- Start
- Mar 7, 202690% CONFIDENCEfrom the source
Salesforce Warns of Mass Theft From Misconfigured Experience Cloud Sites
- On 7 March 2026 Salesforce Security said it had identified a campaign in which malicious actors exploit customers' overly permissive Experience Cloud guest user configurations to reach more data than organisations intended[1].
- The actor used a modified version of Aura Inspector, an open-source tool Mandiant released to find exposed objects through the /s/sfsites/aura endpoint, adapted to actually extract data from public-facing sites without logging in[1][4].
- Salesforce said the platform remained secure and the issue was a customer-configured guest user setting, told customers to audit guest profiles down to least privilege, and on 11 March widened its guidance after finding more exposing configurations[1].
- ShinyHunters claimed data from almost 400 websites and about 100 high-profile companies, including Salesforce itself[4]; FINRA warned member firms the data was being used for phishing, vishing and extortion[2].
- Salesforce Ben's running timeline lists later 2026 breaches claimed by ShinyHunters against Salesforce customers, among them Loblaw, Hallmark, 7-Eleven, ADT and Brinks Home[3].
References 485% CONFIDENCE
The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
- [1]90%salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-accesssalesforce.com· Posted Sep 24, 2026· Starts Mar 7, 2026 ✓· 30% of score
Salesforce Security's post is dated 'March 7, 2026' (published 22:48 UTC); FINRA[2]: 'On March 7, 2026, Salesforce reported that ShinyHunters was actively exploiting misconfigured Experience Cloud guest user profiles.'
- [2]88%Cybersecurity Alert - Salesforce Experience Cloud Security Incidentfinra.org· Added Sep 24, 2026· 30% of score
FINRA names ShinyHunters as the group exploiting misconfigured guest profiles and says the stolen data feeds phishing, vishing and extortion against firms and clients.
- [3]75%Salesforce Hacks 2026: Everything We Know So Farsalesforceben.com· Published Aug 5, 2026· 25% of score
Salesforce[1] Ben's timeline of 2026 incidents: the 7 March blog, a 12 March trust-site post, and later breaches claimed by ShinyHunters at Loblaw, Hallmark, 7-Eleven, ADT and Brinks Home.
- [4]85%ShinyHunters claims yet another Salesforce customers breachtheregister.com· Published Mar 9, 2026· 14% of score
ShinyHunters told The Register it stole data from almost 400 websites and about 100 high-profile companies; Mandiant's CTO confirmed misuse of AuraInspector.
Suggest a correction
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.