On August 7, 2026 at 3:00 PM ET, the extortion group ShinyHunters listed a partially redacted enterprise victim, tracked publicly as "Ali** **********" in the technology sector, on its Tor leak site. The group claims to have taken more than 11.5 million records spanning Salesforce, ServiceNow and Entra, including some customer and employee PII, plus more than 3.1TB of internal corporate data. The listing carries a final contact deadline of August 10, 2026 before publication. Readers should be clear on the evidentiary standing here: this is an actor claim tracked by ransomware.live and republished by hendryadrian.com (S1), and the monitoring post itself carries an explicit disclaimer that the accuracy of the information cannot be confirmed. No victim statement, regulator filing or national CERT advisory naming this organisation appears in the available sourcing. The technical pattern the claim fits, however, is documented in detail by Microsoft, the highest-tier source in this set.
What Happened
The sequence, as recorded by the monitoring source, is tight. ShinyHunters posted the listing on August 7 at 3:00 PM ET, with a publication timestamp of August 8 and an update the same day; the entry was picked up by automated leak-site monitoring on August 9 at 09:29 UTC. The listing is styled as a "final warning, pay or leak," demanding contact by August 10, 2026, and threatening that non-response will result in publication of the stolen data "along with additional disruptive digital consequences."
Two details in the listing are worth flagging for anyone tracking attribution. First, the victim name is redacted in the syndicated post, but the cited onion URL carries the fragment #AlienTechnology, which points at the identity behind the mask. We are not treating that as confirmed identification, because it rests on a single OTHER-tier source and no organisation has acknowledged the incident. Second, the impacted country field in the listing is empty, so geographic exposure and therefore the applicable breach-notification regimes are currently unknown.
The claim sits inside a dense run of ShinyHunters activity. On August 1, 2026, the group listed Questel SAS, Alcon Inc. and Lumenis Ltd. on the same leak site, claiming more than 21 million Salesforce records and roughly 147GB of internal data from Questel, more than 25 million Salesforce records from Alcon, and more than 1.1 million records plus over 176GB of internal data from Lumenis, each with an August 4 contact deadline (breachnews.com). None of those three had issued a public statement at the time of reporting either. The August 7 listing is structurally identical: SaaS record counts, a bulk internal-data figure, a short fuse.
Separately, SC Media reported that the National Association of Insurance Commissioners confirmed a cyberattack in which ShinyHunters claimed 3.1 terabytes of stolen data. Note that this is a distinct incident with a distinct intrusion path, disclosed on June 17 after detection on June 11, and the numeric coincidence with the 3.1TB figure in the August 7 listing should not be read as a link between the two. It is, though, a useful reminder that the group's headline volume figures repeat across listings and should be treated as marketing until corroborated.
What Was Taken
Per the leak-site listing, and only per the leak-site listing:
- More than 11.5 million records across three platforms: Salesforce, ServiceNow and Entra.
- Some customer and employee personally identifiable information within those records.
- More than 3.1TB of internal corporate data described as separately accessed.
No record-count range is available for this victim, because only one source reports the figure. Where the wider ShinyHunters campaign is concerned, the reported per-victim counts vary widely: 1.1 million (Lumenis) to more than 25 million (Alcon) in the August 1 batch, against 11.5 million here. That spread is consistent with tenant-by-tenant CRM enumeration rather than a single fixed dataset.
The three-platform combination is the part that should get attention. A Salesforce-only claim implies CRM contact, account and opportunity data. Adding ServiceNow pulls in ticketing, asset inventory, internal support notes and, depending on configuration, credential-adjacent material captured in ticket bodies. Adding Entra implies exposure of directory data, which means employee identity records and potentially application and service-principal relationships. Where the NAIC incident produced a public dispute over data sensitivity, with NAIC stating that the stolen material was largely public statutory filings, ratings data and outdated logs and configuration files while ShinyHunters claimed the cache included PII, no such counter-statement exists here. That asymmetry, actor claim with no rebuttal, is the current state of the record.
Why It Matters
The strategic point is not the record count. It is that identity-layer and SaaS-layer compromise now travels together.
Microsoft's July 13, 2026 research, the strongest source in this set, states plainly that in campaigns observed between mid-2025 and mid-2026, threat actors with tradecraft overlapping ShinyHunters abused trusted OAuth relationships for unauthorised access, data exfiltration and persistence, and that a single entry point can rapidly expand to greater enterprise impacts. A claim covering Salesforce, ServiceNow and Entra simultaneously is exactly what that expansion looks like when it succeeds.
The NAIC case shows the other end of the same problem: SC Media reported that ShinyHunters exploited a zero-day in Oracle PeopleSoft starting May 27, compromising over 100 organisations before Oracle shipped an emergency update on June 10. Same actor, entirely different access vector, comparable scale. Defenders who model ShinyHunters as "the Salesforce group" are modelling one campaign, not the adversary.
Third-party and integration exposure is the connective tissue across the rest of this reporting. Lidl told customers in Germany, Belgium and the Netherlands that attackers stole personal data through a breach at an external IT service provider, with the online shop system itself unaffected (BleepingComputer, Security Affairs). Chick-fil-A confirmed that credential-stuffing attacks between June 17 and June 19 used credentials "obtained from a third-party source," with filings to the Maine Attorney General putting the total at 13,322 people, 2,182 of them in Texas and 39 in Massachusetts (BleepingComputer). Different actors, different scale, same structural lesson: the data leaves through a relationship, not through the front door.
And the tail is expensive. Fidelity and Fidelity Brokerage Services agreed on May 13 to a $2.5 million settlement over a 2024 breach, with final approval on July 9, 2026, a July 27 claim deadline, individual reimbursement up to $5,000, estimated cash payments of roughly $100 to $150, and two years of credit monitoring (CNBC). Plaintiffs alleged suspicious activity was detected between August 17 and 19, 2024 but customers were not notified for nearly two months; Fidelity denied wrongdoing and cited litigation risk in settling. Notification latency, not just the intrusion, is what gets litigated.
The Attack Technique
No intrusion path has been published for the August 7 listing. What follows is the documented tradecraft for this actor set, from Microsoft, and should be read as the likely pattern rather than as confirmed facts about this victim.
Microsoft identified two primary intrusion paths. The first is vishing, voice phishing aimed at getting a user to approve an OAuth consent grant. The second is supply chain compromise through trusted workflows and integrations, with Salesloft and Gainsight named specifically. Both routes deliver the same outcome: the attacker inherits user and application privileges and can enumerate and query CRM records while evading conventional authentication detections, because the traffic rides a legitimate, already-consented token rather than a suspicious login.
Microsoft is explicit that this activity was not the result of a vulnerability inherent to Salesforce. The abused component is the trust relationship. Microsoft also reported observing this activity across many tenants in industries including retail, education and manufacturing, and said it consulted with Salesforce to improve telemetry granularity for Defender for Cloud Apps, adding near-real-time detection, connected-application attribution and expanded application permission insights.
The reason an OAuth-consent path plausibly produces a Salesforce plus ServiceNow plus Entra claim is that consent abuse is an identity-plane technique. Once an attacker holds a token with inherited privileges and can see the directory, the reachable application estate is whatever that identity was already trusted to reach.
What Organizations Should Do
- Inventory and prune OAuth grants across Entra and Salesforce. Enumerate every connected application, service principal and consented scope. Revoke anything unused, over-scoped or unattributable to a current business owner. This is the single control that most directly addresses the documented path.
- Restrict user consent. Move to admin-consent workflows for third-party applications so that a successful vishing call cannot, by itself, produce a durable data-access grant. Alert on new consent grants and on high-privilege scope requests.
- Turn on Salesforce event monitoring and treat bulk query volume as a detection signal. Microsoft specifically recommends enabling event monitoring; the tell for this tradecraft is anomalous API query and export volume from a legitimate connected app, not a failed login curve.
- Re-validate every third-party integration, including the ones you did not procure. Salesloft and Gainsight are named by Microsoft; Lidl and Chick-fil-A both trace their exposure to third-party relationships. Ask each vendor what tokens they hold against your tenant and what their own compromise-notification commitment is.
- Harden the human path into the help desk. Vishing works against identity-verification procedures, not against firewalls. Require out-of-band verification for MFA resets, device enrolments and consent approvals, and rehearse it.
- Pre-build the notification decision. Fidelity's settlement turned substantially on a roughly two-month notification gap. Know now who decides, on what evidence, and against which state and EU deadlines, so that decision is not being invented during an active extortion window.
- Assume the deadline is theatre and the data movement already happened. The August 10 contact deadline is a pressure device. Whether or not it passes quietly, the remediation work, token revocation, credential rotation, directory review, is identical.
A closing note on confidence. Everything specific to this victim rests on one OTHER-tier monitoring post reproducing an extortion listing. The volume figures are the attacker's, the victim identity is redacted, the affected country is blank, and no organisation has confirmed anything. Treat the 11.5 million and 3.1TB numbers as unverified claims. The tradecraft context, by contrast, is well documented, and that is the part worth acting on today.
Sources: Ransom! Ali ** (AUG-2026) | Defending SaaS-based applications against ShinyHunters OAuth abuse... | NAIC confirms cyberattack after ShinyHunters claims 3.1TB data thef... | Fidelity Data Breach Settlement: How to Claim Part of the $2.5M Payout | Chick-fil-A data breach affects more than 13,000 customers | Lidl discloses online shop breach after service provider hack | Lidl Notified Online Shop Customers in Germany, Belgium, and the Ne... | ShinyHunters Claims Breaches at Questel, Alcon, and Lumenis