Last Update: 08/01/2026 at 12:00 PM EST

ShinyHunters Breaches Salesforce Customers

Coverage from WIRED, The Boston Globe, and others

Articles

99

Active Days

108

The Topic

ShinyHunters Breaches Salesforce Customers topic image

ShinyHunters is associated with a broad campaign of data theft and extortion against organizations using enterprise platforms and customer-data systems. Reported incidents involving 7-Eleven, McGraw Hill, Kodak and the Council of Europe show a recurring pattern of unauthorized access claims, ransom demands and threatened or completed publication of stolen records. The disclosures expose personal, financial and organizational information, while victim organizations continue to investigate the scope and authenticity of the claims.

First Article: 04/11/26

Latest Article: 07/27/26

Summary

  • ShinyHunters has claimed breaches across multiple organizations, including 7-Eleven, McGraw Hill, Kodak and the Council of Europe.
  • Salesforce environments are repeatedly identified in the reported intrusions, while Oracle PeopleSoft is also cited in the group’s broader activity.
  • Extortion often proceeds from a breach claim to a ransom deadline and then to publication of stolen files when negotiations fail.
  • Exposed data reportedly includes names, addresses, phone numbers, email addresses, employment records, financial details and other personal information.
  • McGraw Hill and 7-Eleven disclosures provide examples of large-scale exposure estimates tied to publicly leaked data.
  • Several victims have confirmed unauthorized access but disputed or have not yet verified the attacker’s claimed volume and scope.
  • The FBI has advised victims not to assume that paying a ransom will prevent further extortion or resale of stolen data.

History

07/23/2026

The story is now framed more concretely around named incidents at 7-Eleven, McGraw Hill, Kodak and the Council of Europe, rather than a broader, less specific pattern of ShinyHunters-linked extortion. It also adds the FBI’s guidance that ransom payment does not reliably stop further extortion or data resale.

07/22/2026

The story has narrowed from a broader privacy mix into a more focused account of an ongoing ShinyHunters cyberextortion campaign. The current version adds clearer scale and outcome details, including confirmed large exposures in some cases and a wider set of victim types.

