Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

ShinyHunters voice-phishing extortion through Salesforce-connected accounts

Updated 27.04.2026 17:43
Case score 62
Case score 62 Members 1 Latest activity 27.04.2026 17:43
Members 1 First seen 24.01.2026 01:35 Last seen 24.01.2026 01:35 Updated 27.04.2026 17:43

Overview

ShinyHunters is using voice phishing to reach employees who can connect malicious apps to organization **Salesforce** portals or hand over access through SSO, turning account compromise into customer-data theft for extortion. Google later tracked the activity as **UNC6040** and warned that the actors were already pressuring victims over stolen Salesforce data. The operation escalated into public leak pressure through the **Scattered LAPSUS$ Hunters** blog, which named more than three dozen companies and threatened publication of stolen data unless ransom was paid. Available evidence shows the campaign remains active, but the full reach and the amount of unreleased data are still unquantified.