Story perspectives
ShinyHunters Breaches Salesforce, Stealing Data from 100 Firms
3/10/2026
1 of 1
Story summary
- ShinyHunters claims responsibility for the Salesforce Aura data theft affecting about 100 high-profile organizations.
- Attackers exploited misconfigured guest permissions on Salesforce Experience Cloud to extract CRM data.
- The stolen data includes names and phone numbers used in social engineering and voice phishing.
- Salesforce acknowledged the threat and attributed it to user configuration rather than a platform vulnerability.
- Most affected companies remain silent as LastPass investigates the claims.