Full History

Featured

Timeline: 108 Days

Apr 11May 2May 23Jun 13Jul 4Jul 25

Additional Articles

⭐⭐⭐⭐⭐

BleepingComputer / Sergiu Gatlan04-16-2026
ShinyHunters claimed a Salesforce misconfiguration led to theft of 13.5 million McGraw Hill accounts, exposing PII for potential spear-phishing and extortion threats.
BleepingComputer / Sergiu Gatlan05-26-2026
7-Eleven disclosed an April 2026 Salesforce-linked data breach after ShinyHunters claimed responsibility and leaked PII affecting about 185,300 people.
BleepingComputer / Sergiu Gatlan06-15-2026
The Council of Europe began investigating ShinyHunters claims of an HR and payroll data breach in connection with dark web leak threats.
BleepingComputer / Lawrence Abrams07-25-2026
Using breach-leaked email addresses, sextortion scammers sent Bitcoin ransom demands in emails tied to exposures from Amtrak and Betterment starting in April.
Cassius Life / Davonta Herring07-10-2026
Madison Square Garden faced privacy concerns after ShinyHunters published leaked documents about an alleged people-tracking database with sensitive identity labels.
TechCrunch05-26-2026
ShinyHunters claimed a hack-and-extortion attack on 7-Eleven in April, and Have I Been Pwned flagged 185,000+ affected people with sensitive identity data.
CNET06-24-2026
Hackers published a reported MSG database in June, exposing customer records and activist dossiers tied to facial recognition surveillance and leading to class-action lawsuits.
New York Times / Christina Caron06-23-2026
ShinyHunters allegedly stole data from Madison Square Garden entities before June 16, and class-action lawsuits were filed in the Southern District of New York.
Pitchfork / Walden Green07-23-2026
Madison Square Garden disabled facial recognition and camera monitoring during July 2-3 Swift and Kelce events after an internal client privacy request, while legal disputes continue over a leaked talent database.
The Record / Jonathan Greig05-20-2026
7-Eleven notified Maine, Vermont, and Massachusetts regulators in connection with an April 8 intrusion that exposed franchisee documents containing Social Security numbers.
Cybernews06-15-2026
Hackers claim ShinyHunters breached Council of Europe systems, exposing HR and payroll data with personal, financial, and medical records, as the organization has not confirmed.
Endtimeheadlines06-26-2026
ShinyHunters reportedly leaked facial recognition and biometric visitor records tied to Madison Square Garden Entertainment in mid-June 2026, leading to a federal class-action filing.
CNET / Tyler Graham06-24-2026
Madison Square Garden Entertainment faced privacy allegations in 2026 after a reported data leak exposed activist dossiers and biometric or facial recognition data.
BiometricUpdate.com06-22-2026
Madison Square Garden Entertainment faced a federal class action after ShinyHunters claimed to steal and publish biometric and other sensitive data linked to venue facial recognition.
Thought Catalog / Nadia Santiago07-17-2026
WIRED reported on July 9 that ShinyHunters exfiltrated an MSG Entertainment talent database with LGBTQIA labels, leading MSG Entertainment to file a defamation lawsuit around July 16.
Mediaite07-10-2026
WIRED reported that Madison Square Garden maintained a celebrity database with risk scores and biometric-linked monitoring in New York City, with entries updated through early June.
USA Today07-09-2026
Wired reported Madison Square Garden maintained an identity-labeling talent database later leaked by ShinyHunters, followed by class-action lawsuits.
Washington Times07-09-2026
ShinyHunters used vishing to access Madison Square Garden systems and leaked a talent database with identity labels and alleged Dolan-criticism risk scores, prompting federal class-action lawsuits.
CNET / Tyler Graham06-24-2026
Hackers reportedly published a 45GB cache from Madison Square Garden Entertainment in June, exposing activist dossiers and biometric-linked customer records amid class-action litigation.
CNET / Tyler Graham06-24-2026
Madison Square Garden Entertainment faced lawsuits after a June hack reportedly leaked biometric and personal data about customers and activists in New York City.
Tech Times06-21-2026
ShinyHunters leaked 297 gigabytes of Council of Europe employee data after a June 16 ransom deadline, citing an Oracle PeopleSoft zero-day exploited before user warnings.
ClassAction.org / Tracy Bagdonas06-17-2026
A proposed class action filed after an April 2026 cyberattack alleges 7-Eleven failed to encrypt or redact PII stolen by ShinyHunters.
BleepingComputer / Lawrence Abrams04-13-2026
ShinyHunters published an alleged Rockstar Games data leak in 2020s, claiming access via stolen authentication tokens from an Anodot incident impacting Snowflake-linked analytics and support data.
Insurance Business / Matthew Sellers06-28-2026
ShinyHunters published 3.1TB of claimed NAIC breach data in late June 2026 after NAIC confirmed an Oracle PeopleSoft intrusion and Google Mandiant confirmed attribution.
CybersecurityNews / Guru Baran04-25-2026
ADT confirmed a data breach in an SEC filing on April 24, 2026 after a ShinyHunters claim of more than 10 million customer records.
HITC / Ishika Dadhwal06-18-2026
Madison Square Garden Entertainment is sued in New York federal court in a proposed class action over an alleged breach exposing facial-recognition and sensitive consumer data.
