ShinyHunters Hackers Threaten 400 Firms Over Stolen Salesforce Data

2026-03-10T20:51:47Z7ad6cddd7fa0bdd51a731abc4ed882a8c4ed37e02bfc16e74bc91e24188aa7dd
account-takeoverai-agent-abusebackdoorchina-aptclickfixcryptominingdata-theftdeepfakedindoorextortiongithub-compromisehackerbot-clawiran-aptlazaruslinkedin-phishingmacosmudd ywaterplugxsalesforceshub-stealersignalsocial-engineeringsupply-chainverification-code-fraudwhatsapp

What happened

Multiple high-impact cyber incidents reported: ShinyHunters claims theft of Salesforce portal data from ~400 firms and is extorting victims; China-linked actors used fake war-news lures to deploy PlugX backdoors against Qatari military and energy targets; Iran-linked MuddyWater (Dindoor) backdoor campaign targeted US firms and an Israeli software org; North Korean Lazarus operatives used a fake LinkedIn interview plus deepfake audio/video to target an AllSecure CEO; Dutch intel warns of Russian actors hijacking Signal/WhatsApp via fake support bots and verification-code scams; a fake CleanMyMc

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
7ad6cddd7fa0bdd51a731abc4ed882a8c4ed37e02bfc16e74bc91e24188aa7dd
Enrichment time
2026-03-10T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ShinyHunters Hackers Threaten 400 Firms Over Stolen Salesforce Data · Baitaphish