ShinyHunters Claims Cisco Breach — 3M Salesforce Records, GitHub Repos and AWS Buckets Allegedly Stolen
Notorious hacking group ShinyHunters claims to have stolen over 3 million Salesforce records, GitHub repositories, and AWS buckets from Cisco. With Cisco deeply embedded across GCC enterprise and government networks, regional security teams should treat this as an active exposure risk.

Illustration of a Cisco network infrastructure diagram with breach indicators and dark web extortion warning overlays
Notorious criminal hacking and extortion group ShinyHunters has posted extortion demands targeting Cisco Systems, claiming to have stolen over 3 million Salesforce records containing personally identifiable information, GitHub repositories, AWS buckets, and other internal corporate data.
The post, published on ShinyHunters' dark web victim page on 31 March 2026, gives Cisco until 3 April to meet its demands or face what the group describes as "several annoying digital problems."
The alleged breach is said to be a combination of three separate incidents: a voice phishing attack tracked as UNC6040, a Salesforce Aura compromise, and unauthorised access to AWS accounts. Screenshots attached to the post reportedly show an AWS EC2 Volumes console with dozens of virtual storage drives — some created as recently as 16 and 17 March 2026 — and an AWS S3 bucket list allegedly belonging to Cisco. No actual data has been released.
Cisco is among the most widely deployed network infrastructure and enterprise technology providers across GCC governments, financial institutions, and telecommunications operators. A confirmed breach of this scale would have direct implications for regional organisations running Cisco-dependent infrastructure, managed services, or shared cloud environments.
Separately, Bleeping Computer has reported that Cisco allegedly suffered a cyberattack stemming from the recent Trivy supply chain compromise — a popular open-source vulnerability scanner whose automation script was reportedly injected with malware by threat actor TeamPCP on 19 March 2026. According to that report, attackers allegedly cloned over 300 GitHub repositories, including source code for an AI-powered assistant and other unreleased AI products. A portion of the stolen repositories is said to belong to corporate customers including banks, business process outsourcing firms, and US government agencies.
Cybernews researchers assessed the ShinyHunters screenshots as plausible, noting that "data from customers would give attackers a foothold to plan further attacks, and the personally identifiable information could be useful for social engineering, fraud, and other scams."
One of the three breaches cited — the voice phishing incident — had previously been disclosed by Cisco. At the time, the company stated that attackers accessed only basic profile information from a third-party CRM instance and did not obtain confidential, proprietary, or sensitive customer data. The current claims, if verified, would represent a significant escalation beyond that earlier incident.
ShinyHunters has built a substantial track record of high-impact data theft and extortion operations since 2019. TeamPCP is a newer, financially motivated threat group that first emerged in late 2025, conducting worm-driven campaigns targeting popular open-source repositories.
GCC enterprise and government security teams running Cisco infrastructure, Salesforce environments, or GitHub-integrated development pipelines should monitor this situation closely and assess their exposure to the Trivy supply chain compromise as a matter of priority.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.