ShinyHunters Hackers Threaten 400 Firms Over Stolen Salesforce Data
2026-03-10T20:51:47Z•7ad6cddd7fa0bdd51a731abc4ed882a8c4ed37e02bfc16e74bc91e24188aa7dd
account-takeoverai-agent-abusebackdoorchina-aptclickfixcryptominingdata-theftdeepfakedindoorextortiongithub-compromisehackerbot-clawiran-aptlazaruslinkedin-phishingmacosmudd ywaterplugxsalesforceshub-stealersignalsocial-engineeringsupply-chainverification-code-fraudwhatsapp
What happened
Multiple high-impact cyber incidents reported: ShinyHunters claims theft of Salesforce portal data from ~400 firms and is extorting victims; China-linked actors used fake war-news lures to deploy PlugX backdoors against Qatari military and energy targets; Iran-linked MuddyWater (Dindoor) backdoor campaign targeted US firms and an Israeli software org; North Korean Lazarus operatives used a fake LinkedIn interview plus deepfake audio/video to target an AllSecure CEO; Dutch intel warns of Russian actors hijacking Signal/WhatsApp via fake support bots and verification-code scams; a fake CleanMyMc
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 7ad6cddd7fa0bdd51a731abc4ed882a8c4ed37e02bfc16e74bc91e24188aa7dd
- Enrichment time
- 2026-03-10T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.