Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
underground-data-leakvoice-social-engineeringidentity-authentication-vulnerabilitycloud-misconfiguration

ShinyHunters Claims Cisco Breach Exposed Salesforce Records and Cloud Data

Updated 2mo agoFirst seen Apr 1, 20266 sources

ShinyHunters has claimed responsibility for breaching Cisco and stealing more than 3 million Salesforce records along with internal corporate data, GitHub repositories, and contents from AWS S3 buckets, then posted a "FINAL WARNING" on its leak site threatening to publish the data after April 3. Reports said the alleged haul may include information tied to Cisco customers, employees, and personnel from U.S. and foreign government agencies, while screenshots shared by the group purportedly showed access to Cisco-linked AWS infrastructure and multiple connected cloud accounts.

The intrusion was linked in reporting to three alleged access paths involving Salesforce CRM, Salesforce Aura/Experience Cloud, and AWS environments, and to activity tracked as UNC6040 and UNC6395. Threat intelligence cited in the coverage said the attackers have used vishing to trick employees into approving malicious Salesforce OAuth applications, then abused stolen tokens to bypass MFA and move deeper into cloud environments; recommended defenses included auditing connected OAuth apps, revoking suspicious tokens, tightening API access controls, and monitoring for unauthorized Salesforce Data Loader activity. Cisco had not publicly addressed the March 2026 extortion claim at the time of reporting.

Share:
ShinyHunters Claims Cisco Breach Exposed Salesforce Records and Cloud Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 1, 20263mo ago

Cisco has not publicly addressed the March extortion claim

As of the April 1, 2026 reporting, Cisco had not publicly responded to the March 2026 ShinyHunters extortion claim. Researchers urged immediate Salesforce-focused mitigations such as auditing OAuth apps, revoking suspicious tokens, and monitoring for unauthorized Data Loader activity.

Reports detail alleged Cisco intrusion paths and stolen data

Subsequent reporting said the alleged Cisco data originated from Salesforce environments and may include records tied to customers, employees, and U.S. and foreign government personnel. The claimed intrusion paths included Salesforce CRM, Salesforce Aura/Experience Cloud, and AWS environments, with screenshots allegedly showing access to Cisco-linked AWS infrastructure.

Mar 31, 20263mo ago

ShinyHunters posts Cisco extortion claim with April 3 deadline

In late March 2026, ShinyHunters posted a 'FINAL WARNING' on its leak site claiming responsibility for breaches affecting Cisco and threatening to leak data after April 3, 2026. The group alleged compromise of more than 3 million Salesforce records along with internal data, GitHub repositories, and AWS S3 buckets.

Aug 1, 202511mo ago

Cisco describes vishing campaign targeting employee access

Cisco previously disclosed a vishing campaign in which attackers targeted employees to gain access to internal systems and customer data. Later reporting connected this activity to tactics used by ShinyHunters-linked clusters abusing Salesforce OAuth access.

Google designates ShinyHunters activity cluster as UNC6040

Google Threat Intelligence Group assigned the ShinyHunters-linked intrusion activity the cluster name UNC6040 in August 2025. The designation was used in later reporting about Salesforce-focused intrusions and extortion activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
Threat actors
3 linked
Affected products
5 linked
GithubAmazon Web ServicesCiscoGoogleTrivy
Organizations
26 linked
SalesforceCisco SystemsAmazon Web ServicesGitHubBleepingComputerCybernewsGoogleCrunchbaseLitellmSnowflakeOktaAlexander McQueenAdvanced Micro DevicesFarmers InsuranceHackReadResecurityQantasGapSoundcloudBalenciagaGucciLastPass US LPVietnam AirlinesOdidoTelus DigitalSony Group Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.