Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites
    Cybersecurity

    ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites

    adminBy adminMarch 11, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Salesforce customers have, once again, been targeted by the ShinyHunters group – or, at least, it’s what the group claims.

    Attackers modified and abused benign tool

    On Saturday, Saleforce confirmed that its security team has identified an attack campaign by unnamed malicious actors looking to access customers’ data.

    The attackers are not leveraging a vulnerability in the Salesforce platform, the company said, but are using a modified version of the open-source tool Aura Inspector – a tool originally developed by Mandiant – to:

    • Mass scan public-facing Experience Cloud sites
    • Probe their /s/sfsites/aura API endpoint
    • If the guest user profile has excessive permissions, query Salesforce CRM objects without logging in.

    Salesforce urged customers to review their guest user permissions and enforce a “Least Privilege” access model by restricting access for guest users to needed records only and to explicitly shared records only.

    Also, to make necessary changes so that unauthenticated users can’t query data through API endpoints and can’t view or enumerate internal users. Finally, the company said, they should disable the self-registration option (if it’s not required).

    “[Disabling public APIs] is the highest-impact single change you can make. It closes the Aura endpoint to unauthenticated API queries, which is the exact vector used in this campaign,” the company stated.

    Salesforce also advised customers to notify the company’s Support team if they believe or suspect their environment has been affected. Possible indicators of compromise can be found in customers’ Aura Event Monitoring logs, and include queries targeting objects not intended to be public, unexpected spikes from unfamiliar IP addresses, or access outside normal business hours.

    ShinyHunters: An old Salesforce foe

    Salesforce says that the data harvested is these attacks is usually names and phone numbers, which can be used for follow-on targeted social engineering and vishing campaigns.

    But a more immediate problem for the potentially affected companies is ShinyHunters’ usual course of action: cyber extortion, i.e., “pay not to get your stolen data leaked”.

    The group claimed the breach on their data leak site and told Bleeping Computer that they’ve been compromising companies with insecure Experience Cloud access control configurations for guest users since September 2025, but modified and started using the AuraInspector tool in January 2026, when it was released “to help defenders identify and audit access control misconfigurations within the Salesforce Aura framework.”

    The group has previously targeted Salesforce customers via third-party integrations (Salesloft / Drift) and connected apps (Gainsight).

    ShinyHunters stated that they’ve stolen data from around 100 high-profile companies this time around.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    Campaign claims Cloud experience Salesforce ShinyHunters Sites targeting
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWordPress Security Release 6.9.4 Fixes Issues 6.9.2 Failed To Address
    Next Article GrapheneOS coming to Motorola phones is exactly the Android news I wanted
    admin
    • Website

    Related Posts

    Senate Confirms Joshua Rudd to Lead NSA and US Cyber Command

    March 12, 2026

    Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes

    March 11, 2026

    Google completes $32B acquisition of Wiz

    March 11, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Senate Confirms Joshua Rudd to Lead NSA and US Cyber Command

    March 12, 2026

    Yahoo adds personalized homepage to its Scout AI search engine

    March 12, 2026

    Microsoft Will Soon Let You Use Any Windows 11 PC Like an Xbox

    March 12, 2026

    Datalec targets rapid infrastructure deployment with new modular data centers

    March 12, 2026
    Categories
    • Blogging (37)
    • Cybersecurity (724)
    • Privacy & Online Earning (109)
    • SEO & Digital Marketing (457)
    • Tech Tools & Mobile / Apps (891)
    • WiFi / Internet & Networking (120)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Senate Confirms Joshua Rudd to Lead NSA and US Cyber Command

    March 12, 2026

    Yahoo adds personalized homepage to its Scout AI search engine

    March 12, 2026

    Microsoft Will Soon Let You Use Any Windows 11 PC Like an Xbox

    March 12, 2026
    Most Popular
    • Senate Confirms Joshua Rudd to Lead NSA and US Cyber Command
    • Yahoo adds personalized homepage to its Scout AI search engine
    • Microsoft Will Soon Let You Use Any Windows 11 PC Like an Xbox
    • Datalec targets rapid infrastructure deployment with new modular data centers
    • What Is Landing Page Optimization? And How to Do It
    • Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes
    • Change Google Play Region Guide
    • GrapheneOS coming to Motorola phones is exactly the Android news I wanted
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.