2026 Cisco — ShinyHunters extortion; ~3M Salesforce CRM records claimed (vishing / Aura / AWS narrative)
Data compromised
CRM profile-style PII claimed (names, emails, phones, org metadata per prior Cisco CRM disclosures); broader internal assets alleged—verify against Cisco statements
Technical writeup
In early April 2026, the extortion group ShinyHunters publicly claimed theft of more than three million Salesforce CRM records from Cisco and posted demands with an early-April deadline in trade reporting. Journalists summarized an alleged multi-vector narrative—tying together voice phishing (vishing), Salesforce Aura exploitation, and unauthorized AWS access—while noting Cisco had previously disclosed a vishing-related CRM export affecting Cisco.com registrant profile data in August 2025. Industry coverage emphasized that screenshots and volume figures were not fully independently verified at listing time but flagged serious CRM and PII exposure risks. Related reporting also discussed Cisco’s involvement in the broader Trivy / dev-environment credential chain affecting GitHub clones. Cisco customers should monitor official advisories for confirmed scope.
Root cause
Extortion campaign; alleged vishing, cloud/Salesforce access paths (per actor claims and press synthesis)