← Kemper Corporation

2026 Kemper Corporation — ShinyHunters Salesforce extortion/leak (~13M records claimed)

2026 13.0M records affected Share on X

Data compromised

Employee names, email addresses, roles, internal corporate documents, Salesforce data, and Stripe payment-log fields including customer names, timestamps, amounts, and payment status; threat actors claimed 13M+ records

Technical writeup

Mid-April 2026 reporting described ShinyHunters extortion activity against Kemper Corporation, with attackers claiming they leaked more than 13 million records after failed negotiations and had at least 29 GB of data from Kemper Salesforce-linked environments. Cybernews reported that Kemper confirmed it was aware of attacker claims, launched an investigation with third-party cybersecurity experts, and notified law enforcement. Sample analysis described SharePoint, Azure, Salesforce, and Salesforce-object folders, including employee PII and some Stripe payment logs with customer names, timestamps, amounts, and payment status, but no explicit payment-card data in analyzed samples.

Root cause

Salesforce-account compromise via social engineering / credential theft campaign, according to Cybernews context; extortion and claimed leak by ShinyHunters

References