Last updated 1 month ago
In April 2026, Abrigo, a fintech software company, suffered a data breach impacting 711,099 unique email addresses. The incident involved a 'pay or leak' extortion attempt by the ShinyHunters group, who subsequently published data allegedly stolen from Abrigo's Salesforce instance. The exposed records include business contact information such as institution names, employee names, email addresses, and phone numbers, affecting both Abrigo staff and external contacts.
The attack vector was unauthorized access to Abrigo's Salesforce environment, though the specific initial access method is not detailed. The data fields are consistent with a prior incident involving Abrigo's Salesforce compromise via the Drift application connector, suggesting a possible supply chain or misconfiguration vector. ShinyHunters, a known threat actor group, claimed responsibility and published the data after the extortion demand was not met.
No further post-incident details are available in the article regarding regulatory actions, litigation, ransom payment, or remediation milestones.
Data exfiltrated from Salesforce instance and published after extortion attempt
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor