ShinyHunters says it has records from Questel, Alcon and Lumenis, together more than 47 million rows. None of the three companies has publicly confirmed a breach.
The extortion group ShinyHunters listed three more companies on its leak site this month, claiming to have stolen data from systems connected to each company's Salesforce environment: legal and IP-management firm Questel, eye-care company Alcon, and medical device maker Lumenis.
What's being claimed
- Questel: more than 21 million Salesforce records containing personal data, plus roughly 147 GB of internal corporate files.
- Alcon: more than 25 million Salesforce records containing personal data.
- Lumenis: more than 1.1 million records covering customer and employee data, plus roughly 176 GB of internal files.
The claims surfaced on August 1, 2026. ShinyHunters reportedly gave the three companies until August 4 to respond before threatening to publish the data, a standard pressure tactic for groups running this kind of extortion-only operation, where the leverage is the threat of publication rather than active ransomware encryption.
A claim is not a confirmation
As of publication, none of the three companies had issued a public statement, and appearing on a leak site does not by itself confirm that an intrusion occurred or verify the scope of data actually obtained. Attackers running extortion sites have an incentive to inflate both the fact and scale of a breach.
The bigger pattern
This is the latest in a wave of incidents this year in which attackers gained access to corporate Salesforce environments, in many cases by compromising employees or third-party integrations rather than any flaw in Salesforce's own infrastructure. Salesforce has previously said it found no indication its core platform was compromised in similar earlier incidents.
What we don't know yet
Whether Questel, Alcon or Lumenis will confirm the intrusion, and what specific data, if any, was actually accessed, remains unverified as of this writing. We will update this piece if any of the three companies issues a statement.
Why you can trust this article
Written and edited in-house by the THRYV Money Desk. We do not republish or reword agency copy, and we do not invent quotes, statistics, testimonials or ratings. Where figures move frequently, we point you to the primary release rather than printing a number that will be out of date. Advertising and affiliate partnerships have no influence on our reporting — see our editorial standards, fact-checking policy and affiliate disclosure. Spotted an error? Write to newsroom@thryv-news.com.
General information only. Not personalised financial, medical or legal advice.