ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering — Threadlinqs Intelligence
As of 2026-05-30, ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering is a critical-severity campaign threat attributed to ShinyHunters (Multiple (United States, United Kingdom, Jordan)), tracked by Threadlinqs Intelligence with 23 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 108 indicators of compromise.
Threat ID: TL-2026-0013 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: CAMPAIGN
Attribution: ShinyHunters · Multiple (United States, United Kingdom, Jordan) · FINANCIAL
ShinyHunters (UNC6040/UNC6395/UNC6240) is a prolific English-speaking cybercriminal group operating as part of the 'Scattered LAPSUS$ Hunters' (SLSH) — an amalgamation of ShinyHunters, Scattered
ShinyHunters and the Scattered LAPSUS$ Hunters represent the evolution of cybercrime from technical exploitation to SOCIAL ENGINEERING AT SCALE. This is not a sophisticated APT using zero-days — it's teenagers using phone calls, vishing, SIM swapping, and insider recruitment to breach the world's largest corporations.
**The Group — Scattered LAPSUS$ Hunters (SLSH):**
SLSH is an amalgamation of three cybercriminal groups operating from 'the Com' — a mostly English-language cybercriminal community spanning Telegram and Discord servers:
1. **ShinyHunters** (Google: UNC6040) — Data theft and extortion specialists. Responsible for the Salesforce vishing campaign, BreachForums administration, and mass data breaches since 2020.
2. **Scattered Spider** (Google: UNC3944, Microsoft: Octo Tempest) — Social engineering experts targeting corporate helpdesks. Known for MGM Resorts, Caesars Entertainment, and dozens of other breaches via SIM swapping and MFA fatigue.
3. **LAPSUS$** — The original 'Advanced Persistent Teenagers' group that breached Microsoft, Nvidia, Samsung, Uber, and Okta in 2021-2022.
Members overlap significantly and operate across shared Telegram/Discord channels on the Com.
**The Salesforce Vishing Campaign (May 2025):**
The flagship SLSH operation of 2025:
- Voice phishing (vishing) calls to employees at target companies
- Social engineering targets into connecting malicious OAuth apps to their organization's Salesforce portal
- Siphoned over 1 BILLION records from Salesforce customer instances
- Google Threat Intelligence Group (GTIG) warned in June 2025
- Google itself was impacted — their own corporate Salesforce instance was compromised
- 36+ Fortune 500 companies had data stolen: Toyota, FedEx, Disney/Hulu, UPS, and more
- Data leak website launched October 2025: 'Scattered LAPSUS$ Hunters' blog threatening publication
- Group demanded Salesforce pay a single ransom to protect ALL customers: 'If we come to a resolution all individual extortions against your customers will be withdrawn'
- Salesforce refused: 'Salesforce will not engage, negotiate with, or pay any extortion demand'
**The Salesloft Breach (August 2025):**
A separate but connected SLSH operation (tracked as UNC6395):
- Compromised Salesloft, an AI chatbot maker used by many corporations to convert customer interactions into Salesforce leads
- Stole authentication tokens for hundreds of cloud services integrated with Salesloft
- Affected services: Snowflake, Amazon AWS, Microsoft Azure, Slack, Google Workspace, Docker, OpenAI
- Google warned the breach 'goes far beyond Salesforce data'
- Hundreds more organizations affected beyond the initial Salesforce campaign
**Red Hat GitLab Breach (September 2025):**
- Compromised Red Hat's consulting GitLab server
- Stole 28,000+ Git code repositories
- 5,000+ Customer Engagement Reports (CERs) containing client secrets
- Exposed: Artifactory tokens, Git tokens, Azure credentials, Docker credentials, client infrastructure details, audit reports
- Red Hat disclosed October 2, 2025
**Discord Breach (September 2025):**
- Compromised third-party customer service provider used by Discord
- Stole usernames, emails, IP addresses, last 4 digits of payment cards, government ID images from age verification
- Discord began notifying affected users
**Oracle Zero-Day (CVE-2025-61882):**
- SLSH's extortion blog disclosed a critical zero-day in Oracle E-Business Suite
- Unauthenticated remote code execution
- Initially exploited in August 2025 by Clop ransomware
- Oracle issued emergency patch
- SLSH published exploitation scripts on their blog before it was taken down
**ShinySp1d3r Ransomware-as-a-Service:**
- SLSH launched its own RaaS in November 2025
- Derived from Hellcat ransomware source code, modified with AI tools
- Released by Rey (Saif Al-Din Khader)
- Previously used other groups' encryptors: ALPHV/BlackCat, Qilin, RansomHub, DragonForce
**Corporate Insider Recruitment:**
- SLSH actively recruits i
Weaknesses (CWE)
CWE-287, CWE-352, CWE-601
Target sectors: Technology, Financial Services, Retail, Entertainment, Telecommunications, Healthcare, Government, Hospitality, Cloud Services, Cybersecurity
Target regions: Global, North America, Europe, United Kingdom
Detections & IOCs
As of 2026-07-28, this threat has 23 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 108 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CAMPAIGN, CRITICAL, threat intelligence, cybersecurity, T1589, T1594, T1593, T1583, T1596, T1597, T1566, T1566, T1598, T1598