SecurityJuly 29, 202611 min read

How to Protect Yourself From the 2026 Salesforce Data Breach Wave

PT

By PrivacyOn Team

Privacy Research & Removal Operations

How to Protect Yourself From the 2026 Salesforce Data Breach Wave

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

If you have ever done business with a large enterprise — a bank, insurer, telecom, airline, tech vendor, or consulting firm — there is a real chance your name, email, phone, and address are in the 2026 Salesforce data theft wave. To protect yourself: check Have I Been Pwned for your emails, freeze your credit at all three bureaus, enable authenticator-app 2FA on every important account, treat every unexpected "vendor" call as a scam until independently verified, and remove your data from broker sites so leaked contact info cannot be cross-referenced into a full identity profile. This is not one breach — it is dozens.

What Is the 2026 Salesforce Breach Wave?

Between late 2025 and mid-2026, the extortion collectives known as ShinyHunters and Scattered Spider (sometimes tracked jointly as UNC6040) launched a coordinated campaign against companies that use Salesforce for customer relationship management. The attackers did not compromise Salesforce itself — Salesforce's core platform was not breached. Instead, they targeted individual customer tenants using two techniques:

  • Vishing (voice phishing): Attackers called IT helpdesks impersonating employees and tricked staff into approving malicious OAuth applications that granted API access to the company's Salesforce data.
  • Experience Cloud misconfigurations: Starting in September 2025, attackers exploited insecure guest-user access controls on Salesforce Experience Cloud sites, then used the AuraInspector tool released in January 2026 to audit and abuse Aura framework misconfigurations at scale.

Reporting from BleepingComputer, Salesforce Ben, and Help Net Security put the estimated victim count between 300 and 700+ companies across insurance, banking, tech, hospitality, aviation, and manufacturing.

Which Companies Were Hit?

Publicly confirmed or reported victims include:

  • Allianz Life — 2.8M+ customer records including SSNs (July 2025)
  • Cloudflare — customer support case data
  • Zscaler — customer contact information
  • Palo Alto Networks — CRM records
  • Google — Salesforce-hosted business contact data
  • TransUnion — customer records
  • Farmers Insurance — policyholder data
  • Air France and KLM — passenger and loyalty contacts
  • Fluke Corporation — 821K B2B contact records (July 2026)
  • Ernst & Young — client tax records via third-party support system (July 2026)
  • Grubhub — customer records (early 2026)

ShinyHunters has also claimed dozens of additional victims not yet publicly confirmed. If you are a customer of any large enterprise, assume your data has been touched by this wave until you verify otherwise.

What Data Was Exposed?

Because Salesforce is a CRM, the exposed records typically include everything a company stores about its customers or contacts:

  • Full names, email addresses, phone numbers, and physical addresses
  • Employer and job title (for B2B records)
  • Support case contents — often including product serial numbers, purchase history, and personal context
  • Loyalty program IDs and preferences
  • Insurance policy numbers, tax IDs, and financial identifiers (in the worst cases like Allianz Life and EY)
  • Dates of birth and Social Security numbers in a subset of breaches

Why This Wave Is Especially Dangerous

Each individual breach might look modest. Combined, the wave gives attackers a massive cross-referenced graph: your name and address from one company's CRM, your employer from another, your insurance provider from a third, your loyalty program tier from a fourth. That combined profile is what powers convincing spear phishing, invoice fraud, insurance fraud, and business email compromise — attacks that succeed because they cite verifiable details.

Step 1: Check Have I Been Pwned Now

Go to haveibeenpwned.com and check every email address you use — personal, work, secondary aliases, throwaways used at signup. HIBP indexes most confirmed 2026 Salesforce-linked breaches, including Allianz Life, Fluke Corporation, and others. If any Salesforce-tied breach appears in your results, treat all contact information associated with that email as compromised.

Step 2: Freeze Your Credit at All Three Bureaus

If Social Security numbers or financial identifiers were exposed in a breach you were part of (Allianz Life, EY, and others), place a credit freeze at all three major bureaus immediately. It is free, does not affect your credit score, and prevents new accounts from being opened in your name.

  1. Equifax: equifax.com/personal/credit-report-services/credit-freeze
  2. Experian: experian.com/freeze/center.html
  3. TransUnion: transunion.com/credit-freeze

Also freeze the two lesser bureaus most people forget: Innovis and the NCTUE (used by lenders and cellular carriers).

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 3: Turn On Authenticator-App 2FA Everywhere

Because attackers now know your email, phone, employer, and role, they will attempt account takeovers via password-reset flows and MFA fatigue attacks. Enable two-factor authentication on every important account — use an authenticator app (Authy, Google Authenticator, 1Password) or a hardware key like YubiKey. Avoid SMS 2FA where possible: it is vulnerable to SIM-swap attacks, which are far easier when attackers already have your phone number.

Step 4: Assume Every Vendor Call Is Vishing

The 2026 Salesforce wave began with vishing calls to helpdesks. Those same tactics are now being used against consumers at scale, and they succeed because the attacker knows real details about you.

  • Never provide credentials, MFA codes, or account numbers to an inbound caller — even one who correctly names your account, address, or employer.
  • Hang up and call back on the official number from the company's website or the back of your credit card.
  • Do not click links in unexpected texts or emails claiming to be from your bank, insurer, airline, or a vendor — use the official app or website instead.
  • Set a family password that relatives can use to verify identity in an emergency — AI voice cloning combined with leaked personal details is now a mainstream scam.

