Last updated 2 weeks ago
In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters 'pay or leak' extortion campaign. The group published hundreds of gigabytes of data claimed to be obtained from the organization's Salesforce instance, including 139,903 unique email addresses along with names, phone numbers, genders, and age groups.
The attack vector involved unauthorized access to Ralph Lauren's Salesforce instance, with ShinyHunters exfiltrating a broad set of personally identifiable information (PII). The threat actor group is known for extortion-driven breaches, though specific exploitation techniques or CVEs were not disclosed in the article.
No further post-incident details such as regulatory involvement, litigation, ransom payment, or containment milestones were reported in the available article.
Extortion campaign targeting Salesforce instance
Ralph Lauren's breach underscores the critical need for robust access controls and monitoring of third-party cloud platforms like Salesforce. The exfiltration of PII from a Salesforce instance suggests inadequate segmentation, insufficient logging, and possibly weak authentication or misconfiguration. Organizations in the retail sector handling large volumes of customer data should enforce least-privilege access, implement multi-factor authentication, and conduct regular security audits of cloud-based CRM systems to prevent similar unauthorized access and data leaks.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor