Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

ShinyHunters voice-phishing extortion through Salesforce-connected accounts

Updated 27.04.2026 17:43
Case score 62
Case score 62 Members 1 Latest activity 27.04.2026 17:43
Members 1 First seen 24.01.2026 01:35 Last seen 24.01.2026 01:35 Updated 27.04.2026 17:43

Overview

ShinyHunters is using voice phishing to reach employees who can connect malicious apps to organization **Salesforce** portals or hand over access through SSO, turning account compromise into customer-data theft for extortion. Google later tracked the activity as **UNC6040** and warned that the actors were already pressuring victims over stolen Salesforce data. The operation escalated into public leak pressure through the **Scattered LAPSUS$ Hunters** blog, which named more than three dozen companies and threatened publication of stolen data unless ransom was paid. Available evidence shows the campaign remains active, but the full reach and the amount of unreleased data are still unquantified.

Signals

4 derived
Remediation
Patch No Patch
Status
Campaign status Active
Threat context
Actor LAPSUS$ Actor Shinyhunters

Malware context

2 families · 1 tools
Tools
ToogleBox Recall

Member happenings

1 related
Campaign ShinyHunters voice-phishing campaign targeting SSO accounts for extortion
Updated 24.01.2026 01:35 Lead Contribution 62
Objective Financial Extortion Campaign Active Patch No Patch

A **ShinyHunters**-linked extortion campaign is using **voice phishing** to target **Salesforce customers** and steal data for ransom, with the operation first surfacing in **May 2025** and later tied by Google to **UNC6040**. The group has since published a victim-shaming site, **Scattered LAPSUS$ Hunters**, that names dozens of companies and threatens to leak stolen data unless payments are made, while also claiming other breaches including **Discord** and **Red Hat**. The broader activity matters because a compromised account or connected app can expose large volumes of customer and enterprise data across multiple organizations.