Data leak

Cisco Salesforce ShinyHunters Breach

πŸ“… 2025-07-01 🏒 Salesforce
Primary Source β†—

Incident Details

Cisco confirmed in August 2025 that it had been affected by the ShinyHunters Salesforce social engineering campaign. Exposed data included names, addresses, user IDs, email addresses, phone numbers, and account metadata for Cisco customers and partners. This is a separate incident from the April 2026 TeamPCP/Trivy supply chain attack that targeted Cisco’s developer environment. Part of the broader 2025 Salesforce campaign affecting TransUnion (44M+), Air France-KLM, Pandora, Chanel, Stellantis, and Farmers Insurance.

Technical Details

Initial Attack Vector
ShinyHunters compromised Cisco's Salesforce CRM environment through social engineering / vishing of a Salesforce-privileged employee, part of the broader 2025 ShinyHunters Salesforce campaign
Vendor / Product
Salesforce

Timeline

  1. 2025-07-01 Breach occurred
  2. 2025-08-20 Publicly disclosed
  3. 2025-08-20 Customers notified