Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI Chatbots Claude, ChatGPT, Copilot Used in Malware Attacks
August 20, 2026
Critical CyberPanel RCE Chain (CVE-2024-7067) Lets Attackers Gain Server Shell
August 20, 2026
ZombieLoad Flaw Exploits Intel CPUs, Exposes Sensitive Data
August 20, 2026
Home/CyberSecurity News/ShinyHunters claims Cisco data leak, source code theft
CyberSecurity News

ShinyHunters claims Cisco data leak, source code theft

Key Takeaways The ShinyHunters cybercrime group claims to have breached Cisco Systems, exfiltrating over 3 million Salesforce records containing sensitive PII and internal corporate data. The alleged...

Emy Elsamnoudy
Emy Elsamnoudy
April 1, 2026 4 Min Read
58 0

Key Takeaways

  • The ShinyHunters cybercrime group claims to have breached Cisco Systems, exfiltrating over 3 million Salesforce records containing sensitive PII and internal corporate data.
  • The alleged breach impacts Cisco customers and employees, with records reportedly linked to high-profile government agencies in the U.S., Australia, and India.
  • ShinyHunters issued a “FINAL WARNING” to Cisco, threatening public data exposure if the company does not engage by April 3, 2026.
  • The attack vectors cited include Salesforce CRM, Salesforce Aura (Experience Cloud), and AWS account environments, consistent with ShinyHunters’ known tactics involving vishing and OAuth token abuse.

Alleged Breach Claims

The notorious cybercriminal collective ShinyHunters has reportedly asserted responsibility for three distinct data breaches targeting Cisco Systems, Inc. The group claims to have compromised more than 3 million Salesforce records, which purportedly contain personally identifiable information (PII). Further alleged exposures include GitHub repositories, AWS S3 buckets, and other sensitive internal corporate data.

Table Of Content

  • Key Takeaways
  • Alleged Breach Claims
  • ShinyHunters’ Modus Operandi
  • Details of the Alleged Cisco Data
  • Cisco’s Prior Security Incidents
  • What You Should Do

On its data leak site, ShinyHunters issued a “FINAL WARNING” to Cisco, stipulating that the company must make contact before April 3, 2026, or face the public release of the stolen data. This detail was brought to light by security researcher Dominic Alvieri.

An update to the listing on March 31, 2026, specifies a record count exceeding 3 million and references three separate vectors of compromise: Salesforce CRM, Salesforce Aura (Experience Cloud), and AWS account environments.

ShinyHunters’ Modus Operandi

ShinyHunters, a prolific black-hat hacking and extortion group, is believed to have emerged around 2019. It has since become one of the most active operations specializing in data theft and extortion within the cybercrime landscape.

The group operates under various aliases, including UNC6040 and UNC6395. It has been linked to sophisticated vishing (voice phishing) campaigns that manipulate company employees into granting OAuth token access to malicious third-party Salesforce applications.

In March 2026, ShinyHunters publicly stated it had breached between 300 and 400 organizations. These intrusions reportedly leveraged misconfigured Salesforce Experience Cloud (Aura) guest user access controls, utilizing an open-source tool named AuraInspector to automate vulnerability scanning across Salesforce environments.

Details of the Alleged Cisco Data

According to threat intelligence disseminated by Resecurity, the records purportedly stolen from Cisco clearly originate from its Salesforce environment and contain information pertaining to both Cisco customers and employees.

Of significant concern, the dataset reportedly includes records associated with personnel from critical government agencies such as the FBI, DHS, DISA, IRS, and NASA in the United States, alongside the Australian Ministry of Defense and multiple Indian government entities. These individuals are likely linked to the procurement or configuration of Cisco products.

Such highly sensitive data represents a valuable asset for adversaries planning targeted phishing, social engineering, or supply chain attacks.

The UNC6040 cluster, associated with ShinyHunters, is known for deceiving customer support employees via vishing, leading them to authorize malicious Salesforce-connected applications using OAuth tokens. Once OAuth access is granted, it effectively circumvents multi-factor authentication (MFA), password resets, and login monitoring, as these tokens are natively issued by Salesforce.

In a subsequent phase, attributed to UNC6395, stolen tokens are further exploited to exfiltrate secrets, including AWS keys, passwords, and Snowflake tokens, thereby facilitating lateral movement into cloud environments.

Cisco’s Prior Security Incidents

This is not Cisco’s first encounter with data exposure claims. In October 2024, threat actor IntelBroker asserted that they had downloaded 4.5 TB of data from Cisco’s public-facing DevHub environment. This alleged haul included source code, hardcoded credentials, API tokens, and AWS private buckets.

Cisco confirmed at the time that while its core systems remained intact, certain files intended for private use were inadvertently exposed due to a configuration error. Furthermore, in August 2025, Cisco disclosed a separate CRM data breach resulting from a vishing attack, which was attributed to actors linked to ShinyHunters.

The ShinyHunters group has demonstrated a consistent pattern of escalating its Salesforce-themed attacks, having previously claimed breaches against prominent companies such as Snowflake, Okta, LastPass, Google, AMD, Sony, and Crunchbase.

As of this report, Cisco has not yet issued an official public statement specifically addressing the March 2026 ShinyHunters extortion claim.

What You Should Do

  • Organizations should immediately audit all Salesforce OAuth-connected applications for legitimacy and authorized access.
  • Enforce Salesforce API Access Control policies rigorously to restrict unauthorized programmatic access to data.
  • Revoke any unrecognized or suspicious OAuth tokens within Salesforce environments.
  • Monitor for unauthorized Salesforce Data Loader activity, which can indicate data exfiltration.
  • Educate employees, especially those in customer support or with privileged access, on the dangers of vishing attacks and the importance of verifying requests before granting access or authorizing applications.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerphishingSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Attackers Exploit Hotel Booking Systems to Defraud Guests

Next Post

CrystalX Malware-as-a-Service Spreads via Telegram, Offers Stealer and RAT

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts
August 20, 2026
Critical Zimbra RCE Vulnerability CVE-2022-27925 Actively Exploited
August 20, 2026
T-Mobile Physically Disconnects Network to Expel Chinese Hackers
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us