The Salesforce Aura Campaign, an ongoing data theft operation claimed by the ShinyHunters threat actor group, was discovered on March 9, 2026. This incident involves the exploitation of misconfigured Salesforce Experience Cloud guest user permissions, allowing unauthorized access to sensitive data. Salesforce has stated that the issue is not a platform vulnerability but relates to customer-configured guest user settings.
ShinyHunters claims to have compromised between 300-400 organizations, with approximately 100 identified as high-profile. Specific named victims include Salesforce itself, Snowflake, Okta, LastPass, Sony, and AMD. The exposed data includes names, phone numbers, CRM records, and other Salesforce CRM objects accessible through misconfigured guest user profiles. These data types are typically used for targeted social engineering campaigns.
While the number of affected organizations is estimated, the total number of affected individuals remains unclear across all breaches. Salesforce has advised customers to audit guest user permissions and implement least-privilege access controls. Details regarding specific states affected, official breach notification letters, or class-action lawsuits have not been publicly confirmed.