Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

ShinyHunters Salesforce extortion wave with Qantas disclosure

Updated 15.01.2026 23:38
Case score 58
Members 1 First seen 15.01.2026 17:45 Latest activity 15.01.2026 23:38

Overview

ShinyHunters' 2025 **Salesforce** extortion activity includes a **Qantas** breach disclosed after attackers entered a third-party platform used by one customer service contact center on June 30, 2025. Qantas says the intruders reached systems holding customer PII before containment, and the incident sits inside a broader **UNC6040** pattern that has targeted multiple global companies through **Salesforce** entry points. Qantas says about **5.7 million** passengers were affected, with names, email addresses, frequent flyer numbers, and some contact details exposed. It says no payment card numbers, financial information, passport numbers, or account credentials were compromised, and it warned customers about impersonation scams while taking additional protective steps.
Latest development Open development history 1 earlier development ShinyHunters Salesforce extortion campaign against global companies in 2025 The early phase centered on **2025** attacks against **Salesforce portals** using **social engineering** and **voice phishing** to obtain credentials. That foothold then enabled lateral movement and data theft for extortion.
  1. Earlier development

    Allianz Life says July 16 breach impacted 1.5 million

    Allianz Life says a malicious threat actor gained access to a cloud-based system on July 16, 2025, obtained personal information for customers, financial professionals, and select employees, and later determined that 1,497,036 people were impacted; the insurer is notifying affected individuals and offering two years of free identity theft monitoring by Kroll, and the activity is likely tied to the ShinyHunters Salesforce attack wave.

Signals

Impact signals
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

11 listed

Malware & tooling context

3 families · 2 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign ShinyHunters Salesforce extortion campaign against global companies in 2025
Updated 15.01.2026 17:45 Lead Contribution 58
Objective Financial Extortion Campaign Active Patch No Patch

The **ShinyHunters** campaign now includes a **Qantas** breach disclosed after the airline found a **June 30, 2025** intrusion in a **third-party platform** used by one customer service contact center. Qantas says attackers accessed systems holding customers’ **PII** before containment, affecting about **5.7 million passengers**, and it links the incident to broader **UNC6040 / ShinyHunters** activity that has also hit **Adidas, Pandora, Cisco, and others** through **Salesforce** entry points. The airline says **no payment card numbers, financial information, passport numbers, or Qantas account credentials** were exposed, but it reduced executive short-term compensation by **15%** after the breach.