Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted
Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 (TL-2026-0804), also tracked as Infinite Campus Salesforce Breach, is a high-severity data breach, first published 2026-06-15. It is attributed to ShinyHunters with high confidence, affects Infinite Campus Infinite Campus (corporate Salesforce CRM instance), maps to 23 MITRE ATT&CK techniques (T1020, T1071, T1078), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0804
- Threat ID
- TL-2026-0804
- Also known as
- Infinite Campus Salesforce Breach, Scattered LAPSUS$ Hunters Salesforce Extortion, UNC6040 Salesforce Data Theft Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-06-15
- Last reviewed
- 2026-06-15
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- education, k-12, government, technology, saas
- Target regions
- North America, United States
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Infinite Campus Salesforce Breach by ShinyHunters / UNC6040
Malware and tooling: Modified Salesforce Data Loader (Python emulation), TruffleHog - S9009
ShinyHunters (Google-tracked UNC6040 intrusion / UNC6240 extortion, part of the Scattered LAPSUS$ Hunters collective) compromised the Salesforce instance of education-technology vendor Infinite Campus via voice-phishing-driven OAuth abuse, exfiltrating a 1.2GB archive of 137,100 unique school-staff records. The data — names, emails, employers, job titles, phone numbers, physical addresses, usernames, and support tickets — was published on the group's data-leak site after Infinite Campus refused to pay. The vendor serves 3,200+ U.S. school districts and manages data for ~11 million students across 46 states.
How Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 works
On 18 March 2026, multiple internal security controls at Infinite Campus flagged anomalous activity tied to a Salesforce account belonging to an employee. The account was disabled the same day, and that evening the threat actor contacted the company claiming affiliation with ShinyHunters, a financially motivated extortion group responsible for a year-long wave of Salesforce data thefts across hundreds of organizations. The actor set an extortion deadline of 25 March 2026 and threatened to leak the stolen data. Infinite Campus publicly stated it would not engage with the extortion attempt; the actor subsequently published a 1.2GB archive of 137,100 unique Salesforce records, surfaced via Have I Been Pwned, and disclosed publicly on 15 June 2026.
This incident is one node in the broader 2024-2026 UNC6040 / ShinyHunters Salesforce data-theft campaign. The intrusion technique does not rely on a software vulnerability or a Salesforce platform flaw; it abuses the legitimate Salesforce connected-app OAuth authorization flow. UNC6040 operators place telephone calls (vishing) to English-speaking employees and IT/help-desk staff while impersonating internal IT support. During the call the victim is directed to Salesforce's connected-app setup page (login.salesforce.com/setup) and persuaded to enter an attacker-supplied 8-digit connection/authorization code, which links an attacker-controlled, deceptively named OAuth application — frequently a modified or re-branded build of Salesforce's own Data Loader utility (observed app labels include 'My Ticket Portal' and generic 'Data Loader' clones) — to the victim's Salesforce org. Because the victim performs the OAuth consent, the malicious app inherits the user's API privileges and MFA is effectively bypassed: no further credential prompt is required for the app's API calls.
With a valid OAuth refresh/access token, the operators query and bulk-export Salesforce objects through the API using both the genuine Data Loader and custom Python tooling that emulates Data Loader behavior (observed user-agents include 'Salesforce-Multi-Org-Fetcher/1.0', 'Salesforce-CLI/1.0', 'python-requests/2.32.4', and 'Python/3.11 aiohttp/3.12.15'). Tradecraft includes small initial 'test' queries to fingerprint the org and avoid volume-based alerts, followed by rapid scaling of export volume. Infrastructure is obscured behind Mullvad VPN and TOR exit nodes (multiple 185.220.101.0/24 addresses are well-known TOR exits) to frustrate attribution and bypass IP-based controls. In many engagements the same OAuth/credential foothold is leveraged for lateral movement into Okta, Microsoft 365, and other SaaS platforms.
Monetization is handled by the UNC6240 extortion arm under the ShinyHunters brand: victims receive emails (shinycorp@tuta.com, shinygroup@tuta.com, shinyhuntersgroups@tutamail.com) demanding Bitcoin within a 72-hour window, often months after the initial intrusion. In October 2025 the collective escalated by launching a dedicated 'Scattered LAPSUS$ Hunters' data-leak site naming 39-40 victim organizations (including Qantas, Allianz Life, Cisco, Adidas, LVMH brands, Google, FedEx, Toyota and others) and claiming ~1 billion records, with leaks published 10 October 2025 hours after the FBI/BL2C seizure of BreachForums. The Infinite Campus breach follows the same intrusion-then-extortion playbook. Infinite Campus maintains that core customer databases and sensitive student records were not accessed, characterizing the exposed data as directory-style staff information much of which is publicly available on school websites; ShinyHunters claims the archive contains PII and internal corporate data — a more severe characterization. The incident echoes the December 2024 PowerSchool breach (62M students) in sector and sensitivity, underscoring the K-12 supply-chain risk concentrated in a handful of EdTech SaaS vendors.
