On August 7, 2026 at 3:00 PM ET, the threat actor shinyhunters claimed it compromised Ali** ********** and exposed 11.5 million records across Salesforce, ServiceNow, and Entra, including customer and employee PII and 3.1TB+ of internal corporate data. The attacker issued a final payment/leak warning requesting contact by 10 August 2026, with the impacted country(s) listed as # .
Incident Details
- Victim: Ali** **********
- Sector: Technology
- Country:
- Actor: shinyhunters
- Source: https://shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onion/#AlienTechnology
- Discovered: 2026-08-09T09:29:48.912411+00:00
- Published: 2026-08-08T00:00:00+00:00
Information
- Over 11.5 million records across Salesforce, ServiceNow, and Entra were compromised, including some customer and employee PII.
- More than 3.1TB of internal corporate data was also accessed.
- This is a final warning to make contact by 10 August 2026 to prevent the leak.
- If no response is received, the stolen data will be published along with additional disruptive digital consequences.
- Updated: 08 August 2026.
- Warning: final warning, pay or leak.

Disclaimer: This post is based on public claims made by the ransomware group "shinyhunters". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.