A sophisticated cyberattack has put the security of approximately 2.5 billion Gmail and Google Cloud users worldwide at risk. The breach, detected in June 2025, targeted a Salesforce system used by Google, allowing the notorious hacking group ShinyHunters, also known as UNC6040, to access contact information of small and medium-sized businesses. Revealed by Google in August, the incident did not compromise passwords or financial data, but the stolen information is being weaponized for phishing and extortion campaigns. The company issued an emergency alert, urging users to bolster their security measures. The attack, relying on social engineering tactics like fraudulent phone calls, underscores human vulnerabilities in digital systems. The threat persists, with indications that hackers may launch a data leak site to expose stolen information.
Google acted swiftly to contain the breach, blocking hackers’ access within hours. However, ShinyHunters has already demonstrated its ability to exploit stolen data in extortion schemes. The company notified all affected users via email on August 8, emphasizing the need for preventive measures.
The incident highlights the growing sophistication of cyberattacks that exploit human error rather than technical flaws. Below, we detail how the attack unfolded, who is behind it, recommended protective actions, and the broader implications for businesses and users.
ShinyHunters employed social engineering, primarily vishing, to deceive employees. Posing as IT support staff, the hackers tricked victims into sharing credentials or installing fake apps, such as a modified Salesforce Data Loader. These tactics granted access to data stored on the Salesforce platform used by Google.
The campaign began in March 2025 but intensified in June, when Google identified around 20 U.S. and European companies as targets. The group, known for its persistence, has also attacked firms like Cisco, Adidas, and Pandora, exploiting human vulnerabilities in corporate systems.
The use of VPNs like Mullvad and TOR networks made tracking the hackers challenging. They also employed custom Python scripts to automate data extraction, reflecting an evolution in their tactics, blending manual and automated methods for maximum impact.
Formed in 2020, ShinyHunters gained infamy for targeting major corporations like AT&T, Microsoft, Ticketmaster, and Santander. Named after the Pokémon franchise, the group focuses on stealing valuable data. They are notorious for extracting large volumes of user records and selling them on dark web forums or using them for extortion.
Google identifies the group as UNC6040 for initial intrusions and UNC6240 for extortion operations. Evidence suggests collaboration with Scattered Spider, a group known for advanced social engineering. This partnership enhances attack sophistication, using tactics like fake domains and fraudulent login pages.
The group’s decentralized structure complicates law enforcement efforts. Despite arrests linked to BreachForums, a platform for selling stolen data, ShinyHunters remains active, indicating an “extortion-as-a-service” model.
Google warned that hackers may be preparing a data leak site (DLS) to expose stolen information, a tactic used to pressure victims into paying ransoms. This approach was seen in prior attacks, like Ticketmaster’s, where 1.3 terabytes of data were offered on the dark web.
While the stolen data is described as “basic and largely public,” such as company names and contacts, its use in phishing and smishing campaigns poses significant risks. Users report scam calls with hackers posing as Google staff to steal passwords or authentication codes.
Companies like Pandora and Allianz Life reported similar incidents, suggesting a broad and ongoing campaign. Google clarified that Salesforce itself wasn’t directly breached, but its clients were targeted through social engineering.
Google recommends immediate steps to secure Gmail and other services. Enabling two-factor authentication (2FA), ideally via apps like Google Authenticator, is a top priority. Company data shows only a third of users regularly update passwords, increasing vulnerability.
Users should be wary of unsolicited calls or messages, even from seemingly legitimate numbers, due to spoofing techniques. Checking for suspicious account activity and using unique, complex passwords are also advised.
The ShinyHunters campaign extends beyond Google, with companies like Qantas, Louis Vuitton, and Dior reporting Salesforce-related breaches. Collaboration with Scattered Spider adds complexity, with fake domains mimicking corporate login pages.
Previous attacks, like the theft of 91 million Tokopedia accounts and 70 million AT&T records, demonstrate the group’s capacity for large-scale damage. The lack of technical vulnerabilities in Salesforce underscores the need for employee training against social engineering.
Google continues to monitor the situation and collaborate with authorities, but ShinyHunters’ persistence suggests more victims may emerge. Extortion campaigns, including Bitcoin payment demands, remain active, with some companies receiving threats months after initial breaches.
最近数週間、ドナルド・トランプ米大統領の予定されたイベントのキャンセルをきっかけに、彼の死亡に関する噂がソーシャルメディアで急速に広まった。デジタルプラットフォーム上の匿名投稿から始まったこの憶測は、信頼できる情報源による裏付けがなく、米政府の信頼できる機関からも公式なコメントは出されていない。ホワイトハウスや他の政府機関からの信頼できる情報源がこの主張について言及していない中、政治的な分極とオンライン上の誤情報がこの噂を増幅させた。会議や公開イベントのキャンセルが、この根拠のない理論の主な引き金となった。この記事では、噂の起源、ソーシャルメディアでの拡散、そして現在の誤情報との戦いの課題を探る。 噂は、Xなどのプラットフォームで、トランプが深刻な健康問題に直面していると根拠なく示唆するセンセーショナルなメッセージから始まった。米政府からの公式声明がないことで、これらの物語は特に米国政治を注視するグループの間で勢いを増した。大統領の予定のキャンセル理由に関する透明性の欠如が、さらに憶測を煽った。 噂の主なポイント: ソーシャルメディアの匿名投稿から発生。 トランプのイベントキャンセルが憶測を呼んだ。 米政府の信頼できる情報源は主張を確認していない。 この情報の拡散は、バイラルコンテンツが検証済みの事実をしばしば上回るデジタル環境での誤情報との戦いの難しさを反映している。 噂の起源と増幅 トランプの死亡に関する噂は、2025年8月末に予定されていたワシントンでのCEOとの会議や政治イベントへの出演キャンセル後に勢いを増した。これらの延期の理由に関する詳細の欠如が情報真空を生み、憶測で急速に埋められた。ソーシャルメディアの投稿では、内部情報源を引用したが、書類や具体的な証拠は提示されなかった。 トランプの高い注目度でのイベント欠席と、米国政治の中心人物としての役割が、噂を共有しやすくした。米国での政治的分極、特にトランプの最近の通商関税導入などの決定が、彼の公的イメージを不安定にすることを狙った物語の拡散に寄与した。 Ver essa foto no Instagram…
A wave of rumors about the alleged death of U.S. President Donald Trump has swept…
Uma onda de rumores sobre a suposta morte do presidente dos Estados Unidos, Donald Trump,…
O apresentador e chef Edu Guedes, de 51 anos, abriu o coração sobre sua recente…
A BYD lançou em 2025 o sedã híbrido King 2026 com benefícios exclusivos para Pessoas…
A PlayStation Store lançou a promoção “Preparar, Apontar, Jogar”, trazendo descontos de até 90% em…