Salesforce is warning its customers about new cyberattacks targeting websites built on its Experience Cloud. According to the company, hackers are exploiting incorrect security settings that allow anonymous visitors to gain access to more data than they should. The issue mainly concerns cases where visitor user profiles have excessive permissions, creating a loophole that could lead to the leakage of sensitive information.

The warning focuses on attacks targeting the /s/sfsites/aura API, which is used by Experience Cloud to communicate with Salesforce backend services. In cases of misconfiguration, this access point could allow direct queries to Salesforce CRM objects without requiring a user login.
Salesforce's position on the security issue
Salesforce notes that the problem is not due to an inherent vulnerability in the platform. As emphasized in a related update to customers, the attacks are related to settings that have been set by the organizations themselves.
See also: Hacker claims to have leaked NordVPN's Salesforce data
Specifically, Experience Cloud public websites use a Guest User Profile, which allows anonymous visitors to access content that is designed to be public. However, if this profile has excessive access rights, a malicious user can query CRM data without any authentication process.
The company emphasizes that proper implementation of the principle of least privilege is a key protection measure. In other words, visitors should only have the access permissions that are absolutely necessary and nothing more.
Practical protection measures for organizations
According to Salesforce, the most important change organizations can implement immediately is to disable guest access to public APIs . It is also recommended to remove the API Enabled setting from guest profiles to drastically reduce the risk of exploitation.
Additionally, the company recommends a number of security actions that should be implemented immediately. First, administrators should carefully review guest user permissions and limit them to a minimum. Second, default external access settings should be set to private mode at the organization level.

It's also important to disable Portal User Visibility and Site User Visibilityso that visitors can't identify or register internal users within an organization. Salesforce also recommends disabling user self-registrationunless absolutely necessary, as exposed visitor data could be used to create accounts and further infiltrate corporate systems.
See also: Mandiant: How ShinyHunters abuses SSO to steal cloud data
The role of the AuraInspector tool in attacks
An interesting aspect of the case is the use of a modified version of the AuraInspector. This tool was originally developed as an open source solution for detecting incorrect security settings in the Salesforce Aura.
However, Mandiant confirmed that attackers are now leveraging modified versions of the tool to automate vulnerability scanning on publicly accessible Experience Cloud websites . Charles Carmakal, the company's CTO, said that security teams are working closely with Salesforce to create detection rules that will allow organizations to spot suspicious activity.
It is also clarified that the presence of scans in an organization's logs does not necessarily mean that a successful breach has occurred.
The ShinyHunters gang and the claims of massive breaches
The well-known cybercriminal group ShinyHunters , which has been linked to large-scale data breaches for years, has claimed responsibility for some of the attacks . They claim to have breached around 100 major companies , with the total number of organizations affected possibly reaching between 300 and 400.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The attackers claim to have begun their attacks in September 2025, locating public Aura installations by scanning the internet for endpoints like /s/sfsites/. They were able to retrieve data via GraphQL API , although there was a limit of 2,000 records per request.
See also: Drift hacks: 1.5 billion Salesforce files in the hands of ShinyHunters

The hackers claim to have managed to temporarily bypass this limit via the sortBy, speeding up the data extraction process. Later, when this method was fixed, they report that they discovered new techniques to bypass the restrictions.
The next day for cloud security
While some of the attackers' claims have not been independently verified, the incident highlights a broader reality: misconfigurations often pose a greater threat than the technical vulnerabilities themselves.
In the world of cloud platforms, where services are highly flexible and customizable, even a small configuration oversight can open the door to serious breaches. For businesses relying on solutions like Experience Cloud, constant monitoring of security settings and regular analysis of log files have become a necessary practice.
Source: www.bleepingcomputer.com
