Desk live·
ForensicPost
Cloud/Extortion/File 25-1029

ShinyHunters Used Stolen CRM Data to Phish the Affected Firms' Own Clients

Operators used data taken from CRM tenants to run targeted phishing and extortion against the affected firms’ own personnel and clients. The breach became the input to the next attack.

Constructed geometry · not a chart of case data
TargetTenant clients and personnel
ActorShinyHunters
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

Reporting describes operators leveraging data stolen from CRM tenants for targeted phishing — including further voice phishing — and for extortion directed at the affected firms’ personnel and clients.

A Breach With An Operational Output

This database mostly records data going somewhere: published, sold, or held. The harm is diffuse and arrives later through channels nobody traces.

Here the output is immediate and specific. A CRM record tells an attacker who a person is, which firm they deal with, who their account manager is, what was recently discussed and what is currently outstanding. That is everything required to place a call that sounds entirely legitimate.

The corpus filed the same mechanism at 25-0613, where staff directories became reconnaissance. This is the completed version: the reconnaissance was used.

Extorting Clients Moves The Pressure Off The Balance Sheet

A company can decide, on commercial grounds, that it will not pay. It is far harder to decide that on behalf of clients receiving calls, or of employees being contacted individually.

That is the structure recorded at 25-0507, where districts were extorted after the vendor had already paid, and it works for the same reason: the party being pressured is not the party with the decision.

And It Defeats The Notification Remedy Entirely

Breach notification exists so affected people can protect themselves. It assumes a lag — data is taken, is eventually misused, and warning arrives in between.

When the misuse begins before the notification is drafted, the remedy runs behind the harm. There is no version of "monitor your accounts" that helps someone who has already taken the call.

Graded medium: the downstream targeting is described in vendor research, and this desk cannot establish its scale or success rate.

How we reported this

Compiled from published vendor research and regulatory advisories, listed below. Scale of downstream targeting is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Cybersecurity alert — Salesforce Experience Cloud security incidentFINRA
  2. Threat spotlight: ShinyHunters data breach targets Salesforce amid Scattered Spider collaborationReliaQuest
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary