2026 ZenBusiness — multi‑TB exfiltration claimed (vishing + SaaS; ShinyHunters extortion listing)
Data compromised
Potentially large internal and customer datasets; exact categories unconfirmed publicly
Technical writeup
ZenBusiness, a U.S. online business formation and compliance platform, appeared on extortion-oriented leak sites in late March 2026 with claims of several terabytes of data taken from internal environments and connected SaaS footprints (e.g., Snowflake, Salesforce, Mixpanel cited in press summaries). Industry coverage described social engineering and credential takeover—often framed as voice phishing (vishing)—as the likely entry path. Attackers issued public deadlines threatening large-scale publication; the company’s full forensic findings and exact customer impact counts were not publicly confirmed at listing time. Treat actor claims and volume figures as unverified until independently corroborated.
Root cause
Vishing / social engineering leading to SaaS and cloud account compromise (per reporting); extortion listing