In summary. The ShinyHunters group claims to have stolen 21 million Salesforce records from the French software publisher Questel—not through a software vulnerability, but via a fake IT support call. This technique targets any company that uses a cloud-based CRM, including small and medium-sized businesses.
What Happened
On August 2, 2026, ShinyHunters listed the Paris-based company Questel on its leak site. The group claims to have 147 GB of internal data and more than 21 million Salesforce records containing personal information, setting an ultimatum of August 4 for Questel to get in touch before the data is published. Questel develops software for intellectual property and innovation management. At this point, the authenticity and exact origin of the data have not been independently confirmed, and the company has not issued a public statement.
This incident is part of an ongoing campaign that has been underway for months. On July 13, 2026, Microsoft detailed the group’s method: between mid-2025 and mid-2026, ShinyHunters hijacked Salesforce OAuth connections to bypass two-factor authentication and extract customer databases. Three common entry points have been identified: a phishing call to an employee, the theft of access tokens from a service provider, and misconfigured guest accounts. The most common method is the phone call. A fake support technician guides the employee to a Salesforce authorization screen and has them approve an application disguised as a legitimate tool, often a fake “Data Loader.” Once the app is connected, the attacker reads and exports the data without ever stealing a password.
Does this apply to me?
You are at risk if your company stores contacts, quotes, or customer files in an online CRM—such as Salesforce—or any SaaS tool that supports third-party applications via OAuth. The vulnerability being exploited isn’t the software itself, but rather the human tendency to say yes to an “IT specialist” on the phone. Small and medium-sized businesses (SMBs) are particularly easy targets: they have smaller in-house security teams, employees who are accustomed to having an external vendor manage their IT, and application connections that are rarely audited.
Two related risks deserve your attention. First, your own customer data, which could be used for targeted phishing or wire transfer fraud in the coming weeks. Second, the data you’ve entrusted to a vendor: if one of your SaaS providers has its CRM compromised, your information could be compromised as well—without you being notified right away.
What to Do Now
1. Review the apps connected to your CRM. In Salesforce, as in most SaaS tools, there is a screen that lists the apps authorized via OAuth. Remove any that no one recognizes, starting with any recently installed “Data Loader” or export connector.
2. Inform your teams of the exact procedure. A legitimate IT department never asks you to approve an authorization urgently during a phone call. The guideline can be summed up in one sentence: If you receive a request for authorization over the phone, hang up and call your usual internal contact back.
3. Restrict who can connect an application. Limit the installation of new connected apps to administrators, enable phishing-resistant MFA (physical token or passkey), and keep track of OAuth authorizations. These settings are part of maintaining a well-managed Microsoft 365 and Salesforce environment.
If no one in your company is currently managing your SaaS access and logins, this is the first task you should entrust to your IT outsourcing provider. You can get a quick update by visiting our contact page.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
ShinyHunters doesn't break into Salesforce; it convinces an employee to open the door. The solution is within reach: clean up connected applications, provide clear instructions to teams, and monitor permissions. A few adjustments are all it takes to close that door, and an SME with the right support can handle it without spending all day on it.
Frequently asked questions
Should we change our Salesforce passwords? It’s a useful precaution, but not enough on its own: the attack comes through an authorized app, not a password. First, check the connected apps.
Does MFA protect us? Not in this case: the victim authorizes access themselves, which bypasses the second factor. Phishing-resistant MFA helps, but the vigilance of the teams remains crucial.
— Samir Amara, CEO — IT Systèmes



