Campaign
ShinyHunters voice-phishing extortion through Salesforce-connected accounts
Updated 27.04.2026 17:43
Case score 62
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 62
- Main story score
- 62
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Campaign Anchors the extortion campaign, the voice-phishing access path, and the public leak-pressure narrative. main
Members 1
First seen 24.01.2026 01:35
Latest activity 27.04.2026 17:43
Overview
ShinyHunters is using voice phishing to reach employees who can connect malicious apps to organization **Salesforce** portals or hand over access through SSO, turning account compromise into customer-data theft for extortion. Google later tracked the activity as **UNC6040** and warned that the actors were already pressuring victims over stolen Salesforce data.
The operation escalated into public leak pressure through the **Scattered LAPSUS$ Hunters** blog, which named more than three dozen companies and threatened publication of stolen data unless ransom was paid. Available evidence shows the campaign remains active, but the full reach and the amount of unreleased data are still unquantified.
Latest development Open development history ShinyHunters breach ADT data affecting 5.5 million ShinyHunters breached ADT after compromising an employee's Okta single sign-on (SSO) account in a vishing attack, then used that access to reach ADT's Salesforce instance and steal data. Have I Been Pwned said the exposed data affected 5.5 million people and included names, phone numbers, addresses, and in a small percentage of cases dates of birth and partial Social Security numbers or Tax IDs; the group later leaked an 11GB archive after extortion failed.
-
ShinyHunters claims SSO voice-phishing campaign
ShinyHunters claims responsibility for an ongoing voice-phishing campaign against SSO users at Okta, Microsoft Entra, and Google, where attackers impersonate IT support, steer employees to phishing pages, capture credentials and MFA codes in real time, and use the compromised access to reach connected SaaS platforms and steal data for extortion.
ShinyHunters is using voice phishing to trick targets into connecting a malicious app to their organization’s Salesforce portal, which gives the group access to customer data for ransom. Google later tracked the activity as UNC6040 and warned that the actors were extorting victims over stolen Salesforce data.
The group escalated the pressure with a victim-shaming blog called Scattered LAPSUS$ Hunters that listed more than three dozen companies and said stolen Salesforce data would be published unless ransom was paid. Named entries included Toyota, FedEx, Disney/Hulu, and UPS, and the listed breach dates ranged from May to September 2025. The same material says the group claimed responsibility for a Discord breach and a Red Hat intrusion involving a GitLab server and more than 28,000 Git code repositories.
The extortion threat also included a stated deadline of October 10 for publication of stolen Salesforce data if demands were not met. Available evidence shows an active social-engineering and data-extortion operation against enterprise accounts, but the full reach and any unreleased victim data remain unquantified.
Signals
Impact signals
CVEs/products
Remediation
Status
Threat context
Threat actor context
12 listedMalware & tooling context
2 families · 1 toolsTechnical intelligence
Existing Case dataMember happenings
Campaign
ShinyHunters voice-phishing campaign targeting SSO accounts for extortion
Objective
Financial Extortion
Campaign
Active
Patch
No Patch
Campaign
ShinyHunters voice-phishing campaign targeting SSO accounts for extortion
Objective
Financial Extortion
Campaign
Active
Patch
No Patch