Campaign
ShinyHunters Salesforce extortion wave with Qantas disclosure
Updated 15.01.2026 23:38
Case score 58
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 58
- Main story score
- 58
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Campaign Lead campaign event with a disclosed Qantas breach, passenger PII exposure, and explicit UNC6040/ShinyHunters context. main
Members 1
First seen 15.01.2026 17:45
Latest activity 15.01.2026 23:38
Overview
ShinyHunters' 2025 **Salesforce** extortion activity includes a **Qantas** breach disclosed after attackers entered a third-party platform used by one customer service contact center on June 30, 2025. Qantas says the intruders reached systems holding customer PII before containment, and the incident sits inside a broader **UNC6040** pattern that has targeted multiple global companies through **Salesforce** entry points.
Qantas says about **5.7 million** passengers were affected, with names, email addresses, frequent flyer numbers, and some contact details exposed. It says no payment card numbers, financial information, passport numbers, or account credentials were compromised, and it warned customers about impersonation scams while taking additional protective steps.
Latest development Open development history ShinyHunters Salesforce extortion campaign against global companies in 2025 The early phase centered on **2025** attacks against **Salesforce portals** using **social engineering** and **voice phishing** to obtain credentials. That foothold then enabled lateral movement and data theft for extortion.
-
Allianz Life says July 16 breach impacted 1.5 million
Allianz Life says a malicious threat actor gained access to a cloud-based system on July 16, 2025, obtained personal information for customers, financial professionals, and select employees, and later determined that 1,497,036 people were impacted; the insurer is notifying affected individuals and offering two years of free identity theft monitoring by Kroll, and the activity is likely tied to the ShinyHunters Salesforce attack wave.
Qantas disclosed that attackers broke into a third-party platform used by one customer service contact center on June 30, 2025, and accessed systems containing customer PII before the breach was contained. The incident fits the wider 2025 **ShinyHunters**/**UNC6040** extortion wave that has used **Salesforce** as an entry point against multiple companies.
Qantas says about **5.7 million** passengers were affected, with exposed records including names, email addresses, and frequent flyer numbers for most impacted customers and some records also containing addresses, dates of birth, and phone numbers. The airline says no payment card numbers, financial information, passport numbers, or Qantas account credentials were impacted, and it reduced executive short-term compensation by **15%**, including a **$250,000** cut for CEO **Vanessa Hudson**, after the customer impact became clear.
Qantas says it took immediate action to contain the breach, added further customer protections, and warned customers about scam and phishing activity impersonating Qantas personnel.
Signals
Impact signals
CVEs/products
Geographic context
Remediation
Status
Threat context
Threat actor context
11 listedMalware & tooling context
3 families · 2 toolsTechnical intelligence
Existing Case dataMember happenings
Campaign
ShinyHunters Salesforce extortion campaign against global companies in 2025
Objective
Financial Extortion
Campaign
Active
Patch
No Patch
Campaign
ShinyHunters Salesforce extortion campaign against global companies in 2025
Objective
Financial Extortion
Campaign
Active
Patch
No Patch