Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

ShinyHunters’ Salesforce extortion wave hits Fluke, Ingram

Ransomnews Research TeamBy Ransomnews Research TeamJuly 17, 2026Updated:July 18, 2026No Comments4 Mins Read72 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
ShinyHunters' Salesforce extortion wave hits Fluke and Ingram, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

ShinyHunters has extended its 2026 Salesforce extortion campaign, listing test-equipment maker Fluke Corporation, with a claimed 21 million Salesforce records, and book distributor Ingram Content Group on its leak site. The listings, which surfaced in early July and escalated through the week of July 17, fit a pattern the group refined after the Salesloft and Drift OAuth-token thefts: breach corporate Salesforce tenants, exfiltrate customer relationship data, then extort. Class-action lawyers are already circling Ingram over claimed exposure of Social Security numbers.

Who is ShinyHunters?

ShinyHunters is a data-theft and extortion crew, tracked by some vendors as Bling Libra, that specializes in stealing and monetizing corporate databases rather than deploying encryption. In 2026 the group has focused on Salesforce environments, often gaining access through stolen OAuth tokens and voice-phishing of help desks. It operates within the broader extortion alliance sometimes called Scattered Lapsus Hunters. Track its listings on the Ransomtracker live feed.

What was claimed against Fluke and Ingram?

For Fluke, a Fortive-owned maker of electronic test tools, ShinyHunters claimed more than 100GB including roughly 21 million Salesforce records containing personal data. Fluke subsequently appeared on Have I Been Pwned. For Ingram Content Group, reporting cited about 80,190 rows including Social Security numbers, emails, phone numbers, and addresses. Neither company had issued a detailed public statement at the point the listings appeared, which is typical in the first phase of a leak-site extortion.

SHINYHUNTERS // SALESFORCE EXTORTION CHAIN 1. ACCESS OAuth tokens / help-desk vishing → 2. EXFIL pull CRM records → 3. LIST leak-site post → 4. EXTORT pay or go public THIS WEEK’S LISTINGS FLUKE CORPORATION Claimed: 100+ GB ~21M Salesforce records INGRAM CONTENT GROUP ~80,190 rows SSNs, emails, phones, addresses

How the Salesforce campaign works

The 2026 wave leans on identity, not malware. After the Salesloft and Drift incidents exposed OAuth tokens for connected apps, attackers gained a reusable path into Salesforce tenants without touching a victim’s endpoints. Combined with voice-phishing that talks a help desk into resetting access, the crew can reach CRM data and pull it wholesale. Because CRM databases are dense with personal information, a single tenant can yield tens of millions of records. Session tokens and credentials that end up in infostealer logs feed the same access economy.

What this means for Salesforce customers

Any organization running Salesforce with third-party connected apps should treat OAuth tokens as sensitive credentials: inventory them, revoke unused grants, and rotate after any connected-vendor incident. Help desks need identity-verification procedures that resist a confident caller. And because these are extortion-only intrusions, the leverage is publication, not encryption, so a tested breach-response and notification plan matters more than a decryptor ever would. The class-action activity around Ingram shows the legal exposure begins the moment records are claimed, not when they are confirmed.

Frequently asked questions

Did Fluke confirm the ShinyHunters breach?

Fluke had not issued a detailed public statement when the listing appeared, though the company subsequently surfaced on Have I Been Pwned. ShinyHunters claimed roughly 21 million Salesforce records.

How does ShinyHunters get into Salesforce?

The 2026 campaign relies on stolen OAuth tokens, exposed after the Salesloft and Drift incidents, and voice-phishing of help desks, rather than on malware or encryption.

Is ShinyHunters ransomware?

ShinyHunters is an extortion group that steals and threatens to publish data. It does not typically deploy file-encrypting ransomware, relying on the threat of leaks for leverage.

What data was exposed at Ingram Content Group?

Reporting cited around 80,190 rows including Social Security numbers, emails, phone numbers, and addresses. Class-action investigations began shortly after the listing.

How can Salesforce customers reduce this risk?

Inventory and revoke unused OAuth grants, rotate tokens after any connected-vendor incident, and enforce strong identity verification at the help desk to resist social-engineering resets.

Sources and further reading

  • BreachNews: ShinyHunters adds Ingram Content and Fluke to leak site (July 2026)
  • Security Boulevard: Top 10 breaches of the week (July 17, 2026)
  • Have I Been Pwned: Fluke breach entry
  • Ransomnews Ransomtracker: live ransomware victim feed
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleLockBit 5.0: the comeback nobody wanted
Next Article DragonForce: the cartel that absorbed its rivals
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.