Desk live·
ForensicPost
Cloud/Extortion/File 25-0923

One Technique, One Platform, Several Hundred Companies

The operators claimed to have targeted several hundred organisations through a single SaaS platform. A technique that works against one tenant works against every tenant.

Constructed geometry · not a chart of case data
TargetSaaS platform tenants
ActorShinyHunters
D. Kennedy12 min readConfidence: medium2 sources reviewed

The operators claimed to have targeted several hundred companies through a single enterprise SaaS platform, and threatened to publish data taken from those tenants unless extortion demands were met. Reporting describes millions of records compromised across the disclosed incidents.

The "several hundred" figure originates with the attackers and is recorded here as a claim.

This Is Concentration Without A Shared Compromise

The corpus files supplier concentration constantly — one vendor breached, dozens of downstream victims, as at 25-0814 and 25-0801. This is a different shape and produces the same outcome.

The platform was not compromised. Each tenant was reached separately, through its own employees, using its own legitimate authorisation flow. What concentrated was not the data but the *method*: every customer of a widely-adopted platform presents the same interface, the same consent screen and the same vocabulary for a caller to use.

Standardisation is what makes enterprise software work. It also means research costs are paid once and reused indefinitely — the sector-rotation argument at 25-0512, generalised from an industry to a product.

The Platform Vendor Cannot Fix It And Cannot Escape It

No defect existed to patch. The vendor’s consent model worked as designed; its customers authorised applications they should not have.

And yet the vendor is the only party positioned to act at the scale of the problem — by changing enrolment defaults, restricting connected-app authorisation, or alerting on anomalous grants across tenants. The party with no fault has the only lever, which is an accountability structure this database has not previously recorded in quite this form.

How we reported this

Compiled from published research and regulatory advisories, listed below. The victim count is an attacker claim and is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Hundreds of Salesforce customers allegedly targeted in new data theft campaignSecurityWeek
  2. Cybersecurity alert — Salesforce Experience Cloud security incidentFINRA
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary