Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

ShinyHunters Salesforce extortion wave with Qantas disclosure

Updated 15.01.2026 23:38
Case score 58
Case score 58 Members 1 Latest activity 15.01.2026 23:38
Members 1 First seen 15.01.2026 17:45 Last seen 15.01.2026 17:45 Updated 15.01.2026 23:38

Overview

ShinyHunters' 2025 **Salesforce** extortion activity includes a **Qantas** breach disclosed after attackers entered a third-party platform used by one customer service contact center on June 30, 2025. Qantas says the intruders reached systems holding customer PII before containment, and the incident sits inside a broader **UNC6040** pattern that has targeted multiple global companies through **Salesforce** entry points. Qantas says about **5.7 million** passengers were affected, with names, email addresses, frequent flyer numbers, and some contact details exposed. It says no payment card numbers, financial information, passport numbers, or account credentials were compromised, and it warned customers about impersonation scams while taking additional protective steps.

Signals

3 derived
Impact signals
Affected approximately 5.7 million passengers
Remediation
Patch No Patch
Status
Campaign status Active
Threat context
Actor Shinyhunters

Malware context

3 families · 2 tools
Tools
BreachForums RaidForums

Member happenings

1 related
Campaign ShinyHunters Salesforce extortion campaign against global companies in 2025
Updated 15.01.2026 17:45 Lead Contribution 58
Objective Financial Extortion Campaign Active Patch No Patch

The **ShinyHunters** campaign now includes a **Qantas** breach disclosed after the airline found a **June 30, 2025** intrusion in a **third-party platform** used by one customer service contact center. Qantas says attackers accessed systems holding customers’ **PII** before containment, affecting about **5.7 million passengers**, and it links the incident to broader **UNC6040 / ShinyHunters** activity that has also hit **Adidas, Pandora, Cisco, and others** through **Salesforce** entry points. The airline says **no payment card numbers, financial information, passport numbers, or Qantas account credentials** were exposed, but it reduced executive short-term compensation by **15%** after the breach.