Cisco Source Code and Data Leak Allegedly Claimed by ShinyHunters
ID: b9bc9ace-4ef6-59ed-93d6-75242d00c665
STIX ID: report--b9bc9ace-4ef6-59ed-93d6-75242d00c665
Feed Name: cybersecurityNews.com
ShinyHunters has claimed responsibility for multiple alleged breaches of Cisco, stating over 3 million Salesforce records and additional internal assets (GitHub, AWS S3) were exfiltrated, and posted a “FINAL WARNING” demanding contact before April 3, 2026. The report links the incident to known ShinyHunters tactics — vishing to procure OAuth tokens, automated Aura/Experience Cloud scanning (AuraInspector), and subsequent token-driven exfiltration — and recommends immediate Salesforce OAuth audits, token revocation, and monitoring for unauthorized data access; Cisco has not publicly confirmed the March 2026 claim.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
