We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

The ShinyHunters Scam on Salesforce: How a Fake IT Support Team Empties Your CRM—and How to Avoid It

The ShinyHunters group claims to have stolen 21 million Salesforce records from the French company Questel. Behind this attack lies a simple method that targets any company using an online CRM: a fake call from IT support. Here’s how it works and what steps you can take to protect your teams.

The ShinyHunters Scam on Salesforce: How a Fake IT Support Team Empties Your CRM—and How to Avoid It

In summary. The ShinyHunters group claims to have stolen 21 million Salesforce records from the French software publisher Questel—not through a software vulnerability, but via a fake IT support call. This technique targets any company that uses a cloud-based CRM, including small and medium-sized businesses.

What Happened

On August 2, 2026, ShinyHunters listed the Paris-based company Questel on its leak site. The group claims to have 147 GB of internal data and more than 21 million Salesforce records containing personal information, setting an ultimatum of August 4 for Questel to get in touch before the data is published. Questel develops software for intellectual property and innovation management. At this point, the authenticity and exact origin of the data have not been independently confirmed, and the company has not issued a public statement.

This incident is part of an ongoing campaign that has been underway for months. On July 13, 2026, Microsoft detailed the group’s method: between mid-2025 and mid-2026, ShinyHunters hijacked Salesforce OAuth connections to bypass two-factor authentication and extract customer databases. Three common entry points have been identified: a phishing call to an employee, the theft of access tokens from a service provider, and misconfigured guest accounts. The most common method is the phone call. A fake support technician guides the employee to a Salesforce authorization screen and has them approve an application disguised as a legitimate tool, often a fake “Data Loader.” Once the app is connected, the attacker reads and exports the data without ever stealing a password.

Does this apply to me?

You are at risk if your company stores contacts, quotes, or customer files in an online CRM—such as Salesforce—or any SaaS tool that supports third-party applications via OAuth. The vulnerability being exploited isn’t the software itself, but rather the human tendency to say yes to an “IT specialist” on the phone. Small and medium-sized businesses (SMBs) are particularly easy targets: they have smaller in-house security teams, employees who are accustomed to having an external vendor manage their IT, and application connections that are rarely audited.

Two related risks deserve your attention. First, your own customer data, which could be used for targeted phishing or wire transfer fraud in the coming weeks. Second, the data you’ve entrusted to a vendor: if one of your SaaS providers has its CRM compromised, your information could be compromised as well—without you being notified right away.

What to Do Now

1. Review the apps connected to your CRM. In Salesforce, as in most SaaS tools, there is a screen that lists the apps authorized via OAuth. Remove any that no one recognizes, starting with any recently installed “Data Loader” or export connector.

2. Inform your teams of the exact procedure. A legitimate IT department never asks you to approve an authorization urgently during a phone call. The guideline can be summed up in one sentence: If you receive a request for authorization over the phone, hang up and call your usual internal contact back.

3. Restrict who can connect an application. Limit the installation of new connected apps to administrators, enable phishing-resistant MFA (physical token or passkey), and keep track of OAuth authorizations. These settings are part of maintaining a well-managed Microsoft 365 and Salesforce environment.

If no one in your company is currently managing your SaaS access and logins, this is the first task you should entrust to your IT outsourcing provider. You can get a quick update by visiting our contact page.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

ShinyHunters doesn't break into Salesforce; it convinces an employee to open the door. The solution is within reach: clean up connected applications, provide clear instructions to teams, and monitor permissions. A few adjustments are all it takes to close that door, and an SME with the right support can handle it without spending all day on it.

Frequently asked questions

Should we change our Salesforce passwords? It’s a useful precaution, but not enough on its own: the attack comes through an authorized app, not a password. First, check the connected apps.

Does MFA protect us? Not in this case: the victim authorizes access themselves, which bypasses the second factor. Phishing-resistant MFA helps, but the vigilance of the teams remains crucial.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
software
Development & automation

"I'm afraid to install software"

In 1996, I took my first steps in computing on an Excel spreadsheet where I filed cheat codes for my favorite video games. 🕹️Le the beginning of a passion for office tools (to each his own 😅 ). There were 3,000 machines connected to the internet! 😶 But what happened next?
July 31, 2026
fishing
Cybersecurity

Phishing 2026: Definition, Examples, and Protection for Small and Medium-Sized Businesses (Comprehensive Guide)

Spear phishing, BEC, voice deepfakes: why training alone isn’t enough, the true cost of an incident (€275,000), and the security measures that will work in 2026
June 26, 2026
backup-vs-retention
Cloud & infrastructure

Comparing backup VS retention

Backup VS retention: here's the match everyone's been waiting for!!!! 🥊 (okai not at all but I needed a catchy title..🤫)
August 3, 2026