ShinyHunters Exploits Salesforce Experience Cloud for Massive Data Heist
Mar 9, 2026 // 23:12 - Lina Schonbein


The threat actor group ShinyHunters (also tracked as UNC6040/UNC6240) has claimed responsibility for a new wave of data theft attacks targeting Salesforce Experience Cloud (formerly Community Cloud) sites using the Aura framework.

Key Details of the Attack

The attackers are reportedly exploiting misconfigured guest user permissions on public-facing Salesforce sites. By leveraging these misconfigurations, they can exfiltrate sensitive data without needing valid credentials or bypassing MFA.

  • Targets: ShinyHunters claims to have compromised approximately 100 high-profile companies, including names like Salesforce itself, Snowflake, Okta, LastPass, Sony, and AMD. In total, they allege that between 300 and 400 organizations have been breached in this specific campaign.
  • Methodology:
    • Scanning: The group is using a modified version of AuraInspector, an open-source tool originally developed by Mandiant, to identify vulnerable endpoints (specifically the /s/sfsites/ endpoint).
    • Bypassing Limits: The threat actor claims to have found a way to bypass Salesforce’s 2,000-record query limit through the GraphQL API by manipulating the sortBy parameter.
    • Timeline: Exploitation began around September 2025 and is considered ongoing.

Salesforce and Expert Response

Salesforce has issued a security advisory clarifying that these incidents are not due to a vulnerability in the Salesforce platform itself. Instead, the breaches result from incorrectly configured guest user access.

Recommended Actions for Organizations:

  • Audit Guest Permissions: Immediately review and restrict guest user access to objects and fields to ensure a least privilege model.
  • Monitor API Usage: Look for unusual spikes in API calls or bulk data exports from guest profiles.
  • Check for Scanning: While scanning does not equal a breach, it indicates that your site is being targeted.

#cloud  #data  #experience  #exploits  #for  #heist  #massive  #news  #salesforce  #shinyhunters   —   News