortion demands, public leak postings, regulatory scrutiny, operational friction, and reputational harm as proprietary sales data and consumer PII were weaponized.
Loading diagram...
Threat Actor Profile
- Name / Alias: ShinyHunters (tracked across activity clusters UNC6040, UNC6240, UNC6395, UNC6661, UNC6671; associated with the Scattered-Lapsus$-Hunters supergroup)
- Attribution Confidence: High — Confirmed via infrastructure overlap, negotiation personas, TTP mapping, and law enforcement indictments by Mandiant, ReliaQuest, and the FBI.
- Motivation: Financial — Extortion, ransom demands, and monetization of stolen corporate data on cybercriminal forums.
- Sophistication Level: Advanced — Demonstrated mastery of cloud identity architectures, OAuth 2.0 grant flows, API endpoint abuse, and the weaponization of open-source administrative tools.
- Known Previous Operations: Ticketmaster, Santander Bank, AT&T, GitHub, Bonobos, Pixlr, and the Snowflake data theft campaign.
- Nation-State Nexus: No — Characterized as a financially motivated multinational cybercriminal collective.
- MITRE ATT&CK Techniques:
T1020— Automated ExfiltrationT1671— Cloud Application IntegrationT1059.006— Command and Scripting Interpreter: PythonT1586.002— Compromise Accounts: Email AccountsT1213.004— Data from Information Repositories: Customer Relationship Management SoftwareT1567— Exfiltration Over Web ServiceT1598.004— Phishing for Information: Spearphishing VoiceT1090.003— Proxy: Multi-hop ProxyT1078.002— Valid Accounts: Domain Accounts
- Operational Security (OpSec): Extensive use of commercial VPN networks, residential proxies, and Tor infrastructure to mask source IPs, alongside aggressive defense evasion tactics inside victim email tenants to suppress security alerts.
Technical Indicators
domains:
- "ticket-lvmh[.]com"
- "ticket-dior[.]com"
- "ticket-louisvuitton[.]com"
- "dashboard-salesforce[.]com"
ip_addresses:
- "24.242.93[.]122"
- "23.234.100[.]107"
- "23.234.100[.]235"
- "73.135.228[.]98"
- "157.131.172[.]74"
- "149.50.97[.]144"
- "67.21.178[.]234"
- "142.127.171[.]133"
- "76.64.54[.]159"
- "76.70.74[.]63"
- "206.170.208[.]23"
- "68.73.213[.]196"
- "37.15.73[.]132"
- "104.32.172[.]247"
- "85.238.66[.]242"
file_hashes: []
urls: []
c2_infrastructure:
- "shinycorp@tuta[.]com"
- "shinygroup@tuta[.]com"
- "shinygroup@onionmail[.]com"Legal and Regulatory Response
Law Enforcement Actions
The United States Department of Justice, FBI Seattle Cyber Task Force, and international partners systematically pursued core members of ShinyHunters. In May 2022, French national Sebastien Raoult was arrested in Morocco and subsequently extradited to the U.S. in January 2023. Additional co-conspirators were named in federal indictments filed in the Western District of Washington.
Government Directives
The FBI published flash notices detailing ShinyHunters' vishing and SaaS exploitation campaigns. Additionally, the Financial Industry Regulatory Authority (FINRA) issued a high-priority cybersecurity alert warning member firms that ShinyHunters was actively exploiting misconfigured Salesforce Experience Cloud portals to steal sensitive client data.
Platform Response
Salesforce implemented mandatory security updates, introducing API Access Control requiring administrators to pre-approve all connected apps. Modern OAuth 2.0 standards were enforced globally, making Proof Key for Code Exchange (PKCE) mandatory, enforcing Refresh Token Rotation (RTR), and setting a strict 30-day absolute Time-To-Live (TTL) for idle refresh tokens. Salesforce also issued advisories urging customers to audit and harden Guest User Profiles.
Criminal Proceedings
Following his extradition, Sebastien Raoult pleaded guilty in September 2023 to conspiracy to commit wire fraud and aggravated identity theft. On January 9, 2024, U.S. District Judge Robert S. Lasnik sentenced Raoult to three years in federal prison and ordered him to pay $5 million in restitution.
Impact Assessment
- Ticketmaster: Confirmed: 560 million customer records exposed.
