Full Breakdown
ShinyHunters Claims Responsibility for Salesforce Aura Data Theft
3/10/2026, 7:44:01 PM
Overview of the Data Theft Incident
The hacking collective ShinyHunters has claimed responsibility for an ongoing data theft campaign targeting Salesforce Aura, a platform that allows organizations to create web portals linked to their Salesforce CRM data. The attack, which began in September 2025, involved exploiting misconfigured guest user permissions across public-facing Salesforce Experience Cloud instances. ShinyHunters reportedly scanned these instances using a modified version of AuraInspector, a tool designed to detect misconfigurations.
Methodology of the Attack
The attackers identified vulnerable sites by probing exposed API endpoints to find portals with excessive guest user permissions. Once these vulnerabilities were confirmed, they utilized a custom tool to bypass authentication limits and extract sensitive Salesforce CRM data. The stolen information, which includes names and phone numbers, has been employed in subsequent social engineering and voice phishing campaigns.
Impact on Organizations
ShinyHunters claims that approximately 100 high-profile organizations have been affected by this campaign, including notable companies such as Snowflake, Okta, LastPass, Salesforce, Sony, and AMD. The group asserted that they have stolen data from nearly 400 websites. Salesforce has acknowledged the threat, warning its customers about the activities of a "known threat actor group" scanning Experience Cloud sites. However, Salesforce representatives clarified that the issue stems from misconfigured guest user profiles rather than an inherent vulnerability in the Salesforce platform.
Official Statements & Responses
Salesforce has refrained from disclosing the number of companies impacted or the total volume of data stolen. A spokesperson stated, "This issue is not due to any vulnerability inherent to the Salesforce platform, but rather Experience Cloud sites where a guest user profile has been inadvertently configured with overly broad permissions." In contrast, ShinyHunters has indicated that they are exploiting a flaw in the product but have chosen not to reveal specifics until the exploitation phase concludes.
Criticism & Opposition
While Salesforce has maintained that the attack is due to user misconfiguration, cybersecurity experts have raised concerns about the adequacy of security measures in place for protecting sensitive data. Critics argue that organizations must take greater responsibility for securing their configurations to prevent such breaches.
What's Next
As the situation develops, organizations affected by the data theft are expected to enhance their security protocols and investigate the claims made by ShinyHunters. LastPass has publicly stated that it is looking into the allegations, while other companies have remained silent on the matter.
Verbatim Quotes
- “Have stolen data from almost 400 websites and about 100 essential high profile companies Snowflake, Okta, Lastpass, Salesforce itself, Sony, AMD, and a lot more,” — ShinyHunters spokesperson
- “This issue is not due to any vulnerability inherent to the Salesforce platform, but rather Experience Cloud sites where a guest user profile has been inadvertently configured with overly broad permissions,” — Salesforce representative
