Ransomware victim disclosure
← All victimsSalesforce Aura Campaign
Claimed by Hunters International · listed 2 months ago
Status timeline
- Listed
Mar 9, 2026
- Data leaked
At a glance
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 9, 2026
About the victim
AI dossier — public-source company profileThe victim name 'Salesforce Aura Campaign' does not correspond to a distinct independent company but rather appears to reference a campaign or dataset associated with Salesforce's Aura framework or platform. No independent public site or corporate entity matching this exact name could be identified. It may represent a bulk exfiltration targeting multiple companies via the Salesforce Aura interface.
- Industry
- Technology / SaaS Platform
Attack summary
Severity: critical — The group claims exfiltration affecting hundreds of companies via a shared SaaS platform (Salesforce Aura), implying large-scale PII and business data exposure across multiple organisations; data is marked as published, indicating confirmed exfiltration at significant scale.Hunters International (posting under the 'ShinyHunters' alias) claims to have exfiltrated data from several hundreds of companies via what appears to be a Salesforce Aura-related campaign, threatening final-warning publication if affected companies do not pay. The post indicates data has been published ('data_published' status) and is being used as leverage for extortion across multiple victims.
Data the group says was taken
AI dossier — extracted from the leak post- Multi-company customer/CRM records (alleged)
- Salesforce Aura platform data
- Unspecified exfiltrated business data from hundreds of companies
What the group claims
Several hundreds of companies set to release with FINAL WARNINGs upon failure to comply. To all affected companies who will be or are being contacted by us ("ShinyHunters"), please consider this a preliminary warning before we release your name with FINAL WARNING or a complete data leak. Reply, engage, pay a small price, and prevent a publication. Make the right decision, don't be the next headline. | Updated: 10 Mar 2026 | Warning: NOTICE OF WARNING
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
