8/13/2025, 10:00:00 PM | www.cpomagazine.com | news
Google Is the Latest Company Hit by Salesforce Hack as ShinyHunters Escalates to Launching Data Breach Site
Google Threat Intelligence has reported that a Salesforce instance within a Google corporate branch was breached in June by the ShinyHunters hacking group, with stolen data limited to basic business contact information. The breach is part of a broader campaign where ShinyHunters and Scattered Spider have reportedly merged or formed a close alliance, with ShinyHunters now preparing to launch a public data leak site to pressure victims. The attack involves both vishing (voice phishing) and infostealer malware, exploiting weak credential hygiene, inconsistent MFA enforcement, and poor SaaS integration practices. Victims include luxury brands like Pandora, Tiffany, Dior, and Louis Vuitton, as well as companies such as Qantas, Adidas, Cisco, and Allianz Life. Despite recent arrests in France and other regions, both groups remain active, and cybersecurity experts emphasize the need for improved identity and access management, including MFA enforcement across all access vectors and reduced human exploitability.