2026 Abrigo — ShinyHunters claims ~1.7M+ Salesforce-oriented records (fintech; Apr)
Data compromised
Customer and prospect PII, support-style metadata, internal corporate files per actor and trade summaries
Technical writeup
In mid-April 2026, the extortion group ShinyHunters claimed a major breach of Abrigo, Inc., a U.S. fintech and risk-management software vendor serving financial institutions, alleging compromise of Salesforce-linked environments with on the order of 1.7–1.75 million records of PII and internal corporate material. Industry summaries (NeuraCyB Intel, DeXpose, extortion leak-site monitors) described pay-or-leak deadlines and vishing-adjacent SaaS takeover narratives consistent with broader ShinyHunters spring 2026 reporting. Treat exact counts and all data categories as subject to Abrigo’s forensic confirmation.
Root cause
Extortion-group claimed SaaS / CRM path compromise (voice phishing and token takeover cited in sector analysis)