Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted

Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 (TL-2026-0804), also tracked as Infinite Campus Salesforce Breach, is a high-severity data breach, first published 2026-06-15. It is attributed to ShinyHunters with high confidence, affects Infinite Campus Infinite Campus (corporate Salesforce CRM instance), maps to 23 MITRE ATT&CK techniques (T1020, T1071, T1078), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-0804

Threat ID
TL-2026-0804
Also known as
Infinite Campus Salesforce Breach, Scattered LAPSUS$ Hunters Salesforce Extortion, UNC6040 Salesforce Data Theft Campaign
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-06-15
Last reviewed
2026-06-15
Attribution
ShinyHunters
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
education, k-12, government, technology, saas
Target regions
North America, United States
Detection rules
9
Indicators of compromise
30

Malware and tooling in Infinite Campus Salesforce Breach by ShinyHunters / UNC6040

Malware and tooling: Modified Salesforce Data Loader (Python emulation), TruffleHog - S9009

ShinyHunters (Google-tracked UNC6040 intrusion / UNC6240 extortion, part of the Scattered LAPSUS$ Hunters collective) compromised the Salesforce instance of education-technology vendor Infinite Campus via voice-phishing-driven OAuth abuse, exfiltrating a 1.2GB archive of 137,100 unique school-staff records. The data — names, emails, employers, job titles, phone numbers, physical addresses, usernames, and support tickets — was published on the group's data-leak site after Infinite Campus refused to pay. The vendor serves 3,200+ U.S. school districts and manages data for ~11 million students across 46 states.

How Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 works

On 18 March 2026, multiple internal security controls at Infinite Campus flagged anomalous activity tied to a Salesforce account belonging to an employee. The account was disabled the same day, and that evening the threat actor contacted the company claiming affiliation with ShinyHunters, a financially motivated extortion group responsible for a year-long wave of Salesforce data thefts across hundreds of organizations. The actor set an extortion deadline of 25 March 2026 and threatened to leak the stolen data. Infinite Campus publicly stated it would not engage with the extortion attempt; the actor subsequently published a 1.2GB archive of 137,100 unique Salesforce records, surfaced via Have I Been Pwned, and disclosed publicly on 15 June 2026.

This incident is one node in the broader 2024-2026 UNC6040 / ShinyHunters Salesforce data-theft campaign. The intrusion technique does not rely on a software vulnerability or a Salesforce platform flaw; it abuses the legitimate Salesforce connected-app OAuth authorization flow. UNC6040 operators place telephone calls (vishing) to English-speaking employees and IT/help-desk staff while impersonating internal IT support. During the call the victim is directed to Salesforce's connected-app setup page (login.salesforce.com/setup) and persuaded to enter an attacker-supplied 8-digit connection/authorization code, which links an attacker-controlled, deceptively named OAuth application — frequently a modified or re-branded build of Salesforce's own Data Loader utility (observed app labels include 'My Ticket Portal' and generic 'Data Loader' clones) — to the victim's Salesforce org. Because the victim performs the OAuth consent, the malicious app inherits the user's API privileges and MFA is effectively bypassed: no further credential prompt is required for the app's API calls.

With a valid OAuth refresh/access token, the operators query and bulk-export Salesforce objects through the API using both the genuine Data Loader and custom Python tooling that emulates Data Loader behavior (observed user-agents include 'Salesforce-Multi-Org-Fetcher/1.0', 'Salesforce-CLI/1.0', 'python-requests/2.32.4', and 'Python/3.11 aiohttp/3.12.15'). Tradecraft includes small initial 'test' queries to fingerprint the org and avoid volume-based alerts, followed by rapid scaling of export volume. Infrastructure is obscured behind Mullvad VPN and TOR exit nodes (multiple 185.220.101.0/24 addresses are well-known TOR exits) to frustrate attribution and bypass IP-based controls. In many engagements the same OAuth/credential foothold is leveraged for lateral movement into Okta, Microsoft 365, and other SaaS platforms.

Monetization is handled by the UNC6240 extortion arm under the ShinyHunters brand: victims receive emails (shinycorp@tuta.com, shinygroup@tuta.com, shinyhuntersgroups@tutamail.com) demanding Bitcoin within a 72-hour window, often months after the initial intrusion. In October 2025 the collective escalated by launching a dedicated 'Scattered LAPSUS$ Hunters' data-leak site naming 39-40 victim organizations (including Qantas, Allianz Life, Cisco, Adidas, LVMH brands, Google, FedEx, Toyota and others) and claiming ~1 billion records, with leaks published 10 October 2025 hours after the FBI/BL2C seizure of BreachForums. The Infinite Campus breach follows the same intrusion-then-extortion playbook. Infinite Campus maintains that core customer databases and sensitive student records were not accessed, characterizing the exposed data as directory-style staff information much of which is publicly available on school websites; ShinyHunters claims the archive contains PII and internal corporate data — a more severe characterization. The incident echoes the December 2024 PowerSchool breach (62M students) in sector and sensitivity, underscoring the K-12 supply-chain risk concentrated in a handful of EdTech SaaS vendors.

