Salesforce Warns of Mass Theft From Misconfigured Experience Cloud Sites
Salesforce Tower, 415, Mission Street, Rincon Hill, San Francisco, California, 94105, United StatesSalesforce
CONFIRMEDDate confidence: CONFIRMEDStated as firmHow firmly the source words the date: confirmed, scheduled, estimated, delayed or unverified.Show all CONFIRMED pins85% CONFIDENCEOverall confidence: 85%How well the pin's source and references back up its dates.Weighted average of how firmly 4 references, the source included, support the pin's start and end times; a reference counts half as much for every 180 days older than the newestShow all pins at 75% confidence or betterSalesforce[1] Security's post is dated 'March 7, 2026' (published 22:48 UTC); FINRA[2]: 'On March 7, 2026, Salesforce reported that ShinyHunters was actively exploiting misconfigured Experience Cloud guest user profiles.'
Salesforce said a known threat group was mass-scanning public Experience Cloud sites with a modified Mandiant tool and pulling CRM data through overly permissive guest user profiles.