- AT&T: Confirmed: 109 million call records exposed; AT&T paid a $370,000 ransom.
- Santander Bank: Confirmed: 30 million customer records exposed.
- Salesloft Drift Integration Victims: Confirmed: 1.5 billion records exfiltrated across 760 companies (including Cloudflare, CrowdStrike, Zscaler, and Palo Alto Networks).
- Gainsight Integration Victims: Confirmed: 285 Salesforce instances compromised, prompting Salesforce to globally revoke associated OAuth tokens.
- Questel SAS: Reported: Over 21 million Salesforce records and 147 GB of internal corporate data stolen.
- Alcon Inc.: Reported: Over 25 million Salesforce records containing PII stolen.
- Baxter International: Reported: 7.1 million Salesforce records stolen and published on leak sites.
- Brinks Home: Reported: 4.9 million Salesforce records containing PII stolen.
- RingCentral: Reported: Over 623 GB of data exfiltrated, exposing contact details for 1.6 million users.
- CyrusOne: Reported: 12.9 million Salesforce records, 600 GB of SharePoint data, and employee PII stolen with a $13 million ransom demanded.
- McGraw-Hill: Confirmed: Data breach confirmed and traced to Salesforce misconfigurations, with exposure described as limited.
- ReliaQuest: Confirmed: Social engineering attack encountered on August 22, 2026, resulting in view-only access to a single identity with no customer data affected.
Lessons and Defensive Recommendations
For Security Teams / SOC Analysts: Security operations centers must pivot toward identity and SaaS-centric threat hunting. Analysts should monitor Okta and Microsoft Entra ID logs for anomalous MFA lifecycle events, particularly those originating from commercial VPNs, Tor nodes, or residential proxies. Deploy SIEM correlation rules to detect high-velocity data retrieval patterns, bulk file downloads, or suspicious GraphQL query activities. Monitor workspace audit logs for the unauthorized authorization of add-ons like ToogleBox Recall that scrub security notification emails.
For Developers and Architects: Developers must never embed static, long-lived OAuth credentials, API keys, or database passwords in source code repositories; use automated secret-scanning tools like TruffleHog defensively. Transition cloud architectures exclusively to dynamic Workload Identity Federation (OIDC) using short-lived, ephemeral tokens. Within Salesforce, Apex developers must enforce Field-Level Security and Object permissions in custom UI controllers using constructs like WITH USER_MODE or Security.stripInaccessible().
For Platform / Cloud Providers: Salesforce and Experience Cloud administrators must conduct zero-trust audits of public-facing portals, completely disabling API access for unauthenticated users by unchecking the "API Enabled" permission on Guest User Profiles. Ensure Default External Access for all objects in Organization-Wide Defaults is set to "Private," disable portal and site user visibility settings, and deactivate self-registration if unrequired by business operations.
For Leadership / CISO: Executive leadership must recognize identity as the primary corporate perimeter. CISOs must mandate phishing-resistant Multi-Factor Authentication—such as FIDO2/WebAuthn hardware keys—across the enterprise, phasing out vulnerable SMS, email, or simple push notifications. IT help desk verification protocols must be overhauled, banning password resets based solely on inbound phone calls or static identifiers in favor of live video verification. Finally, enforce rigorous Third-Party Risk Management programs to ensure SaaS vendors adhere to strict OAuth governance.
