Ransomware victim disclosure
← All victimsAli** **********
Claimed by Shinyhunters · listed 3 hours ago
Status timeline
- ListedAug 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Sector
- Technology
- Listed on leak site
- Aug 9, 2026
About the victim
AI dossier — public-source company profileAli** ********** is a technology company. Limited details are available due to the redacted victim name and absence of a public site.
- Industry
- Technology
Attack summary
Severity: critical — Confirmed exfiltration of 11.5 million PII records at scale across multiple systems, plus 3.1TB+ of sensitive internal data. Large-scale personal data exposure involving customers and employees constitutes critical severity.ShinyHunters claims to have compromised 11.5 million records across Salesforce, ServiceNow, and Entra, exfiltrating PII of customers and employees plus 3.1TB+ of internal corporate data. The group issued a final extortion demand with a deadline of August 10, 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Customer PII
- Employee PII
- Salesforce records
- ServiceNow records
- Entra identity data
- Internal corporate documents
What the group claims
August 7, 2026 3:00 PM ET: Over 11.5 million records across Salesforce, ServiceNow, and Entra containing some PII of customers and employees and 3.1TB+ of internal corporate data was compromised. This is a final warning to reach out by 10 August 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 08 August 2026 | Warning: FINAL WARNING PAY OR LEAK
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

