Berkadia, one of the largest commercial real estate and mortgage banking firms in the United States, has been confirmed as a victim in a ShinyHunters "pay or leak" extortion campaign. According to disclosure from Have I Been Pwned, the breach notification platform maintained by security researcher Troy Hunt, attackers exfiltrated data from Berkadia's Salesforce environment and published more than 300,000 unique email addresses after the company was targeted in March 2026. Roughly 76 percent of those addresses had appeared in prior breach datasets, but the exposure still hands threat actors fresh material to correlate and weaponize.
What Happened
Berkadia was allegedly compromised in March 2026 by ShinyHunters, a threat group that has become one of the most recognized names in the cybercrime underground over the past several years. The attackers claimed to have accessed data residing in the company's Salesforce environment, then escalated to extortion: pay the demand, or the stolen dataset goes public. When demands were not met, the group followed through, publishing a large dataset of email addresses.
The incident was surfaced through breach notification tracking services and confirmed by Have I Been Pwned, which logged the exposure as a ShinyHunters extortion operation. This is the increasingly common double-pressure model, where the public threat of disclosure is the leverage, not the encryption of systems.
What Was Taken
The published dataset contained more than 300,000 unique email addresses tied to Berkadia. Have I Been Pwned reported that approximately 76 percent of those addresses were already present in previous breach collections it maintains.
While that overlap reduces the novelty of some records, it does not reduce the risk. Every fresh exposure gives attackers another data point to stitch together across multiple leaks, building more complete victim profiles for targeted phishing, business email compromise, and credential-stuffing campaigns. Email addresses tied to a named financial and real estate firm are especially valuable for crafting convincing, industry-specific lures.
Why It Matters
This breach is a textbook example of where modern cybercrime has shifted. Attackers no longer need to encrypt a single file to extract a payday. By stealing sensitive data and threatening public exposure, groups like ShinyHunters exploit a simple truth: organizations often fear reputational damage more than operational downtime.
It also underscores the systemic risk of cloud-based business platforms. Berkadia's data was reportedly pulled from Salesforce, part of a broader wave of incidents in which attackers target SaaS environments rather than on-premise infrastructure. For defenders, the lesson is that the crown jewels increasingly live in third-party clouds, and the security controls protecting them are only as strong as the configurations and credentials guarding access.
The Attack Technique
ShinyHunters' established playbook centers on gaining unauthorized access to corporate environments, extracting valuable data, and threatening disclosure. In this case, the entry point was the company's Salesforce environment.
While the specific intrusion vector has not been publicly confirmed, ShinyHunters campaigns against Salesforce tenants have historically leaned on social engineering, voice phishing of employees, abuse of OAuth-connected applications, and stolen or phished credentials rather than novel exploits. The group's strength lies in operating at the human and access-management layer, then leveraging legitimate platform functionality to bulk-export data once inside.
What Organizations Should Do
- Enforce phishing-resistant multi-factor authentication on all SaaS platforms, especially Salesforce and other CRM systems holding customer data.
- Audit and restrict connected/OAuth applications in your SaaS tenants, removing unused integrations and limiting the scope of API access tokens.
- Train staff against voice phishing and help-desk social engineering, the tactics ShinyHunters frequently uses to obtain initial access.
- Monitor for anomalous bulk data exports and unusual API activity within cloud platforms, and alert on large query or download volumes.
- Notify affected individuals and prepare for downstream targeted phishing, since exposed email addresses will fuel follow-on lures referencing Berkadia.
- Assume reuse and correlation: rotate credentials, monitor for credential-stuffing, and check exposed accounts against known breach datasets.
Sources: Berkadia Data Breach Exposes Hundreds of Thousands of Records After ShinyHunters Extortion Campaign