Salesforce confirms ShinyHunters exploited Experience Cloud sites
- Joseph K

- Mar 10
- 1 min read
Salesforce confirmed March 10 that an ongoing campaign exploiting organizations running publicly accessible or misconfigured Salesforce Experience Cloud sites was done by the ShinyHunters cybercrime group.
In its original March 7 post on the case, Salesforce did not identify the actor — they were also adamant that this incident was not because of an exploited vulnerability on its platform, but a misconfiguration.
Comments