{"id":4784,"date":"2026-03-10T12:36:50","date_gmt":"2026-03-10T12:36:50","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2026\/03\/10\/shinyhunters-targets-hundreds-of-websites-in-new-salesforce-campaign\/"},"modified":"2026-03-10T12:36:50","modified_gmt":"2026-03-10T12:36:50","slug":"shinyhunters-targets-hundreds-of-websites-in-new-salesforce-campaign","status":"publish","type":"post","link":"https:\/\/ft365.org\/index.php\/2026\/03\/10\/shinyhunters-targets-hundreds-of-websites-in-new-salesforce-campaign\/","title":{"rendered":"ShinyHunters Targets Hundreds of Websites in New Salesforce Campaign"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Salesforce has urged Experience Cloud customers to audit their website configurations after reports that a notorious threat group has already stolen data from hundreds of companies.<\/p>\n<p>The SaaS giant said that it had been tracking an increase in threat actor activity targeting misconfigurations of publicly accessible sites built using its Experience Cloud platform.<\/p>\n<p>\u201cSpecifically, we have identified a campaign in which malicious actors are exploiting customers\u2019 overly permissive Experience Cloud guest user configurations to potentially access more data than targeted organizations intended,\u201d it explained.<\/p>\n<p>The group has been using a customized version of an open source tool originally developed by Mandiant (Aura Inspector) to perform mass scanning of the \/s\/sfsites\/aura API endpoint. The tool apparently identifies vulnerable CRM objects\u00a0and extracts data from misconfigured endpoints, Salesforce said.<\/p>\n<p>\u201cData harvested in these scans, such as names and phone numbers,\u00a0is often used to build follow-on targeted social engineering and vishing (voice phishing) campaigns,\u201d it continued.<\/p>\n<p><em>Read more on ShinyHunters campaigns: New Data Theft Campaign Targets Salesforce via Salesloft App.<\/em><\/p>\n<p>Salesforce was at pains to point out that the threat actors are exploiting a \u201ccustomer-configured guest user setting, not a platform security flaw.\u201d<\/p>\n<h2>ShinyHunters Gives a Final Warning<\/h2>\n<p>The infamous ShinyHunters group has claimed responsibility for the campaign. In screenshots from its leak site published on X (formerly Twitter) it claimed to have breached \u201cseveral hundreds\u201d of companies.<\/p>\n<p>It claims to have compromised around 400 websites and 100 \u201chigh-profile companies.&#8221;<\/p>\n<p>That would suggest that it did indeed use the contact details cited by Salesforce and obtained via the website intrusions in order to perform\u00a0follow-on social engineering, network intrusions and wider data theft.<\/p>\n<h2><strong>Salesforce Urges Immediate Action<\/strong><\/h2>\n<p>Salesforce claimed that any Experience Cloud customers that are using the guest user profile and have configured permissions \u201cto allow public access to objects and fields not intended to be publicly available\u201d could be affected.<\/p>\n<p>It urged these customers to:<\/p>\n<ul>\n<li>Audit guest user permissions and enforce a least privilege access model to ensure these profiles are restricted to the \u201cabsolute minimum\u201d objects and fields needed for the site to function<\/li>\n<li>Ensure the Default External Access for all objects is set to \u201cprivate\u201d<\/li>\n<li>Uncheck \u201cAllow guest users to access public APIs\u201d in site settings and uncheck \u201cAPI Enabled\u201d in the guest user profile\u2019s System Permissions<\/li>\n<li>Uncheck \u201cPortal User Visibility\u201d and \u201cSite User Visibility\u201d in Sharing Settings to stop guest users from enumerating internal organization members<\/li>\n<li>If the site does not require unauthenticated visitors to create their own accounts, disable self-registration<\/li>\n<li>Review Aura\u00a0Event Monitoring\u00a0logs for unusual access patterns\u00a0<\/li>\n<\/ul>\n<p>\u200bShinyHunters has a long track record of going after Salesforce customers, having targeted their instances on multiple occasions in connected campaigns last year.<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Salesforce has urged Experience Cloud customers to audit their website configurations after reports that a notorious threat group has already stolen data from hundreds of companies. The SaaS giant said that it had been tracking an increase in threat actor activity targeting misconfigurations of publicly accessible sites built using its Experience Cloud platform. \u201cSpecifically, we<\/p>\n","protected":false},"author":2,"featured_media":4785,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4784","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"thumbnail":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8-150x150.jpg",150,150,true],"medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"medium_large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"1536x1536":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"2048x2048":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"morenews-featured":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"morenews-large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"morenews-medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8.jpg",300,300,false],"crawlomatic_preview_image":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/03\/4784-9907c490-22b2-4bc1-a490-172e76d741a8-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"https:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"https:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/4784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=4784"}],"version-history":[{"count":0,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/4784\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/4785"}],"wp:attachment":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=4784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=4784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=4784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}