Salesforce Warns of Mass Theft From Misconfigured Experience Cloud Sites
CONFIRMED85% CONFIDENCESalesforce[1] Security's post is dated 'March 7, 2026' (published 22:48 UTC); FINRA[2]: 'On March 7, 2026, Salesforce reported that ShinyHunters was actively exploiting misconfigured Experience Cloud guest user profiles.'
Salesforce said a known threat group was mass-scanning public Experience Cloud sites with a modified Mandiant tool and pulling CRM data through overly permissive guest user profiles.
1.00