Heavy / Jonathan Vankin07-10-2026
ShinyHunters leaked Madison Square Garden Entertainment files in 2024, exposing a celebrity risk scoring database and other personal data used for venue screening.
Yahoo07-09-2026
ShinyHunters released stolen Madison Square Garden records in June after a ransom threat, exposing an attendee database tied to sensitive identity attributes.
Front Office Sports06-17-2026
Carlos Avalo filed a proposed class action in New York federal court alleging Madison Square Garden Entertainment suffered a breach exposing biometric and identity data claimed by ShinyHunters in 2025.
Techtimes / Kyle Belmonte05-24-2026
On April 8, 2026, 7-Eleven reported a franchise application systems breach that exposed Social Security and driver's license data for some franchisees, with notifications sent May 1 and regulator filings in Maine, Vermont, and Massachusetts mid-May.
C-Store Dive05-20-2026
7-Eleven disclosed a spring intrusion discovered April 8, and Massachusetts, Maine, and Vermont filings reported exposure of franchisee names, addresses, and some SSNs and driver’s license data.
All About Cookies / Thomas Kent05-30-2026
ShinyHunters published stolen 7-Eleven franchise applicant records on May 24 after a breach discovered April 8 exposed SSNs and driver license details for more than 185,000 people.
Gadgetreview / Nikshep Myle06-16-2026
ShinyHunters published a near-45 GB data dump from MSG Sports on a dark-web blog after a June 15, 2026 ransom deadline passed without payment.
GovInfoSecurity06-30-2026
Nissan and NAIC confirmed ShinyHunters-linked cyber extortion attacks using a PeopleSoft PeopleTools zero-day, with potential employee data exposure across the U.S., Canada, Mexico, and Brazil.
Endtimeheadlines06-26-2026
ShinyHunters allegedly leaked about 45GB of facial recognition and biometric data from Madison Square Garden Entertainment after a missed ransom deadline in mid-June 2026.
BankInfoSecurity / Mathew J. Schwartz06-30-2026
ShinyHunters ransomware operators used a PeopleSoft zero-day to extort multiple organizations, including Nissan and NAIC, with breach notifications filed in California.
Databreachtoday06-19-2026
ShinyHunters threatened to publish alleged 8.8TB of One Medical patient data on June 22 after unauthorized access to third-party archived health records in June.
Security Affairs / Pierluigi Paganini06-07-2026
ShinyHunters leaked a 234 GB archive allegedly stolen from DentaQuest in the United States, potentially exposing data for about 2.6 million individuals.
Technadu / Lore Apostol07-27-2026
Threat actors reportedly used leaked email addresses from ShinyHunters-linked breaches to send sextortion emails demanding Bitcoin, prompting recipient warnings not to respond or open attachments.
Tech Jacks Solutions Security Command Center / Tech Jacks Solutions06-17-2026
UNC6395 claimed responsibility for an Eastman Kodak Company breach by June 18, 2026, warning of release of 2.2 million records tied to SaaS integrations.
Security Magazine05-19-2026
7-Eleven disclosed an April 8 data breach in Maine involving unauthorized access to franchise application systems, with ShinyHunters claiming responsibility.
Security Magazine / Jordyn Alger06-17-2026
Kodak confirmed a ShinyHunters data breach claim on 2.2 million records, with a June 18 leak threat, after an unknown compromise method.
AI Weekly06-15-2026
Council of Europe investigates a ShinyHunters dark web leak claim after a June 16 threat covering 429,000+ employee records allegedly exposed via an Oracle PeopleSoft zero-day campaign.
Pluang06-24-2026
Madison Square Garden Entertainment faced class-action lawsuits after a hacker leak exposed 26 million customer records containing sensitive biometric data.
MS NOW07-24-2026
Madison Square Garden temporarily disabled facial recognition during Taylor Swift's wedding as reporting raised concerns about private biometric surveillance and limited legal safeguards in US venues.
Kavout05-21-2026
7-Eleven confirmed a May 2026 ShinyHunters breach that exposed over 600,000 Salesforce records containing franchisee PII, with notices going to Maine and Massachusetts.
All About Cookies / Sara J. Nguyen07-10-2026
French authorities arrested suspected individuals linked to ShinyHunters in 2025 after the group used social engineering and identity bypasses for large-scale data extortion.
Almeida Law Group06-06-2026
Rockville Fuel and Feed Company Inc. disclosed May 11, 2026 discovery of a breach after network suspicious activity on April 1, 2026, with notifications issued June 5, 2026.
Architecture & Governance / Holt Hackney07-14-2026
Carlos Avalos filed a class action in New York federal court against Madison Square Garden over an alleged ShinyHunters breach involving patron biometric and PII collection.
Kiteworks / Patrick Spencer05-20-2026
ShinyHunters announced April 2026 access to Rockstar Games' Snowflake environment through Anandot, with vendor credential privilege described as the pivot enabling data exfiltration.
DoControl / Albert Louison07-03-2026
Madison Square Garden Sports reported a ShinyHunters breach in New York, with alleged 46 GB data exfiltration beginning via EntraID and exposing potential facial recognition data.

