Salesforce Under Attack: The 600K Record Breach
In April 2026, the hacker group ShinyHunters accessed a 7-Eleven franchisee's Salesforce CRM system, exposing over 600,000 sensitive customer records due to insufficient real-time identity verification and access controls, highlighting a widespread enterprise identity gap that allowed unauthorized access to persist undetected for six weeks.
In April 2026, a threat actor gained access to data held by a 7-Eleven franchisee. Six weeks passed before anyone confirmed the breach. By May 18, more than 600,000 Salesforce records had been exposed.
The actor was ShinyHunters, one of the most active data theft groups operating today. The target was the CRM—the system organizations use to manage their most sensitive customer relationships.
This breach deserves more attention than the headlines have given it, because what happened here is not primarily a story about a software flaw. It is a story about an identity gap that exists in nearly every enterprise.
How the breach unfolded
According to Security Affairs, ShinyHunters gained access to a 7-Eleven franchisee's data on April 8. The breach was not discovered and publicly confirmed until May 18, a gap of approximately six weeks.
During that window, the attacker had access to Salesforce records. The confirmed scope of 600,000+ records reflects how much CRM systems hold: names, contacts, transaction history, relationship data, and in many cases personally identifiable information tied to financial accounts.
The six-week detection window is the number that should concern every security and compliance team. Whatever access controls were in place, they were not sufficient to detect an unauthorized actor in real time. Who was actually in this system was not being answered at the level of granularity the situation required.
The identity gap at the center of every CRM breach
CRM systems are among the most data-rich environments in any enterprise. When access controls depend on a username and password, or even a basic MFA token, the identity assurance behind any given session is thin. ShinyHunters did not need to break encryption. They needed access. And once access was obtained, 600,000 records were within reach.
This is the pattern that strong identity infrastructure is designed to interrupt, at the moment access is first established, before any data changes hands.
Identity proofing that evaluates millions of compliance rules per transaction and meets NIST IAL2 standards creates a different posture entirely. It means that before a session begins, the organization has high assurance about who is on the other side. That assurance is cryptographically recorded and court-admissible. It does not expire. And it cannot be generated by AI.
Why the detection gap matters as much as the breach itself
Six weeks is a long time. In a breach scenario, every day of undetected access is another day of potential exfiltration, reconnaissance, and downstream exposure.
Most enterprise security teams operate on the assumption that perimeter controls will catch unauthorized access quickly. The ShinyHunters breach is a reminder that this assumption fails when the attacker holds valid-appearing credentials.
Stronger identity at the point of access changes the detection dynamic. When the identity behind every session is cryptographically established before access is granted, the attack surface for credential-based intrusion shrinks substantially. A stolen username and password cannot replicate a biometric-bound, verified identity credential.
What compliance and security teams should take from this
Several things stand out for teams responsible for protecting CRM data:
- 1.Breach origin: This breach originated at a franchisee relationship, not at the central organization's perimeter. Identity risk is not contained within your own four walls. It extends to every downstream entity that touches your systems, and the verification standard applied to those sessions is typically weaker than what you apply internally.
- 2.CRM data as a target: The 600,000-record scale confirms that CRM data is a primary target. Attackers pursue systems with the richest data, and CRM systems are consistently near the top of that list.
- 3.Audit trails: The six-week detection window suggests that audit trails were insufficient. A cryptographic audit trail, one that records the verified identity behind every access event, changes the investigation entirely. Instead of reconstructing who might have done this, teams can ask who was verified to do this, and when.
A different identity architecture
Proof issues cryptographic identity credentials anchored in PKI. These credentials are portable, court-admissible, and tamper-evident. When a transaction or access event is tied to a Proof credential, there is no ambiguity about who authorized it.
The Proof Engine evaluates 4.5 million compliance rules per transaction. Proof is NIST IAL2 compliant. And it has secured more than $374 billion in transactions across real estate, financial services, and enterprise use cases.
The ShinyHunters breach is a data point in a pattern that has been building for years. Threat actors target the systems with the richest data, and they enter through identity gaps that perimeter controls were never designed to close.
Every compliance and security leader needs to know two things: whether their identity architecture would detect unauthorized access in hours rather than weeks, and whether their audit trail can reconstruct exactly who accessed what, and when.
If you want to see how Proof approaches CRM identity risk, schedule a conversation with our team.
Related
Introducing Persistent Identity: The Foundation of Repeatable Trust
Persistent Identity is a secure digital ID system that enables individuals to verify their identity once to a high-assurance standard, store it on the Proof platform, and reuse it across multiple online transactions and organizations via the Identity Authorization Network, thereby reducing inefficiency, abandonment rates, and trust erosion caused by repeated identity verifications in an increasingly digital and threat-prone environment.
Proof Release Notes: March 16, 2026 (DEPLOY-1292)
The March 16, 2026 Proof release (DEPLOY-1292) introduces multi-select field capabilities for bulk editing in document preparation, a streamlined "Download All" feature that packages completed documents and audit trails into a single ZIP file, and a new Digital ID enrollment for IAL2-verified signers to enable persistent identity recognition across Proof products, enhancing efficiency and user experience across business, real estate, and Verify transactions.
Capture Selfie Photos for Identity Verification – Proof Help Center
The Proof Help Center explains that Selfie Comparison, an IAL2-compliant biometric verification method, securely verifies a signer's identity by automatically capturing real-time selfies and comparing them to their government-issued ID photos, with guidance on proper lighting, removing accessories, and using a smartphone to ensure clear images, and includes steps like centering the face and looking left and right for enhanced verification, serving as a primary or secondary identity check during the signing process.
What's New in Deepfake Detection, Persistent Identity, and More – March Updates
The March updates introduce real-time deepfake detection during notary meetings to enhance fraud protection, a reusable Digital ID with biometric authentication for faster identity verification across Proof's services, and new organizational management tools aimed at improving efficiency and security for enterprise users handling closings, document preparation, and multi-branch operations.
Proof Title Pro Identity Verification FAQs
Proof verifies signer identities across its Close, Notarize, Identify, and Sign solutions using a combination of Knowledge-Based Authentication (KBA), credential analysis, live notary verification, biometric selfie comparisons against government-issued IDs, and NIST IAL2-compliant methods, with additional live verification by Trusted Referees available when needed.
Identify Transaction Overview
Identify transactions are identity verification tools available to all organizational users that prevent fraud in both in-person and online interactions by using methods like credential analysis, selfie comparison, IAL2-compliant verification, and knowledge-based authentication, providing a Proof identity report to safeguard processes such as property sales, rental applications, and account recovery without requiring notarization or document signing.