MITRE ATT&CK techniques used in TL-2026-0804
Exfiltration
T1020 Automated Exfiltration; T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Persistence
T1078 Valid Accounts; T1556 Modify Authentication Process
Discovery
T1087 Account Discovery; T1538 Cloud Service Dashboard
command-and-control
Collection
T1213 Data from Information Repositories
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1621 Multi-Factor Authentication Request Generation
collection
lateral-movement
T1550 Use Alternate Authentication Material
Lateral Movement
T1550 Use Alternate Authentication Material
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information
reconnaissance
T1598 Phishing for Information
Impact
defense-impairment
Affected products and versions in Infinite Campus Salesforce Breach by ShinyHunters / UNC6040
- Infinite Campus — Infinite Campus (corporate Salesforce CRM instance)
Vulnerable versions: Corporate Salesforce org with OAuth connected-app authorization enabled - Salesforce — Salesforce / Data Loader (OAuth connected-app authorization flow abused; not a product flaw)
Vulnerable versions: All orgs without connected-app allowlisting / approval workflow
Remediation for Infinite Campus Salesforce Breach by ShinyHunters / UNC6040
Immediate actions
- Audit all Salesforce connected apps; revoke any unrecognized OAuth applications and refresh tokens (especially Data Loader clones or apps such as 'My Ticket Portal').
- Disable the affected employee Salesforce account and rotate all associated credentials and session tokens.
- Block the published UNC6040/UNC6240 IPs, TOR exit ranges, and known extortion email addresses at perimeter and mail gateways.
- Search Salesforce Event Monitoring / login history for the attacker user-agents and Mullvad/TOR source IPs.
Workarounds
- Block commercial VPN and TOR IP ranges from authenticating to SaaS where feasible.
- Require admin approval for all newly authorized OAuth connected apps.
Longer-term hardening
- Restrict the 'API Enabled' permission and Data Loader access to a minimal set of vetted accounts.
- Restrict 'Customize Application' and 'Manage Connected Apps' permissions to essential administrators and require an approval workflow for new connected apps.
- Allowlist approved connected apps and enforce IP-based login ranges limited to trusted corporate/VPN egress.
- Deploy Salesforce Shield (Event Monitoring + Transaction Security Policies) to alert on large data exports and anomalous connected-app authorizations.
- Deliver targeted anti-vishing / social-engineering training to help-desk and IT-support staff; establish out-of-band caller verification.
Weaknesses (CWE) in Infinite Campus Salesforce Breach by ShinyHunters / UNC6040
CWE-1021, CWE-862, CWE-269, CWE-522, CWE-200
Timeline of Infinite Campus Salesforce Breach by ShinyHunters / UNC6040
- UNC6040 begins voice-phishing campaign abusing Salesforce connected-app OAuth flow to deploy malicious Data Loader clones (late 2024, per Google Threat Intelligence).
- Google Threat Intelligence (Mandiant) publicly discloses UNC6040, detailing vishing-to-Data-Loader OAuth abuse and the UNC6240 extortion arm operating under the ShinyHunters brand.
- FBI publishes FLASH advisory with IOCs (IPs, user-agents, email addresses) for UNC6040 and UNC6395 Salesforce data-theft activity.
- 'Scattered LAPSUS$ Hunters' launch a dedicated data-leak site naming 39-40 Salesforce victim organizations and claiming ~1 billion records, with a 10 October ransom deadline.
- Collective publishes first wave of stolen Salesforce victim data, hours after the FBI/BL2C seizure of BreachForums.
- Same evening, the threat actor contacts Infinite Campus claiming ShinyHunters affiliation and demands a ransom to prevent a data leak.
- Infinite Campus internal security controls flag anomalous activity on an employee Salesforce account; the account is disabled the same day.
- ShinyHunters extortion deadline; Infinite Campus declines to engage with the extortion attempt.
- 1.2GB archive of 137,100 unique Infinite Campus Salesforce staff records published on the leak site and surfaced via Have I Been Pwned; breach disclosed publicly.
Sources cited for Infinite Campus Salesforce Breach by ShinyHunters / UNC6040
- Infinite Campus data breach affects 137,000 school staff accounts
- Infinite Campus warns of breach after ShinyHunters claims data theft
- Infinite Campus discloses Salesforce breach as ShinyHunters claims data theft
- The Cost of a Call: From Voice Phishing to Data Extortion (UNC6040)
- Google Salesforce Breach: A Deep Dive into the UNC6040 Compromise Chain
- FBI FLASH: Cyber Criminal Groups UNC6040 and UNC6395 Targeting Salesforce (IOCs)
- FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data
- Scattered Lapsus$ Hunters Leak First Wave of Salesforce Victim Data
- Hackers launch data leak site to extort 39 victims, or Salesforce
- Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App
- What Salesforce Organizations Need to Know About ShinyHunters and Vishing
- Hacker group breached Infinite Campus, school software used by 11 million students
Threats related to Infinite Campus Salesforce Breach by ShinyHunters / UNC6040
- ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments
- NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII Theft
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering
Detection coverage for TL-2026-0804
As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0804 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.