⭐⭐⭐

BleepingComputer / Sergiu Gatlan05-19-2026
ShinyHunters claimed a 7-Eleven ransomware-linked Salesforce breach on April 17, followed by a May 1 notification effort after dark web data leakage.
BleepingComputer / Sergiu Gatlan06-17-2026
Kodak engaged external cybersecurity experts in 2026 after unauthorized access to limited company data, as ShinyHunters claimed more than 2.2 million PII records and threatened leaks.
Seeking Alpha07-19-2026
Madison Square Garden Entertainment sued Wired in connection with alleged false LGBTQ+ data discrimination claims following prior cyberattack reporting.
Yahoo / Scooby Axson07-09-2026
ShinyHunters released about 26 million stolen records tied to Madison Square Garden attendee risk scoring and sensitive attribute labeling in June, leading to class-action lawsuits.
New York Times06-23-2026
ShinyHunters ransomware demands and record publication against Madison Square Garden entities led to Southern District of New York class-action lawsuits filed in June.
New York Times06-23-2026
Customers filed class-action suits in the Southern District of New York after ShinyHunters allegedly leaked over 26 million records from Madison Square Garden in June.
Cybernews / Paulina Okunytė06-12-2026
ShinyHunters threatened to release alleged stolen records from JCPenney by June 15, 2026, including Social Security numbers and driver license scans.
Cybernews06-18-2026
ShinyHunters issued a dark web claim of 8.8TB stolen from One Medical, with a June 22 negotiation deadline, as medical data exposure risks remain unverified.
Security Boulevard / John Kevin Hao06-17-2026
Kodak confirmed unauthorized temporary data access in connection with ShinyHunters extortion claims, as investigation efforts focused on accessed data containing customer PII.
404 Media / Joseph Cox06-23-2026
Madison Square Garden internal document listing facial recognition activists was exposed online after hackers posted a 45GB stolen data cache this month.
AI Weekly06-18-2026
Kodak confirmed temporary access to limited company data on June 18 after ShinyHunters claimed theft of over 2.2 million records with a deadline for public release.
The Register / Carly Page04-27-2026
ADT reported an April 20 intrusion exposing customer PII, while ShinyHunters claimed over 10 million Salesforce records were stolen after talks with ADT failed.
Help Net Security / Sinisa Markovic05-26-2026
7-Eleven disclosed a 2026 cyberattack discovered April 8 that exposed about 185,000 franchise applicant records, after ShinyHunters claimed responsibility.
Top Class Actions06-17-2026
Carl Ellison and Rebecca Choplin filed two Northern District of Texas class actions in 2026 over 7-Eleven alleged April 2026 exposure of unencrypted PII tied to ShinyHunters extortion.
Claim Depot05-18-2026
7-Eleven notified the Maine Attorney General in 2026 and started letters May 1 after unauthorized access exposed franchise application personal data.
Malwarebytes / Pieter Arntz06-18-2026
Kodak reported an ongoing investigation after ShinyHunters claimed theft of 2.2 million records and issued a June 18 data leak threat.
Polygon04-14-2026
ShinyHunters demanded payment from Rockstar Games on April 11 and released leaked documents allegedly detailing GTA Online and Red Dead Online financial metrics.
CSP Daily News / Hannah Hammond05-20-2026
7-Eleven reported an April 8 data breach affecting 50 franchisees in Massachusetts, Vermont, and Maine through unauthorized access to franchisee document systems.
Cyber Defense Magazine / Carmen Estela06-22-2026
Eastman Kodak Company reported a ShinyHunters extortion threat tied to alleged access to company data and potential exposure of customer PII by June 18, 2026.
HookPhish05-24-2026
ShinyHunters published April 2026 leaked data from a 7-Eleven extortion campaign affecting 185k unique email addresses and other personal fields.
Security Affairs / Pierluigi Paganini05-18-2026
ShinyHunters claimed stolen Salesforce records from 7-Eleven, and 7-Eleven confirmed unauthorized access to franchisee document systems on April 8, 2026.
CPO Magazine / Alicia Hope06-22-2026
Eastman Kodak Company investigated a data breach involving more than 2 million customer records in Rochester, New York, after ShinyHunters claimed theft and dark-web leak threats in June 2026.
CPO Magazine / Alicia Hope06-24-2026
