← Salesforce

2026 Salesforce ecosystem — ShinyHunters vishing wave against CRM tenants (platform context)

2026 Unknown records affected Share on X

Data compromised

Tenant-specific customer CRM data across Charter, Cisco, and hundreds of orgs—not a single Salesforce corporate DB leak

Technical writeup

Throughout 2026, ShinyHunters and copycat actors exploited voice-phishing against employees to steal Microsoft Entra session tokens and bulk-export Salesforce CRM data from many tenants. Salesforce published security guidance and platform detections; individual victim counts (Charter 4.9M, Cisco ~3M marketing, McGraw Hill 13.5M emails, etc.) belong to each customer organization. BreachHistory indexes this contextual row under Salesforce with recordsAffected 0 to document the platform-wide campaign without double-counting tenant breaches.

Root cause

Industry-wide vishing → Microsoft Entra → Salesforce export pattern affecting many CRM customers

References