Last Update: 08/01/2026 at 1:00 PM EST

ShinyHunters Breaches Salesforce Customers

Coverage from WIRED, The Boston Globe, and others

Articles

99

Active Days

108

The Topic

ShinyHunters Breaches Salesforce Customers topic image

ShinyHunters is associated with a broad campaign of data theft and extortion against organizations using enterprise platforms and customer-data systems. Reported incidents involving 7-Eleven, McGraw Hill, Kodak and the Council of Europe show a recurring pattern of unauthorized access claims, ransom demands and threatened or completed publication of stolen records. The disclosures expose personal, financial and organizational information, while victim organizations continue to investigate the scope and authenticity of the claims.

First Article: 04/11/26

Latest Article: 07/27/26

History

07/23/20260 new articles

The story is now framed more concretely around named incidents at 7-Eleven, McGraw Hill, Kodak and the Council of Europe, rather than a broader, less specific pattern of ShinyHunters-linked extortion. It also adds the FBI’s guidance that ransom payment does not reliably stop further extortion or data resale.

07/22/20263 new articles

The story has narrowed from a broader privacy mix into a more focused account of an ongoing ShinyHunters cyberextortion campaign. The current version adds clearer scale and outcome details, including confirmed large exposures in some cases and a wider set of victim types.

  • Confirmed millions of McGraw Hill email addresses were exposed.
  • 7-Eleven leak affected more than 185,000 people.
  • Council of Europe is now among the implicated organizations.
  • Victims are notifying law enforcement and containing incidents.
  • ShinyHunters' claims are described as partly unverified.
07/17/202614 new articles

The story has broadened from ShinyHunters-linked breach/extortion incidents into a wider privacy-and-surveillance narrative that now includes Madison Square Garden’s biometric monitoring practices and resulting litigation. It also adds clearer technical pathways—especially cloud vendors and identity tools—behind several breaches, while showing some incidents as limited or disputed rather than uniformly severe.

  • Madison Square Garden surveillance practices are now a distinct privacy track.
  • MSG faces a lawsuit over biometric safeguards and informational harm.
  • New breach paths include Snowflake, Anodot, and Okta.
  • Some companies now say only non-material information was accessed.
  • The timeframe extends into July 2026, with older Rockstar context added.
06/24/20265 new articles

The story now places more emphasis on operational and franchisee-system exposure, not just consumer data leakage, and adds Eastman Kodak Company as a new affected entity. It also sharpens the risk picture by highlighting follow-on misuse of stolen data for phishing, impersonation, and fraud.

06/21/20266 new articles

The story has broadened to include additional named victims and access paths, with newer reporting emphasizing identity-provider, archived-storage, and third-party analytics exposure rather than just CRM/cloud intrusions. The framing also shifts toward operational incident handling, with filings and forensic findings now central alongside leak claims.

06/19/202612 new articles

The story has broadened from a general cluster of ShinyHunters-linked cloud breaches into a more specific, denser pattern centered on SaaS/CRM access paths, vendor integrations, and active notification and investigation activity. New company examples also sharpen the scope of exposed data, especially identity records, tax forms, and franchisee or internal operational files.

06/16/20263 new articles

The story has broadened from a recurring ShinyHunters breach-and-leak pattern into a more specific cloud-ecosystem narrative centered on Salesforce, Snowflake, and third-party tools, with more explicit claims of extortion deadlines and downstream privacy harm. It also now includes some institutional and regulatory-disclosure angles that were less visible before.

06/08/20264 new articles

The story broadens from a single 7-Eleven/ShinyHunters incident to a wider pattern of similar cloud- and vendor-mediated breaches across multiple companies. The new version frames this as a recurring extortion-and-leak campaign rather than an isolated case.

  • Multiple new companies are now part of the breach-and-leak pattern.
  • Other extortion branding appears alongside ShinyHunters.
  • Vendor and third-party access is presented as a recurring failure point.
  • Breach notifications and leak follow-up are now part of the ongoing storyline.
05/30/2026Topic Formed

Recent reporting shows 7-Eleven dealing with a breach affecting franchisee and applicant records, while ShinyHunters escalates the incident through leak-site claims and data publication tied to Salesforce access and extortion pressure.