ShinyHunters claimed responsibility on June 12, 2026 for a Madison Square Garden Sports and New York Knicks breach, exposing 26M+ records and demanding ransom before June 15.
Have I Been Pwned05-02-2026
ShinyHunters released a ZenBusiness dataset in April 2026 after March 2026 extortion claims involving Snowflake, Mixpanel, and Salesforce and exposure of about 5 million email addresses.
Have I Been Pwned05-12-2026
ShinyHunters targeted Cushman and Wakefield in May 2026 with pay or leak extortion and published alleged corporate contact data.
Have I Been Pwned05-24-2026
ShinyHunters published leaked personal data from 7-Eleven in April 2026, exposing 185,000 unique email addresses and additional identifiers tied to franchisee documents.
Have I Been Pwned06-01-2026
In early June 2026, ShinyHunters published alleged data from Baker Distributing Company SharePoint and Salesforce, including 103,000 contractor email addresses and contact details.
TechNadu / Lore Apostol06-29-2026
Sysco faced a June 2026 ShinyHunters extortion leak, and Have I Been Pwned added 2,691,852 exposed accounts on June 28.
The National CIO Review / Emily Hill04-16-2026
McGraw Hill confirmed a Salesforce-hosted data breach in 2020s reporting, attributed to ShinyHunters, after misconfiguration exposed millions of accounts' contact details.
PCMag / Michael Kan04-24-2026
ADT disclosed a ShinyHunters-linked data breach on April 20 detection after a dark web leak threat, exposing limited customer personally identifying information.
PCMag04-24-2026
ADT said a breach detected April 20 exposed customer and prospective customer identifiers and led to forensic investigation and notifications after ShinyHunters ransom threats.
PCMag04-24-2026
ADT disclosed an April 20 data breach linked to ShinyHunters after dark-web extortion threats, exposing names, phone numbers, and addresses in some cases.
PCMag04-24-2026
ADT detected a ShinyHunters-linked intrusion on April 20, exposing limited customer data and triggering forensic investigation and identity-protection offers.
PR Newswire06-18-2026
Edelson Lechtzin LLP opened an investigation in June 2026 into JCPenney and Catalyst Brands breach disclosures discovered around June 12, involving sensitive identity records.
TipRanks06-19-2026
Madison Square Garden Entertainment Corp. faces investor pressure in response to a massive biometric and personal data breach affecting up to 26 million visitors.
Security Boulevard / Evan Rowe04-12-2026
Rockstar reported no player data impact after a third-party cloud or analytics compromise, with privacy response guidance focused on incident scope and leak-threat handling.
Forbes / Davey Winder04-12-2026
ShinyHunters set an April 14 deadline for Rockstar Games after a reported third-party breach tied to stolen authentication tokens used for cloud platform access.
Mashable / Alex Perry04-13-2026
ShinyHunters set an April 14 deadline for payment tied to alleged Rockstar Games Snowflake compromise via Anodot.com, while Rockstar described limited non-material third-party breach access.
Newsweek04-11-2026
Rockstar Games confirmed limited third-party breach access to non-material information in 2020s reporting involving Anodot and Snowflake authentication tokens.
IGN04-11-2026
Rockstar Games confirmed a third-party breach involving alleged authentication-token access to its Snowflake instance via compromised Anodot after ShinyHunters claims in a reported extortion attempt.
IGN04-13-2026
ShinyHunters told BBC it breached Rockstar Games' Snowflake data warehouse using Anodot and planned data publication after an unmet April 14 ransom demand.
TweakTown / Derek Strickland04-11-2026
Rockstar Games confirmed an unauthorized access incident linked to a third-party analytics tool, denying compromise of player data and GTA 6 source code.
VGC04-11-2026
Rockstar Games disclosed a third-party breach after ShinyHunters claimed access via analytics platform Anodot and issued a leak threat.
GamesIndustry.biz / Sophie McEvoy04-13-2026
Rockstar Games confirmed a third-party vendor breach on April 11 involving Anodot access to Snowflake servers after a hacking group claim.
Morgan & Morgan06-19-2026
Morgan & Morgan sued Madison Square Garden Entertainment Corp. in a class action over a June 16 ShinyHunters hack that allegedly exposed millions of consumer records, including biometric data.