Ransomware victim disclosure
← All victimsSalesforce Aura Campaign
Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 9, 2026
About the victim
AI dossier — public-source company profileThe victim identifier 'Salesforce Aura Campaign' does not refer to a discrete company but rather appears to describe a campaign targeting companies using Salesforce's Aura framework or platform. No specific single company can be identified from the leak post; it references hundreds of unnamed companies across an unspecified campaign.
- Industry
- Technology / SaaS Platform
Attack summary
Severity: medium — Data is claimed as published ('data_published' status) across multiple companies, but no specific data types, volumes, or proof files are described, and no individual victim or regulated data category is confirmed, preventing a higher severity classification.ShinyHunters claims to have exfiltrated data from several hundred companies and is issuing final warnings demanding payment to suppress publication; the post indicates data has been published for non-compliant victims, though no specific data types or volumes are enumerated.
Data the group says was taken
AI dossier — extracted from the leak post- Unspecified corporate data from multiple unnamed companies
What the group claims
Several hundreds of companies set to release with FINAL WARNINGs upon failure to comply. To all affected companies who will be or are being contacted by us ("ShinyHunters"), please consider this a preliminary warning before we release your name with FINAL WARNING or a complete data leak. Reply, engage, pay a small price, and prevent a publication. Make the right decision, don't be the next headline. | Updated: 10 Mar 2026 | Warning: NOTICE OF WARNING
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