MITRE ATT&CK techniques used in TL-2026-0804

Exfiltration

T1020 Automated Exfiltration; T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing

Persistence

T1078 Valid Accounts; T1556 Modify Authentication Process

Discovery

T1087 Account Discovery; T1538 Cloud Service Dashboard

command-and-control

T1090 Proxy

Collection

T1213 Data from Information Repositories

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1621 Multi-Factor Authentication Request Generation

collection

T1530 Data from Cloud Storage

lateral-movement

T1550 Use Alternate Authentication Material

Lateral Movement

T1550 Use Alternate Authentication Material

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Infinite Campus Salesforce Breach by ShinyHunters / UNC6040

  • Infinite Campus — Infinite Campus (corporate Salesforce CRM instance)
    Vulnerable versions: Corporate Salesforce org with OAuth connected-app authorization enabled
  • Salesforce — Salesforce / Data Loader (OAuth connected-app authorization flow abused; not a product flaw)
    Vulnerable versions: All orgs without connected-app allowlisting / approval workflow

Remediation for Infinite Campus Salesforce Breach by ShinyHunters / UNC6040

Immediate actions

  • Audit all Salesforce connected apps; revoke any unrecognized OAuth applications and refresh tokens (especially Data Loader clones or apps such as 'My Ticket Portal').
  • Disable the affected employee Salesforce account and rotate all associated credentials and session tokens.
  • Block the published UNC6040/UNC6240 IPs, TOR exit ranges, and known extortion email addresses at perimeter and mail gateways.
  • Search Salesforce Event Monitoring / login history for the attacker user-agents and Mullvad/TOR source IPs.

Workarounds

  • Block commercial VPN and TOR IP ranges from authenticating to SaaS where feasible.
  • Require admin approval for all newly authorized OAuth connected apps.

Longer-term hardening

  • Restrict the 'API Enabled' permission and Data Loader access to a minimal set of vetted accounts.
  • Restrict 'Customize Application' and 'Manage Connected Apps' permissions to essential administrators and require an approval workflow for new connected apps.
  • Allowlist approved connected apps and enforce IP-based login ranges limited to trusted corporate/VPN egress.
  • Deploy Salesforce Shield (Event Monitoring + Transaction Security Policies) to alert on large data exports and anomalous connected-app authorizations.
  • Deliver targeted anti-vishing / social-engineering training to help-desk and IT-support staff; establish out-of-band caller verification.

Weaknesses (CWE) in Infinite Campus Salesforce Breach by ShinyHunters / UNC6040

CWE-1021, CWE-862, CWE-269, CWE-522, CWE-200

Timeline of Infinite Campus Salesforce Breach by ShinyHunters / UNC6040

  • UNC6040 begins voice-phishing campaign abusing Salesforce connected-app OAuth flow to deploy malicious Data Loader clones (late 2024, per Google Threat Intelligence).
  • Google Threat Intelligence (Mandiant) publicly discloses UNC6040, detailing vishing-to-Data-Loader OAuth abuse and the UNC6240 extortion arm operating under the ShinyHunters brand.
  • FBI publishes FLASH advisory with IOCs (IPs, user-agents, email addresses) for UNC6040 and UNC6395 Salesforce data-theft activity.
  • 'Scattered LAPSUS$ Hunters' launch a dedicated data-leak site naming 39-40 Salesforce victim organizations and claiming ~1 billion records, with a 10 October ransom deadline.
  • Collective publishes first wave of stolen Salesforce victim data, hours after the FBI/BL2C seizure of BreachForums.
  • Same evening, the threat actor contacts Infinite Campus claiming ShinyHunters affiliation and demands a ransom to prevent a data leak.
  • Infinite Campus internal security controls flag anomalous activity on an employee Salesforce account; the account is disabled the same day.
  • ShinyHunters extortion deadline; Infinite Campus declines to engage with the extortion attempt.
  • 1.2GB archive of 137,100 unique Infinite Campus Salesforce staff records published on the leak site and surfaced via Have I Been Pwned; breach disclosed publicly.

Sources cited for Infinite Campus Salesforce Breach by ShinyHunters / UNC6040

Threats related to Infinite Campus Salesforce Breach by ShinyHunters / UNC6040

Detection coverage for TL-2026-0804

As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0804 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats