Breach in Google’s Salesforce Database: Details on the ShinyHunters Attack
Overview of the Incident
In a concerning development, Google has confirmed that its corporate Salesforce database was breached by a group known as ShinyHunters. The incident was identified as occurring in June 2025, with affected users being notified on August 8.
How the Attack Happened
According to reports, the threat actors employed a sophisticated strategy to infiltrate the database. By using a malicious version of Salesforce’s Data Loader, they managed to convince company employees to authorize access. This deception was executed through phishing phone calls, where the hackers impersonated IT support staff, leading to unauthorized access to sensitive information.
Nature of Compromised Data
In discussions with Cyber Security News, Google clarified that the stolen data primarily included basic business information, such as company names and contact details that are often publicly available. Importantly, they noted that sensitive payment data remained secure and that several core services—including Google Ads, Google Analytics, and Merchant Centre—were unaffected by this breach.
Speed of Response
Google has reassured its users that the threat actors had only a brief opportunity to access the database. The tech giant acted swiftly to cut off their access. Following the incident, Google conducted a thorough impact analysis and has since enhanced its security protocols to prevent similar occurrences.
Identification of the Attacking Group
Google’s Threat Intelligence team has pinpointed the attackers as UNC6040, more commonly recognized as ShinyHunters. This group has gained notoriety for orchestrating large-scale attacks on Salesforce instances. Recent claims from ShinyHunters indicate they have stolen approximately 2.55 million data records related to this incident.
Ransom Demands from ShinyHunters
Reports indicate that ShinyHunters has begun reaching out to affected companies, soliciting ransom payments. They have threatened to publicly release or sell the stolen data from any companies that do not comply, continuing a pattern observed in their previous cyber campaigns, such as the Snowflake attack.
Ongoing Threat
The ShinyHunters group has indicated that their campaign against Salesforce instances is ongoing, suggesting that more organizations could be at risk in the near future. It is crucial for companies to reevaluate their Salesforce privacy settings and monitor their database access to ensure robust security.
Salesforce’s Position on the Breach
In response to the breach, Salesforce has stated that there has not been any compromise of its broader network. They emphasize that the issue arises from unauthorized access to individual instances rather than any vulnerabilities in the Salesforce platform itself. Salesforce has reiterated the importance of customer responsibility in safeguarding their data, especially as phishing attacks become increasingly sophisticated.
Security Best Practices Recommended
Salesforce recommends that all clients adopt best practices for security, which include enabling multifactor authentication, following the principle of least privilege, and carefully managing connected applications to safeguard against unauthorized access.
Companies Affected by the Breach
Several well-known organizations have reportedly fallen victim to the ShinyHunters breach campaign. These include Allianz Life, Qantas, Chanel, Pandora, and adidas, all of which need to take proactive measures to enhance their security postures in light of this incident.
By understanding these details, companies can better prepare themselves against future cyber threats and ensure a more secure operational environment.


