LIVE NEWS
  • Ukraine’s top drone units to bring frontline lessons to Washington this month
  • Undisclosed ads on TikTok skirt ban on profiling minors
  • Who wins and loses in the global energy crisis? | Business and Economy
  • Bank of England hints at softer approach to stablecoin restrictions
  • Splunk, Zoom Patch Severe Vulnerabilities
  • When should I buy plane tickets, as Iran war disrupts travel : NPR
  • The Irresistible Urge to Invoke World War III as Wars Rage in Middle East, Ukraine
  • Stocks Pressured by Higher Oil Prices, But Positive Oracle AI News Helps Tech Stocks
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites
Cybersecurity

ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites

primereportsBy primereportsMarch 11, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites
Share
Facebook Twitter LinkedIn Pinterest Email


Salesforce customers have, once again, been targeted by the ShinyHunters group – or, at least, it’s what the group claims.

Attackers modified and abused benign tool

On Saturday, Saleforce confirmed that its security team has identified an attack campaign by unnamed malicious actors looking to access customers’ data.

The attackers are not leveraging a vulnerability in the Salesforce platform, the company said, but are using a modified version of the open-source tool Aura Inspector – a tool originally developed by Mandiant – to:

  • Mass scan public-facing Experience Cloud sites
  • Probe their /s/sfsites/aura API endpoint
  • If the guest user profile has excessive permissions, query Salesforce CRM objects without logging in.

Salesforce urged customers to review their guest user permissions and enforce a “Least Privilege” access model by restricting access for guest users to needed records only and to explicitly shared records only.

Also, to make necessary changes so that unauthenticated users can’t query data through API endpoints and can’t view or enumerate internal users. Finally, the company said, they should disable the self-registration option (if it’s not required).

“[Disabling public APIs] is the highest-impact single change you can make. It closes the Aura endpoint to unauthenticated API queries, which is the exact vector used in this campaign,” the company stated.

Salesforce also advised customers to notify the company’s Support team if they believe or suspect their environment has been affected. Possible indicators of compromise can be found in customers’ Aura Event Monitoring logs, and include queries targeting objects not intended to be public, unexpected spikes from unfamiliar IP addresses, or access outside normal business hours.

ShinyHunters: An old Salesforce foe

Salesforce says that the data harvested is these attacks is usually names and phone numbers, which can be used for follow-on targeted social engineering and vishing campaigns.

But a more immediate problem for the potentially affected companies is ShinyHunters’ usual course of action: cyber extortion, i.e., “pay not to get your stolen data leaked”.

The group claimed the breach on their data leak site and told Bleeping Computer that they’ve been compromising companies with insecure Experience Cloud access control configurations for guest users since September 2025, but modified and started using the AuraInspector tool in January 2026, when it was released “to help defenders identify and audit access control misconfigurations within the Salesforce Aura framework.”

The group has previously targeted Salesforce customers via third-party integrations (Salesloft / Drift) and connected apps (Gainsight).

ShinyHunters stated that they’ve stolen data from around 100 high-profile companies this time around.

ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDonald Trump’s options to cool oil prices are sorely limited
Next Article Dogecoin Descending Channel Shows Where It Is In This Cycle
primereports
  • Website

Related Posts

Cybersecurity

Splunk, Zoom Patch Severe Vulnerabilities

March 12, 2026
Cybersecurity

Salesforce issues new security alert tied to third customer attack spree in six months

March 11, 2026
Cybersecurity

Cyber-Attacks on UK Firms Increase at Four Times Global Rate

March 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20255 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Ukraine’s top drone units to bring frontline lessons to Washington this month
  • Undisclosed ads on TikTok skirt ban on profiling minors
  • Who wins and loses in the global energy crisis? | Business and Economy
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.