Last updated 1 month ago
In March 2026, Berkadia, a commercial real estate finance company, was targeted by the ShinyHunters threat group in a 'pay or leak' extortion campaign. The group published over 300,000 unique email addresses along with names, physical addresses, and phone numbers, allegedly exfiltrated from Berkadia's Salesforce instance. The breach was publicly disclosed via Have I Been Pwned, with the data appearing in March 2026.
The attack vector involved unauthorized access to Berkadia's Salesforce environment, though the specific initial access method (e.g., credential compromise, misconfiguration) is not detailed. ShinyHunters, known for extortion-driven data theft, exfiltrated structured customer and business contact data including email addresses, names, physical addresses, and phone numbers. No technical exploitation details or CVEs are associated with this incident.
No post-incident developments such as regulatory actions, litigation, ransom payment, or remediation milestones are reported in the available information.
Extortion campaign by ShinyHunters, data allegedly taken from Salesforce instance
Berkadia's breach underscores the critical need for robust access controls and monitoring of cloud-based CRM platforms like Salesforce. The exfiltration of over 300,000 records suggests inadequate data loss prevention (DLP) and insufficient segmentation of sensitive customer data within the Salesforce instance. Organizations in the finance sector should enforce multi-factor authentication, strict API access policies, and regular audits of third-party integrations to mitigate similar extortion-driven attacks.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor