Last updated 1 month ago
Baker Distributing Company, a U.S.-based HVAC/R wholesale distributor, suffered a data breach involving 102,935 unique email addresses. The breach was publicly disclosed in early June 2026 after the ShinyHunters extortion group published the data on their 'pay or leak' site. The exposed data includes names, physical addresses, phone numbers, and tickets related to the company's HVAC contractor customer base.
The attack vector involved unauthorized access to Baker's SharePoint and Salesforce infrastructure, with the threat actor ShinyHunters claiming responsibility. The exfiltrated data primarily consists of corporate contact and support information, with limited sensitivity. No specific CVEs or MITRE ATT&CK techniques were mentioned in the available information.
No post-incident developments such as regulatory actions, litigation, ransom payments, or containment milestones were reported in the article.
Data exfiltrated from SharePoint and Salesforce infrastructure by ShinyHunters extortion group
Baker Distributing's breach highlights the risk of exposing corporate contact and support data through cloud infrastructure like SharePoint and Salesforce. The company's failure to secure these platforms against unauthorized access by an extortion group suggests inadequate access controls and monitoring. Implementing robust identity and access management (IAM) and continuous monitoring for anomalous access patterns could have mitigated this incident.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor