ShinyHunters has posted a technology-sector victim to its Tor leak site claiming 11.5 million records stolen across Salesforce, ServiceNow and Microsoft Entra, plus more than 3.1TB of internal corporate data. The listing carries a final "pay or leak" deadline of 10 August 2026, which is today. One important caveat up front: this claim rests on a single OTHER-tier source, a ransomware.live-derived aggregator post that partially redacts the victim as "Ali **" while linking to a leak-site URL fragment reading #AlienTechnology. There is no victim statement, regulator filing or vendor confirmation for this specific incident in the available sourcing. Everything below about the victim is the attacker's account. What is well corroborated is the campaign around it: Microsoft, BleepingComputer, The Register and SecurityWeek all independently document ShinyHunters running a sustained, high-yield operation against exactly this class of SaaS target through mid-2026.
What Happened
According to the aggregator post monitoring ShinyHunters' leak site, the actor published its claim on 7 August 2026 at 3:00 PM ET, with the listing recorded as published 8 August and discovered by monitoring on 9 August. The post states that more than 11.5 million records were compromised across three separate platforms, Salesforce, ServiceNow and Entra, including customer and employee PII, alongside more than 3.1TB of internal corporate data. The victim is categorised as Technology sector, with no country listed. The extortion note is explicit that this is a final warning: make contact by 10 August 2026 or the data is published "along with additional disruptive digital consequences."
The aggregator itself carries a disclaimer that it cannot confirm the accuracy of the claim and invites an official statement from the affected organisation. As of writing, no such statement appears in the source set. Treat the 11.5M and 3.1TB figures as attacker-supplied marketing until the victim or a regulator says otherwise.
That scepticism is warranted but should not be mistaken for dismissal. ShinyHunters' recent claims have repeatedly held up. When the group listed Brinks Home in late July claiming more than 4.9 million Salesforce records, Brinks Home confirmed a breach it identified on 20 July, and SecurityWeek later reported the group leaked over 41GB of files after no ransom was paid. When the group listed Abbott's Exact Sciences cancer diagnostics business in mid-July, Abbott confirmed unauthorised access, and by 7 August The Register reported the dumped data had been ingested by Have I Been Pwned containing 10.9 million unique email addresses. The pattern is: claim, denial or minimisation, then leak.
What Was Taken
For this incident, the claimed inventory is 11.5 million records spanning three SaaS estates plus 3.1TB of internal corporate data. The breakdown between customer PII and employee PII is not specified, and no per-platform split is given. No independent party has sampled the data.
Comparable, better-evidenced ShinyHunters hauls give a sense of what "records" tends to mean in practice for this crew:
- Brinks Home. ShinyHunters claimed more than 4.9 million Salesforce records to both BleepingComputer and SecurityWeek. Speaking to BleepingComputer, the actor broke this down as more than 1.1 million rows from the Salesforce "Contacts" object plus more than 4,000 rows of employee PII including full names, email addresses, job titles and phone numbers. Note the gap between the 4.9M headline and the 1.1M-row customer detail: the two figures are not reconciled in either outlet, which is a useful reminder that headline record counts and distinct-person counts are different animals.
- Abbott / Exact Sciences. Accounts differ meaningfully here. Abbott's own statements, first on 16 July and updated 5 August, described unauthorised access to "a limited number of internal systems" in its Cancer Diagnostics business only, acknowledged some accessed files contained personal and/or personal health information, and said it was still analysing the data and had not determined who needed notifying. The Register, reporting on the actual dump, counted 10.9 million unique email addresses alongside names, physical addresses, phone numbers, dates of birth, genders and personal health information belonging to customers, patients and healthcare providers. "Limited number of internal systems" and "10.9 million unique email addresses" are both technically compatible, which is precisely the problem with early victim statements as a sizing tool.
If the 11.5 million figure in the current listing is of the same character as the Exact Sciences dump, it likely represents unique contact records rather than distinct affected individuals, and the 3.1TB figure likely covers bulk document and file storage rather than structured database rows.
Why It Matters
The strategic point is not the record count. It is the three named platforms.
Salesforce, ServiceNow and Entra in a single claim describes an identity-first compromise, not an application-specific one. Entra is the identity provider. If an attacker holds Entra, the SaaS applications federated behind it are downstream consequences, not separate breaches. That maps directly onto what BleepingComputer reported from the actor about Brinks Home, an Entra vishing attack on 13 July that yielded the Salesforce data, and what ShinyHunters told BleepingComputer about Abbott, a mid-June vishing campaign against several employees that compromised a Microsoft Entra SSO account and opened access to internal systems.
Second, this is a volume business. Microsoft's July 2026 advisory states it observed this tradecraft across many tenants in retail, education and manufacturing. Add the confirmed and claimed victims across the sourcing here, Brinks Home, Abbott, and the technology firm in the current listing, and the picture is an industrialised campaign working a repeatable playbook rather than a targeted operation against any one enterprise.
Third, the third-party dimension is now the dominant risk vector, and it is no longer only ShinyHunters. Microsoft explicitly names supply chain compromise through trusted workflows and integrations such as Salesloft and Gainsight as one of two primary intrusion paths. SecurityWeek's reporting on the Klue incident shows a parallel case: between 11 and 12 June, attackers used compromised legacy credentials to access market intelligence platform Klue, obtain OAuth tokens for customers' Klue integrations, and bulk-exfiltrate from downstream Salesforce instances. Salesforce disabled the Klue integration on 17 June and, per SecurityWeek, has not re-enabled it. That incident allegedly affects 195 Klue customers, though only roughly two dozen have publicly confirmed compromise, and it was claimed by a distinct actor calling itself Icarus. It then got stranger: Klue reportedly told customers Icarus was itself hacked, with the stolen data passing to a second threat actor now running its own extortion campaign. TechCrunch's reporting on Framework is another variant, where the computer maker notified all customers of stolen names, email addresses, phone numbers and physical addresses due to an upstream zero-day exploitation at business intelligence provider Metabase.
The through-line: your data is being taken from systems you do not administer, by actors you have no relationship with, and possibly resold to actors nobody has heard of yet.
The Attack Technique
Microsoft's advisory is the authoritative source here and is unambiguous on the mechanism. Across campaigns observed between mid-2025 and mid-2026, Microsoft identified activity with tradecraft overlapping ShinyHunters using two primary intrusion paths:
- Vishing targeting OAuth consent. The actor phones an employee and talks them through a Microsoft Entra authentication or registration flow, as BleepingComputer described for Brinks Home, or through granting consent to a malicious connected application. The result is an authorised OAuth grant.
- Supply chain compromise through trusted integrations, with Salesloft and Gainsight named explicitly.
Both paths lead to the same outcome: inherited user and application privileges that permit enumeration and bulk querying of CRM records while evading conventional authentication detections. This is the critical detail for defenders. The access is not stolen credentials replayed at a login page. It is a legitimate token operating within a legitimate trust relationship, which is why MFA and impossible-travel style controls do not fire. Microsoft notes these paths frequently produced persistent access and exfiltration at scale.
Microsoft is also clear on what this is not: "This activity was not the result of a vulnerability inherent to Salesforce." No CVE, no patch. It is trust relationship abuse. Microsoft states it consulted Salesforce to improve telemetry granularity in Defender for Cloud Apps, adding near real time detection, connected application attribution, and expanded application permission insights.
For the current listing, no technique detail has been published. Given the Salesforce plus Entra combination and the actor's documented preference, an Entra vishing entry followed by lateral movement into federated SaaS is the most probable chain, but that is inference from pattern, not reporting.
What Organizations Should Do
- Inventory and prune OAuth grants across every SaaS tenant. Enumerate all connected applications in Salesforce, ServiceNow and Entra, identify who consented and when, and revoke anything unrecognised, unowned or dormant. Disable end user consent for third-party applications and route all grants through admin approval. This directly closes Microsoft's first intrusion path.
- Enable Salesforce event monitoring and Defender for Cloud Apps app governance. Microsoft specifically calls out event monitoring, and the Salesforce telemetry improvements it drove now provide connected application attribution and near real time detection. Alert on bulk record enumeration and high-volume API queries against Contacts, Accounts and Cases objects, since bulk querying is the signature behaviour and it is invisible at the authentication layer.
- Harden the help desk and identity enrolment path against voice social engineering. Every confirmed intrusion in this campaign with a known vector started with a phone call. Require out-of-band verification for MFA resets, device registration and new authenticator enrolment. Deploy phishing-resistant FIDO2 or certificate-based authentication so that a talked-through enrolment flow does not yield a usable credential. Train staff that IT will never phone-walk them through an Entra registration.
- Treat every third-party integration as an inbound attack path. Klue, Salesloft, Gainsight, Metabase and Exact Sciences are all the same lesson from different angles. Maintain a register of integrations that hold tokens into your SaaS estate, scope those tokens to the minimum objects and fields required, rotate them on a schedule, and require breach notification SLAs contractually. Kill legacy credentials, which is exactly how Klue was reached.
- Rehearse the leak, not just the breach. ShinyHunters' model is publication, not encryption. Abbott's own update stressed this was "not an encryption malware event." Your incident response plan needs a data exposure track covering notification counsel, regulator timelines, HIBP ingestion, and customer communications, running in parallel with technical containment from hour one.
- Assume claimed figures are directionally right and start scoping immediately. Brinks Home and Abbott both saw claims followed by actual publication, 41GB and a 10.9M address dump respectively, after ransoms went unpaid. If your organisation appears on a leak site, begin scoping the exposure on the assumption the actor has what it says it has, and revise downward with evidence rather than upward with hindsight.
Sources: Ransom! Ali ** (AUG-2026) | Defending SaaS-based applications against ShinyHunters OAuth abuse... | ShinyHunters claims Brinks Home breach, threatens to leak stolen data | Abbott probes two cyber incidents amid extortion claims | ShinyHunters called cancer diagnostics biz and tricked staffers int... | Brinks Home Discloses Data Breach as Hackers Leak Files - SecurityWeek | Computer maker Framework notifies 'all customers' of a data breach... | More Klue Breach Victims Identified as Hackers Get Hacked - Securit...