Sources
-
AICerts. "ShinyHunters Salesforce Breach: Claims, Vectors, Defenses"
-
Varonis. "What Salesforce Organizations Need to Know About ShinyHunters"
-
Huntress. "ShinyHunters Threat Actor Profile: TTPs, IoCs & Attacks"
-
Google Cloud. "The Cost of a Call: From Voice Phishing to Data Extortion"
-
Wikipedia. "ShinyHunters"
-
The Record. "FBI warns of Scattered Spider and ShinyHunters attacks on Salesforce"
-
Salesforce Ben. "Salesforce Hacks 2026: Everything We Know So Far"
-
ReliaQuest. "ShinyHunters Data Breach Targets Salesforce Amid Scattered Spider Collaboration"
-
Digital Mass. "Experience Cloud Guest Users and Why This Is a Configuration Issue"
-
MITRE ATT&CK. "Salesforce Data Exfiltration, Campaign C0059"
-
SafeState. "ShinyHunters Behind Salesforce Aura Data Theft Campaign"
-
CyberPress. "AuraInspector: Open-Source Tool to Audit Salesforce Aura Framework Misconfigurations"
-
RH-ISAC. "ShinyHunters Utilize Public Audit Tool to Scan for Salesforce Aura Endpoints"
-
Google Cloud. "Auditing Salesforce Aura for Data Exposure"
-
Omni Cybersecurity. "Salesforce Warning: Misconfigured Customer Portals Targeted"
-
Varonis. "OAuth Connected Application Control: Lock Down Your Salesforce"
-
CyberPress. "Google Warns Of Major Expansion In ShinyHunters Operations"
-
The Hacker News. "Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Compromise SaaS"
-
Black Kite. "ShinyHunters and the Salesforce Experience Cloud Campaign"
-
Obsidian Security. "ShinyHunters and Scattered Spider: A Merger of Chaos in the Salesforce Attacks"
-
Google Cloud. "Expansion of ShinyHunters SaaS Data Theft Campaigns"
-
Valence Security. "Salesforce Experience Cloud is in an Active Data-Theft Campaign"
-
Salesforce. "Essential Actions to Secure Experience Cloud Guest User Access"
-
AppOmni. "What is the Salesforce GraphQL Exploit and What You Should Do"
-
The Hacker News. "Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector"
-
BleepingComputer. "ShinyHunters claims ongoing Salesforce Aura data theft attacks"
-
U.S. Department of Justice. "French Cybercriminal Pleads Guilty to Wire Fraud and Aggravated Identity Theft"
-
Tripwire. "ShinyHunters Suspect Could Face 116 Years in Jail"
-
Flashpoint. "COURT DOC: Alleged French Cybercriminal to Appear In Seattle"
-
Fox 13 Seattle. "French man sentenced to 3 years in prison for role in international hacking group"
-
KIRO 7 News. "Notorious French hacker who stole information from millions sentenced in Seattle"
-
Help Net Security. "AuraInspector: Open-source tool to audit Salesforce Aura access"
-
Salesforce Ben. "ShinyHunters 'Breach 400 Companies' via Salesforce Experience Cloud"
-
SharkStriker. "August 2026 Data Breaches"
-
Medium. "Salesforce Vishing: ShinyHunters (UNC6040) Data Extortion Operations"
-
Cloud Protection. "Salesforce OAuth Device Flow Attacks Explained"
-
The Hacker News. "Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Campaign"
-
Xcitium Threat Labs. "ShinyHunters Exploits Salesforce Aura Misconfigurations in Data Theft Campaign"
-
AuthMind. "ShinyHunters Attacks Further Validate the Need for Identity-Driven Threat Prevention"
-
The Record. "French hacker from 'ShinyHunters' group sentenced to three years in federal prison"
-
FINRA. "Cybersecurity Alert – Salesforce Experience Cloud Security Incident"
-
Salesforce Ben. "Salesforce Hardens Connected Apps Security Amid Social Engineering Attacks"
-
Success Craft. "Salesforce Connected Apps Security Changes Explained"
-
Salesforce Help. "Salesforce Connected Apps & ECA Security Controls Post"
-
Salesforce Developers. "Secure Your Connected Apps and External Client Apps"
-
Google Cloud. "The Cost of a Call: From Voice Phishing to Data Extortion (Korean)"
-
Google Cloud. "Proactive Defense Against ShinyHunters-Branded Data Theft"
-
Medium. "Salesforce Experience Cloud Data Security Rule Book"
-
Salesforce Help. "Guest Site User Policies for Experience Cloud / Salesforce Sites"
-
Obsidian Security. "Salesforce Experience Cloud Guest User Exploit - Key Actions to Take"
Related Research
Between June 11 and June 24, 2026, the global cybersecurity and software-as-a-service (SaaS) ecosystem experienced a severe supply chain compromise orchestrated by the financially motivated extortion...
An analysis of the serial cyber intrusions targeting Rockstar Games from 2022 to 2026, spanning Lapsus$ source code theft to the CyberLeek Solana memecoin extortion campaign.
Apollo Global Management confirmed on August 21, 2026 that it had suffered a data breach stemming from a social engineering attack. Between July 6 and July 10, 2026, attackers used voice phishing,...