DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
HIGH#dark web

ShinyHunters Confirms 600K-Record Salesforce Exfiltration from 7-Eleven; 9.4GB Archive Leaked After Ransom Refusal — Part of Ongoing SaaS CRM Campaign Hitting Dozens of Enterprises

7-Eleven confirmed a breach first flagged by ShinyHunters on April 17, with attackers exfiltrating 600,000+ Salesforce CRM records containing franchise applicant PII — including names, SSNs, driver's licenses, and addresses — after gaining access on April 8 via phishing, OAuth abuse, or misconfiguration (not a Salesforce platform flaw). After 7-Eleven declined ransom payment, ShinyHunters published a 9.4GB archive on their Tor leak site; the FBI has issued guidance urging all ShinyHunters victims not to pay. This breach is part of a sustained high-tempo campaign by ShinyHunters/Coinbase Cartel targeting Salesforce environments at scale — confirmed victims also include Instructure (275M records, 9,000 schools), McGraw-Hill, Medtronic, Vimeo, and the European Commission. Organizations relying on cloud-hosted SaaS CRM platforms must audit OAuth grants, third-party integration scopes, and Salesforce Connected App permissions immediately.

After 7-Eleven declined ransom payment, ShinyHunters published a 9.4GB archive on their Tor leak site; the FBI has issued guidance urging all ShinyHunters victims not to pay.

This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.

For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.

STAY AHEAD OF THREATS
Daily intel briefs and IOC packages — delivered to your inbox the moment a new advisory drops.
SUBSCRIBE — $29/MO →
SHARE BRIEF:✕ Post on Xin Share on LinkedIn