FBI Warns of Follow-On Extortion After ShinyHunters Campaign
An FBI alert confirmed that containing an incident does not mean it is over, as extortion groups continue targeting victims after initial breaches.
Public Service Announcement
On May 15, 2026, the FBI issued a public service announcement warning of follow-on extortion attempts tied to a group that had targeted multiple organizations in the preceding weeks. The announcement did not name specific victims but security analysts linked the activity to ShinyHunters, an extortion group tied to breaches at 7-Eleven, Medtronic, and other organizations throughout 2026.
The pattern involved voice phishing calls to persuade employees to share credentials for cloud accounts, followed by exfiltration of customer data from Salesforce environments. The FBI alert emphasized that organizations' belief that an incident is contained does not necessarily mean the threat has ended.
Broader Campaign Context
The same actors were confirmed in breaches affecting Carnival, Canvas, CarGurus, Panera Bread, and 7-Eleven as part of a Salesforce-focused campaign. Charter Communications, one of the largest broadband providers in the United States, was compromised on April 1, 2026, when the group used voice phishing to reach its Salesforce environment.
ShinyHunters claimed more than 42 million records from Charter, while independent analysis confirmed approximately 4.9 million unique email addresses and 85,000 employee directory records. The May FBI warning came as multiple organizations that believed they had contained breaches discovered continued attacker activity.
Defense Recommendations
Security analysts noted that paying ransom does not guarantee data protection. The defaced Canvas login portals at roughly 330 institutions, including Harvard and Princeton, occurred one day after Instructure said it had contained the issue by May 6.
Analysts recommended persistent encryption on records and message stores, scoped access controls, and discovery processes that surface unverified account programs before attackers find them. The campaign demonstrated that credential-based access through social engineering now rivals technical exploits as a primary intrusion method.