Extortion
ShinyHunters Claims 284M-Record McKesson Breach After Vishing Two Employees Into Salesforce
ShinyHunters says it vished two McKesson employees into authorizing a rogue connected app, then pulled patient and physician records out of Salesforce and Snowflake — a $55M ransom followed.
ExfilSquad's Power Pages Rampage Hits UK Police Legal Database, 14 Other Victims
A new extortion group, ExfilSquad, is scraping data straight out of misconfigured Microsoft Power Pages portals with no exploit required — its highest-profile victim so far is the UK's Police National Legal Database, exposing contact data for 135,000 officers and justice staff.
Accenture Confirms Breach After Threat Actor '888' Lists 35GB of Source Code and Azure Credentials for Sale
A threat actor known as 888 is selling 35GB of alleged Accenture source code, RSA/SSH keys, and Azure access tokens on a cybercrime forum; Accenture has confirmed an incident but not disclosed the access vector.
Klue OAuth Breach Feeds 'Icarus' Salesforce Data-Theft Spree
A dormant legacy credential at market-intelligence vendor Klue let the new Icarus extortion crew steal customer OAuth tokens and bulk-export Salesforce CRM data from Huntress, Recorded Future, Tanium, Jamf, and more.
Oracle Ships Out-of-Band Fix for PeopleSoft Zero-Day CVE-2026-35273 as ShinyHunters Loots 100+ Orgs
Oracle pushed an emergency alert for CVE-2026-35273, an unauthenticated CVSS 9.8 RCE in PeopleSoft PeopleTools. Mandiant confirms in-the-wild exploitation, and ShinyHunters claims data theft from 100+ organizations including the University of Nottingham.
Grafana Refuses Ransom After CoinbaseCartel Pwn Request Attack Steals Source Code From Five Repos
Grafana Labs disclosed that CoinbaseCartel exploited a GitHub Actions pull_request_target misconfiguration to steal privileged CI tokens and pivot into five private repos. A canary token tripped the breach; the company refused the ransom demand.
ShinyHunters Hits Instructure Again: 3.65TB, 275M Canvas Users, May 6 Ransom Deadline
ShinyHunters claims 3.65TB stolen from Instructure's Canvas platform — 275M users across ~9,000 institutions. Second hit in eight months. Ransom timer expires tomorrow.