2026 Salesforce Data Breach Roundup: What You Need to Know
The wave of Salesforce-targeted data theft that started late last year shows no signs of slowing down.
In 2026, high-profile companies continue to fall victim — this time, threat actors are exploiting “overly permissive” Experience Cloud guest user configurations.
If your business runs on Salesforce, staying informed and protected is no longer optional.
That’s where Pletratech comes in. As the best choice for Salesforce security consulting and CRM optimization, Pletratech helps businesses lock down vulnerabilities before attackers can exploit them.
2026 Attack Timeline
The hacking group ShinyHunters has been the primary actor behind most of these breaches. Here’s what unfolded:
January 19 — Food delivery giant Grubhub confirmed a data breach linked to ShinyHunters.
February 16 — Telecom company Odido (formerly T-Mobile Netherlands) was named a victim of social engineering attacks on Salesforce instances.
March 7 — Salesforce officially disclosed it had been tracking a campaign targeting misconfigured Experience Cloud guest user settings.
March 9 — ShinyHunters claimed to have compromised ~100 high-profile companies. Legal data firm LexisNexis had 3.9M records allegedly exfiltrated.
March 10–18 — Canada’s largest grocer Loblaw disclosed a breach involving a staggering 75.1M Salesforce records.
March 24 — Infinite Campus warned customers that hackers accessed an employee’s Salesforce account via ShinyHunters.
March 31 — Axios, Hallmark (7.9M records), and Cisco Systems all became targets, with ShinyHunters issuing extortion demands.
April 18 — ShinyHunters released a new “pay or leak” list targeting 7-Eleven, Pitney Bowes, Aman Resorts, and others.
April 27 — Home security giant ADT confirmed a breach involving over 10M Salesforce records.
How to Protect Your Salesforce Org
Salesforce recommends these immediate actions for all Experience Cloud users:
Audit guest user profiles — restrict access to the absolute minimum objects and fields needed
Set Org-Wide Defaults to “Private” for all objects under Sharing Settings
Disable Public APIs by unchecking “API Enabled” in guest user System Permissions
Restrict visibility by unchecking “Portal User Visibility” and “Site User Visibility”
Disable self-registration if unauthenticated account creation isn’t required
Don’t Wait for a Breach
These attacks prove that even enterprise-level companies aren’t immune to misconfiguration risks.
Pletratech specializes in proactive Salesforce security audits, helping you identify and close dangerous gaps before threat actors find them.
With Pletratech by your side, your data stays where it belongs — safe and secure.











