Vulnerabilities · 188 days ago
Salesforce warns attackers target misconfigured Experience Cloud Aura endpoints that let guest users query CRM data. ShinyHunters claims active exploitation and attackers use a modified AuraInspector to find misconfigurations and steal data. Audit guest profiles, disable guest API access and remove
6 sources covering this story
ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites - Help Net Security
Salesforce customers have, once again, been targeted by the ShinyHunters group - or, at least, it's what the group claims.
Salesforce issues new security alert tied to third customer attack spree in six months
Researchers said the threat group behind the campaign is associated with ShinyHunters, an outfit that’s previously stolen data from Salesforce instances for extortion attempts.
Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool
Modified AuraInspector scans misconfigured Salesforce Experience Cloud sites, extracting CRM data and enabling targeted vishing campaigns.
Hundreds of Salesforce Customers Allegedly Targeted in New Data Theft Campaign
Salesforce has confirmed that customers are being targeted via poorly secured instances.
ShinyHunters Targets Hundreds of Websites in New Salesforce Campaign
Prolific ShinyHunters group claims to have stolen data from nearly 400 websites in Experience Cloud attacks
ShinyHunters claims ongoing Salesforce Aura data theft attacks
Salesforce is warning customers that hackers are targeting websites with misconfigured Experience Cloud platforms that give guest users access to more data than intended.
Part of the PlainSec briefing for 2026-03-15