Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

ShinyHunters uses vishing to breach Salesforce data

AI-powered voice scams fuel ShinyHunters’ global attacks.

byAytun Çelebi
September 3, 2025
in Cybersecurity
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

The cybercrime group ShinyHunters has garnered international attention after Google advised its 2.5 billion users to enhance their security protocols. This recommendation followed a data breach that exploited vulnerabilities within Salesforce, a widely-used customer management platform.

Unlike conventional data breaches involving direct intrusion into databases, ShinyHunters, alongside other groups, has recently employed voice-based social engineering, known as “vishing,” to target major corporations. Vishing represents a form of social engineering where individuals are manipulated into divulging confidential information or performing actions under false pretenses.

In a vishing attack, a perpetrator impersonates an IT helpdesk employee to deceive an actual employee into revealing passwords or multi-factor authentication codes, thereby gaining unauthorized system access. Though not a novel tactic, the increasing sophistication of deepfakes and AI-driven voice cloning has made vishing more difficult to detect. These technologies enable criminals to convincingly mimic voices and create realistic scenarios, enhancing their deceptive capabilities.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Throughout the current year, several prominent companies, including Qantas, Pandora, Adidas, Chanel, Tiffany & Co., and Cisco, have reported being targeted through similar vishing methods, impacting millions of users. These incidents highlight the widespread vulnerability to social engineering tactics.

ShinyHunters, a cybercrime group, emerged in 2020, claiming responsibility for successful attacks against 91 victims. The group’s primary motivation is financial gain, though they have demonstrated a willingness to inflict reputational damage on their targets. In 2021, ShinyHunters announced the sale of data allegedly stolen from 73 million AT&T customers, illustrating the scale of their operations.

Prior to employing vishing, ShinyHunters targeted companies by exploiting vulnerabilities in cloud applications and website databases. Their focus on customer management providers like Salesforce enables them to access extensive data sets from multiple clients through a single successful attack. This approach amplifies the potential impact of their breaches.

The group’s adoption of social engineering techniques signals a shift in their modus operandi. This evolution is reportedly linked to their collaborations with other cybercriminal entities. In mid-August, ShinyHunters announced on Telegram a partnership with Scattered Spider and Lapsus$ to target Salesforce and Allianz Life. Telegram removed the channel shortly after its launch. The group subsequently released Allianz Life’s Salesforce data, which contained 2.8 million records pertaining to customers and corporate partners.

Scattered Lapsus$ Hunters, a rebranded iteration of Lapsus$, has recently advertised the provision of ransomware-as-a-service. This offering involves launching ransomware attacks on behalf of paying clients. The group claims its service surpasses those of other cybercrime organizations, including LockBit and Dragonforce. Instead of private negotiations, they often publish extortion messages publicly.

The cybercriminal landscape involves overlapping memberships among groups like ShinyHunters, Scattered Spider, and Lapsus$. These groups operate internationally, with members participating from various locations on the dark web. Further complicating matters, each group is often identified by multiple aliases; Scattered Spider, for instance, is also known as UNC3944, Scatter Swine, Oktapus, Octo Tempest, Storm‑0875, and Muddled Libra.

Individual users can take limited direct action against organized cybercrime. Maintaining personal vigilance against scams is crucial for self-protection. Social engineering effectively exploits human emotions and the inclination to trust and assist.

Companies can proactively mitigate the risks of vishing. Implementing awareness training and scenario-based education programs for employees is vital. Verification methods, such as on-camera checks requiring employees to present corporate badges or government-issued identification, can also be implemented. Asking questions that cannot easily be answered with publicly available information online presents another layer of defense.

Organizations can bolster security by deploying authenticator applications that mandate phishing-resistant multi-factor authentication, incorporating techniques like number matching or geo-verification. Number matching necessitates users to input numbers from the identity platform into the authenticator app to validate authentication requests. Geo-verification uses the user’s physical location as an additional authentication factor.


Featured image credit

Tags: GooglesalesforceShinyHunters

Related Posts

Proven privacy: Why ‘no-log’ claims need real evidence today

Proven privacy: Why ‘no-log’ claims need real evidence today

June 12, 2026
Critical UpdraftPlus flaw puts 3 million WordPress sites at risk

Critical UpdraftPlus flaw puts 3 million WordPress sites at risk

June 11, 2026
Which security awareness training solution is right for you? 5 options compared

Which security awareness training solution is right for you? 5 options compared

June 10, 2026
Why secure software delivery depends on better release management

Why secure software delivery depends on better release management

June 3, 2026
Popular Codex package caught exfiltrating authentication credentials

Popular Codex package caught exfiltrating authentication credentials

June 2, 2026
GTA V cheat service Atlas Menu hacked, exposing 64,000 accounts

GTA V cheat service Atlas Menu hacked, exposing 64,000 accounts

June 2, 2026

LATEST NEWS

“Free robots are an illusion”: Why we’ll pay for system intelligence, not delivery workers

How Henrique Schmaiske led Meteor.js through its biggest transformation

Proven privacy: Why ‘no-log’ claims need real evidence today

ChatGPT hits 1 billion users as global AI adoption surges despite backlash

Huawei launches HarmonyOS 7 developer beta with upgraded API 26

OpenAI Codex referral program rewards users with extra rate resets

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Roboto AI

Pickaxe

Pfpmaker

MindPal

Syllaby

ScreenApp

FinanceBrain

GitHub Spark

Hints

VisionStory AI

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.