Back to blog

Blog Post

Google Confirms Data Breach Linked to ShinyHunters

Share on social

Aug 15, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Google Confirms Data Breach Linked to ShinyHunters

[Google ShinyHunters Breach]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

Google has confirmed that information from some of its customers was stolen following a breach of one of its databases, in an attack linked to the hacking group ShinyHunters.

In a blog post published on August 4th, Google's Threat Intelligence Group revealed that one of its Salesforce database systems, used to store contact information and related notes for small and medium-sized businesses, was accessed without authorization.

"The data retrieved by the threat actor was confined to basic and largely publicly available business information, such as business names and contact details," the company said. Google did not disclose how many customers were affected and it is not yet known whether the company has received any ransom demands. Google also warned that ShinyHunters may be preparing to launch a data leak site to pressure victims into paying to prevent the public release of stolen data.

ShinyHunters, formally designated as UNC6040, is well known for targeting large corporations and their cloud-based databases. The group has been linked to a number of recent attack on Salesforce systems, including Cisco, Qantas, and Pandora.

Google said the attackers used voice phishing where threat actors posed as trusted contacts over the phone to trick employees into granting access to cloud-based Salesforce databases.

In an update on August 8th in the same blog post, Google said emails are being sent to those affected by the incident, later confirming they have completed sending the email notifications.

Lizzie Clark

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

August 27, 2026

Beacon: North Korean Hackers Linked to Rust Supply Chain Attack

August 20, 2026

Beacon: Cl0p Claims Data Theft from More than 40 Companies

August 19, 2026

wp2shell: Discovering One of 2026’s Biggest Zero-Days, and the Future of Exposure Management

August 14, 2026

Beacon: OpenAI's Astra Paused Due to Hacking Use Concerns

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient