← Cisco

2026 Cisco — ShinyHunters extortion; ~3M Salesforce CRM records claimed (vishing / Aura / AWS narrative)

2026 3.0M records affected Share on X

Data compromised

CRM profile-style PII claimed (names, emails, phones, org metadata per prior Cisco CRM disclosures); broader internal assets alleged—verify against Cisco statements

Technical writeup

In early April 2026, the extortion group ShinyHunters publicly claimed theft of more than three million Salesforce CRM records from Cisco and posted demands with an early-April deadline in trade reporting. Journalists summarized an alleged multi-vector narrative—tying together voice phishing (vishing), Salesforce Aura exploitation, and unauthorized AWS access—while noting Cisco had previously disclosed a vishing-related CRM export affecting Cisco.com registrant profile data in August 2025. Industry coverage emphasized that screenshots and volume figures were not fully independently verified at listing time but flagged serious CRM and PII exposure risks. Related reporting also discussed Cisco’s involvement in the broader Trivy / dev-environment credential chain affecting GitHub clones. Cisco customers should monitor official advisories for confirmed scope.

Root cause

Extortion campaign; alleged vishing, cloud/Salesforce access paths (per actor claims and press synthesis)

References