The 30-Second Vishing Test

Legitimate companies almost never ask you to "verify" your account by reading a code back to them, transferring funds to a "safe account," installing software, or sharing screen access. If a caller pressures you toward any of those actions, it is a scam. Hang up, wait five minutes, and call the official number.

Step 5: Watch for Targeted Phishing Over the Next 12 Months

Salesforce-leaked contact data feeds phishing campaigns for months after each breach is disclosed. Common patterns include:

  • Fake breach notifications from law firms phishing for further personal data during class-action windows.
  • Fake support-ticket replies from spoofed vendor addresses, asking you to log in via a phishing page.
  • Invoice fraud in B2B contexts — attackers pose as a vendor and email a fake overdue invoice with new bank wire details.
  • Loyalty-program phishing offering to "restore" lost points that never existed.
  • Insurance fraud — impostor calls citing your real policy number, aiming to redirect claim payments or harvest health information.

Step 6: Remove Your Data From Broker Sites

This is the step most breach guides skip and that provides the largest long-term risk reduction. Salesforce-leaked contact data becomes exponentially more dangerous when cross-referenced with public data broker profiles. The leak tells attackers where you work; a broker profile tells them where you live, who your relatives are, what other addresses you have used, and what your estimated income is.

Together, that dossier is enough to bypass "knowledge-based authentication" at your bank, spoof calls that name your family members, execute pretexting attacks against your employer's IT helpdesk, or send convincing spear-phishing tailored to your household.

Removing your information from Spokeo, BeenVerified, Whitepages, Intelius, MyLife, TruePeopleSearch, Radaris, and 100+ other broker sites cuts off the raw material attackers need to weaponize a Salesforce-scale leak. Because brokers re-scrape public records every few weeks, most people use an automated service rather than DIY the removals every 30-60 days.

How PrivacyOn Helps After a Wave Like This

You cannot undo what already leaked — but you can shut down the secondary market that keeps making it dangerous. PrivacyOn does two things that matter most in the aftermath of a multi-vendor breach wave:

  • Removes your data from 100+ broker sites so attackers cannot pair Salesforce-leaked business records with a public profile to build a convincing social-engineering target that names your family, address history, and household context.
  • Monitors the dark web 24/7 for your email, phone number, and other identifiers, alerting you the moment your credentials show up in future breaches or combolists — including any additional ShinyHunters dumps expected in the second half of 2026.

Plans start at $8.33/month, cover up to 5 family members, and include a free scan that shows exactly which broker sites currently list your information — the profiles attackers pair with Salesforce leaks to weaponize otherwise-ordinary contact data.

Frequently Asked Questions

How do I know if I was affected by the Salesforce breach wave?

Check haveibeenpwned.com and enter every email address you use. HIBP indexes most publicly disclosed Salesforce-linked breaches from 2025-2026, including Allianz Life, Fluke, and others. You may also receive direct notification letters from any impacted company you were a customer of; check both your inbox and spam folder. Because 300-700+ companies are involved, assume you were affected by at least one and act accordingly.

Was Salesforce itself hacked?

No. The Salesforce platform was not breached. Attackers targeted individual customer tenants — the companies that use Salesforce as their CRM — by tricking employees at those companies into installing malicious OAuth apps or by exploiting insecure Experience Cloud guest-user configurations. Salesforce has published guidance for customers on OAuth app review, guest-user hardening, and Aura framework misconfigurations.

Should I stop doing business with companies that were affected?

Not necessarily. Because 700+ companies across every major industry were impacted, avoiding all of them is not practical. Focus instead on hardening your own identity: credit freezes, authenticator-app 2FA, unique passwords, and continuous data broker removal. Consider using masked email addresses (Hide My Email, SimpleLogin, DuckDuckGo Email Protection) for new signups so future breaches leak an alias, not your primary inbox.

What is ShinyHunters and Scattered Spider?

Both are financially motivated cybercrime collectives active since around 2020, sometimes cooperating and sometimes tracked as a single group (UNC6040). They specialize in stealing customer databases from cloud SaaS platforms via social engineering — typically vishing calls to IT helpdesks — then extorting the affected companies with the threat of a public leak. When ransom negotiations fail, they publish the data on their leak site. In 2026, they have hit Panera Bread, Fluke, Ernst & Young, Grubhub, hundreds of Salesforce customers, and the Canvas LMS breach affecting 275M education users.

Is there a better alternative to just enrolling in the free monitoring each company offers?

Yes. Free monitoring from breached companies is reactive — it alerts you after a fraudulent account is opened, not before, and only covers the specific data type leaked by that company. PrivacyOn provides continuous data broker removal (which prevents cross-referencing attacks) plus 24/7 dark web monitoring across all your emails and identifiers — from any breach, not just one. For $8.33/month it covers 100+ broker sites and up to 5 family members, and includes a free scan up front. Take the free monitoring companies offer, and layer PrivacyOn on top for the proactive side.

How do I stop future breaches from exposing my data?

You cannot prevent vendors from being breached, but you can shrink the fallout. Use unique passwords managed by a password manager, enable authenticator-app 2FA everywhere (not SMS), give companies as little information as legally possible, use masked email aliases for new signups, freeze your credit and keep it frozen, and remove your information from data broker sites so leaked contact info cannot be cross-referenced into a full identity profile. PrivacyOn automates the broker-removal step across 100+ sites — the single highest-leverage privacy investment you can make in 2026.

PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families