Google says database holding customer data breached by hackers


This recording was made using enhanced software.

Summary

Salesforce database

Google says one of its Salesforce databases, which holds information on small and medium-sized businesses, was breached.

ShinyHunters

Google says the cybercrime group “ShinyHunters,” known for breaching Salesforce databases and extorting victims, is to blame.

Vishing attacks

ShinyHunters are known for vishing, or voice phishing attacks, which involve tricking company employees into giving sensitive information over the phone.


Google has revealed that one of its Salesforce database systems, used for holding information on small- and medium-sized businesses, was breached by hackers. The intrusion has been attributed to ShinyHunters, a cybercrime group known for extorting companies with stolen data.

In a blog post on Tuesday, Google said it believed ShinyHunters, also known as UNC6040, was able to briefly access “basic and largely publicly available business information, such as business names and contact details,” before being booted from the system.

QR code for SAN app download

Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™

Point phone camera here

Google has not said whether it has received ransom requests in relation to the breach.

Hacking through ‘social engineering’

The notice of the breach came as an update to a June report from Google that warned of the hacking group’s extortion activities. Google said ShinyHunters were breaching company databases by using voice phishing, or “vishing,” a tactic that involves social engineering over the phone.

Members of ShinyHunters often pose as IT support personnel to trick company employees into granting access to restricted information. After gaining access to internal files, ShinyHunters will call the targeted companies again to demand a ransom.

“The extortion involves calls or emails to employees of the victim organization demanding payment in bitcoin within 72 hours,” Google wrote. “During these communications, UNC6240 has consistently claimed to be the threat group ShinyHunters.”

Google said it knows of no instances in which hackers gained access by exploiting any vulnerability in Salesforce. Instead, the hackers have solely relied on what they called “particularly effective” social engineering tactics.

“Threat actors are increasingly targeting IT support personnel as a primary vector for gaining initial access, exploiting their roles to compromise valuable enterprise data,” Google wrote. “The success of campaigns like UNC6040’s, leveraging these refined vishing tactics, demonstrates that this approach remains an effective threat vector for financially motivated groups seeking to breach organizational defenses.”

Group targets major companies

A ShinyHunters member told the tech site BleepingComputer this week that the group was responsible for the breach of a trillion-dollar company, but did not specify whether that meant Google.

The hacking group said it was considering leaking all the data without making any extortion attempts.

Other high-profile companies targeted by ShinyHunters include Adidas, AT&T, Cisco, Louis Vuitton, Dior and Tiffany & Co., among others.

Tags: , , ,

Straight Arrow
Fear No Fact.

Don't just take our word for it.


Center-rated reporting

According to media bias experts at AllSides

AllSides Center-rated reporting May 2026

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Why this story matters

A hacker group accessed Google’s Salesforce database for small- and medium-sized businesses using social engineering, raising concerns about data protection and the growing risks of sophisticated hacking tactics targeting major companies.

Social engineering

The breach relied on social engineering, highlighting the threat posed by tactics like vishing, where hackers manipulate employees to gain access without exploiting software vulnerabilities.

Cybercrime targeting enterprises

The involvement of ShinyHunters in high-profile company breaches signals an increased focus on extorting large organizations and the potential for broad impacts if sensitive data is leaked.

Straight Arrow
Fear No Fact.

Don't just take our word for it.


Center-rated reporting

According to media bias experts at AllSides

AllSides Center-rated reporting May 2026

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Media landscape

Click on bars to see headlines

46 total sources

Key points from the Left

No summary available because of a lack of coverage.

Report an issue with this summary

Key points from the Right

No summary available because of a lack of coverage.

Report an issue with this summary

Other (sources without bias rating):

Powered by Ground News™