ShinyHunters hit Cisco through a Trivy supply chain attack and want answers by April 3
ShinyHunters posted a “FINAL WARNING” on their leak site on March 31. The target: Cisco Systems. The demand: contact us before April 3 or we publish everything.
What they claim to have stolen is staggering. Over 3 million Salesforce records containing personal data. More than 300 cloned private GitHub repositories, including source code for unreleased products like Cisco AI Assistant and AI Defense. Multiple AWS access keys. Internal CRM databases with names, emails, phone numbers, and account metadata for customers across sectors.
The breach vectors add up to three distinct entry points: Salesforce CRM, Salesforce Aura (Experience Cloud), and AWS environments. According to threat intelligence from Resecurity, the stolen Salesforce records reference both Cisco customers and employees. More worrying, the dataset includes records tied to personnel from the FBI, DHS, DISA, IRS, and NASA, alongside the Australian Ministry of Defense and multiple Indian government agencies. The common thread is procurement or configuration of Cisco products, but the intelligence value for targeted phishing and social engineering attacks is obvious.
The initial intrusion did not come from a direct assault on Cisco. Security researchers traced it back to a supply chain compromise targeting Trivy, the widely used open-source vulnerability scanner maintained by Aqua Security. Attackers deployed a malicious GitHub Action plugin linked to the Trivy compromise. That plugin silently harvested developer credentials from CI/CD pipelines. With those credentials in hand, the attackers bypassed Cisco authentication controls and gained access to internal build environments, compromising lab workstations and developer machines across dozens of devices.
While ShinyHunters is publicly claiming credit, security researchers have attributed the underlying Trivy supply chain attack to TeamPCP, a separate threat group known for deploying custom malware called “TeamPCP Cloud Stealer” to hijack developer platforms. ShinyHunters then appears to have used the access created by TeamPCP to exfiltrate and now extort Cisco.
Cisco internal security units responded rapidly. The Unified Intelligence Center, CSIRT, and EOC isolated compromised systems, began wiping and reinstalling affected machines, and enforced a mass employee credential reset. Despite these containment steps, Cisco has not released any public statement on the breach. When contacted by press, the company declined to comment.
ShinyHunters has been active since 2019 and operates under tracked aliases including UNC6040 and UNC6395. The group has claimed to have breached between 300 and 400 organizations by exploiting misconfigured Salesforce Experience Cloud guest user access controls, using an open-source tool called AuraInspector to automate scanning. Their typical playbook involves vishing (voice phishing) campaigns that trick customer support employees into authorizing malicious Salesforce-connected apps through OAuth tokens.
April 3 is tomorrow. If Cisco does not engage, ShinyHunters will likely start publishing the stolen data on their leak site. Given the scope - government agency contacts, unreleased AI product source code, cloud infrastructure keys - the downstream damage could extend far beyond Cisco itself.