ShinyHunters has extended its 2026 Salesforce extortion campaign, listing test-equipment maker Fluke Corporation, with a claimed 21 million Salesforce records, and book distributor Ingram Content Group on its leak site. The listings, which surfaced in early July and escalated through the week of July 17, fit a pattern the group refined after the Salesloft and Drift OAuth-token thefts: breach corporate Salesforce tenants, exfiltrate customer relationship data, then extort. Class-action lawyers are already circling Ingram over claimed exposure of Social Security numbers.
Who is ShinyHunters?
ShinyHunters is a data-theft and extortion crew, tracked by some vendors as Bling Libra, that specializes in stealing and monetizing corporate databases rather than deploying encryption. In 2026 the group has focused on Salesforce environments, often gaining access through stolen OAuth tokens and voice-phishing of help desks. It operates within the broader extortion alliance sometimes called Scattered Lapsus Hunters. Track its listings on the Ransomtracker live feed.
What was claimed against Fluke and Ingram?
For Fluke, a Fortive-owned maker of electronic test tools, ShinyHunters claimed more than 100GB including roughly 21 million Salesforce records containing personal data. Fluke subsequently appeared on Have I Been Pwned. For Ingram Content Group, reporting cited about 80,190 rows including Social Security numbers, emails, phone numbers, and addresses. Neither company had issued a detailed public statement at the point the listings appeared, which is typical in the first phase of a leak-site extortion.
How the Salesforce campaign works
The 2026 wave leans on identity, not malware. After the Salesloft and Drift incidents exposed OAuth tokens for connected apps, attackers gained a reusable path into Salesforce tenants without touching a victim’s endpoints. Combined with voice-phishing that talks a help desk into resetting access, the crew can reach CRM data and pull it wholesale. Because CRM databases are dense with personal information, a single tenant can yield tens of millions of records. Session tokens and credentials that end up in infostealer logs feed the same access economy.
What this means for Salesforce customers
Any organization running Salesforce with third-party connected apps should treat OAuth tokens as sensitive credentials: inventory them, revoke unused grants, and rotate after any connected-vendor incident. Help desks need identity-verification procedures that resist a confident caller. And because these are extortion-only intrusions, the leverage is publication, not encryption, so a tested breach-response and notification plan matters more than a decryptor ever would. The class-action activity around Ingram shows the legal exposure begins the moment records are claimed, not when they are confirmed.
Frequently asked questions
Did Fluke confirm the ShinyHunters breach?
Fluke had not issued a detailed public statement when the listing appeared, though the company subsequently surfaced on Have I Been Pwned. ShinyHunters claimed roughly 21 million Salesforce records.
How does ShinyHunters get into Salesforce?
The 2026 campaign relies on stolen OAuth tokens, exposed after the Salesloft and Drift incidents, and voice-phishing of help desks, rather than on malware or encryption.
Is ShinyHunters ransomware?
ShinyHunters is an extortion group that steals and threatens to publish data. It does not typically deploy file-encrypting ransomware, relying on the threat of leaks for leverage.
What data was exposed at Ingram Content Group?
Reporting cited around 80,190 rows including Social Security numbers, emails, phone numbers, and addresses. Class-action investigations began shortly after the listing.
How can Salesforce customers reduce this risk?
Inventory and revoke unused OAuth grants, rotate tokens after any connected-vendor incident, and enforce strong identity verification at the help desk to resist social-engineering resets.
