logo

Salesforce AuraInspector Attack: ShinyHunters Scanning Experience Cloud Sites

ID: 6abaab43-6f68-59be-8ca2-42fd5e77bc79

STIX ID: report--6abaab43-6f68-59be-8ca2-42fd5e77bc79

Feed Name: NoHackie

Threat Score
75/100

Date Published: 2026-03-12

Date Updated: 2026-04-19

...
...

A known threat actor (reported as ShinyHunters/UNC6240) repurposed Mandiant's AuraInspector into an automated scanner and extractor targeting Salesforce Experience Cloud sites with overly permissive guest user profiles, allegedly compromising 300–400 organizations beginning September 2025 and accelerating after the tool's January 2026 release; extracted CRM data (names, phone numbers, accounts) has been used for extortion and to enable high-confidence vishing. Salesforce issued an advisory (March 7, 2026) recommending removing the API Enabled permission from guest users; detection and pagination-bypass details, evidence of active exploitation, and remediation steps are documented, while a claimed second bypass affecting correctly configured instances remains unverified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.