Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

ShinyHunters voice-phishing extortion through Salesforce-connected accounts

Updated 27.04.2026 17:43
Case score 62
Members 1 First seen 24.01.2026 01:35 Latest activity 27.04.2026 17:43

Overview

ShinyHunters is using voice phishing to reach employees who can connect malicious apps to organization **Salesforce** portals or hand over access through SSO, turning account compromise into customer-data theft for extortion. Google later tracked the activity as **UNC6040** and warned that the actors were already pressuring victims over stolen Salesforce data. The operation escalated into public leak pressure through the **Scattered LAPSUS$ Hunters** blog, which named more than three dozen companies and threatened publication of stolen data unless ransom was paid. Available evidence shows the campaign remains active, but the full reach and the amount of unreleased data are still unquantified.
Latest development Open development history 1 earlier development ShinyHunters breach ADT data affecting 5.5 million ShinyHunters breached ADT after compromising an employee's Okta single sign-on (SSO) account in a vishing attack, then used that access to reach ADT's Salesforce instance and steal data. Have I Been Pwned said the exposed data affected 5.5 million people and included names, phone numbers, addresses, and in a small percentage of cases dates of birth and partial Social Security numbers or Tax IDs; the group later leaked an 11GB archive after extortion failed.
  1. Earlier development

    ShinyHunters claims SSO voice-phishing campaign

    ShinyHunters claims responsibility for an ongoing voice-phishing campaign against SSO users at Okta, Microsoft Entra, and Google, where attackers impersonate IT support, steer employees to phishing pages, capture credentials and MFA codes in real time, and use the compromised access to reach connected SaaS platforms and steal data for extortion.

Signals

Impact signals
CVEs/products
Remediation
Status
Threat context

Threat actor context

12 listed

Malware & tooling context

2 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign ShinyHunters voice-phishing campaign targeting SSO accounts for extortion
Updated 24.01.2026 01:35 Lead Contribution 62
Objective Financial Extortion Campaign Active Patch No Patch

A **ShinyHunters**-linked extortion campaign is using **voice phishing** to target **Salesforce customers** and steal data for ransom, with the operation first surfacing in **May 2025** and later tied by Google to **UNC6040**. The group has since published a victim-shaming site, **Scattered LAPSUS$ Hunters**, that names dozens of companies and threatens to leak stolen data unless payments are made, while also claiming other breaches including **Discord** and **Red Hat**. The broader activity matters because a compromised account or connected app can expose large volumes of customer and enterprise data across multiple organizations.