Skip to content
Some links are advertising or affiliate links. How we make money
THRYV News

Independent reviews, guides and reporting.

Software & CRM

News

Extortion Group Claims It Stole Data From Three More Companies Tied to Salesforce Systems

ShinyHunters says it has records from Questel, Alcon and Lumenis, together more than 47 million rows. None of the three companies has publicly confirmed a breach.

By THRYV Money Desk·Published August 9, 2026·Updated August 9, 2026·5 min read
Extortion Group Claims It Stole Data From Three More Companies Tied to Salesforce Systems
Software & CRM · Illustration commissioned for THRYV. Photography is replaced with original imagery as each story is produced.

The takeaway

The extortion group ShinyHunters claims to have stolen data from three more companies connected to Salesforce environments: intellectual-property firm Questel, eye-care company Alcon and medical device maker Lumenis. The group says the haul totals more than 47 million records and gave the companies until August 4 to respond before threatening to publish the data. None of the three has issued a public statement.

The extortion group ShinyHunters listed three more companies on its leak site this month, claiming to have stolen data from systems connected to each company's Salesforce environment: legal and IP-management firm Questel, eye-care company Alcon, and medical device maker Lumenis.

What's being claimed

  • Questel: more than 21 million Salesforce records containing personal data, plus roughly 147 GB of internal corporate files.
  • Alcon: more than 25 million Salesforce records containing personal data.
  • Lumenis: more than 1.1 million records covering customer and employee data, plus roughly 176 GB of internal files.

The claims surfaced on August 1, 2026. ShinyHunters reportedly gave the three companies until August 4 to respond before threatening to publish the data, a standard pressure tactic for groups running this kind of extortion-only operation, where the leverage is the threat of publication rather than active ransomware encryption.

A claim is not a confirmation

As of publication, none of the three companies had issued a public statement, and appearing on a leak site does not by itself confirm that an intrusion occurred or verify the scope of data actually obtained. Attackers running extortion sites have an incentive to inflate both the fact and scale of a breach.

The bigger pattern

This is the latest in a wave of incidents this year in which attackers gained access to corporate Salesforce environments, in many cases by compromising employees or third-party integrations rather than any flaw in Salesforce's own infrastructure. Salesforce has previously said it found no indication its core platform was compromised in similar earlier incidents.

What we don't know yet

Whether Questel, Alcon or Lumenis will confirm the intrusion, and what specific data, if any, was actually accessed, remains unverified as of this writing. We will update this piece if any of the three companies issues a statement.

Sources

This article is original writing by THRYV. We link to primary reporting and official documents rather than reproducing them.

  1. ShinyHunters Lists Questel, Alcon, and Lumenis on Leak Site With New Extortion ClaimsBreachNews
  2. Top data breaches of August 2026 (so far)SharkStriker

Why you can trust this article

Written and edited in-house by the THRYV Money Desk. We do not republish or reword agency copy, and we do not invent quotes, statistics, testimonials or ratings. Where figures move frequently, we point you to the primary release rather than printing a number that will be out of date. Advertising and affiliate partnerships have no influence on our reporting — see our editorial standards, fact-checking policy and affiliate disclosure. Spotted an error? Write to newsroom@thryv-news.com.

General information only. Not personalised financial, medical or legal advice.

Related reading

The THRYV Brief

The market in 5 minutes, weekday mornings

Plain-English analysis, the sources behind it, and what it changes for you. Free, and you can unsubscribe any time.

Free. Unsubscribe any time. We never sell your email address.

Advertisement · Newsletter sponsorship600×120
Advertise with THRYV News — medium rectangle placement available

This position is available to a single sponsor per edition, is labelled in the email and on this page, and does not influence what the Brief covers.

Advertisement
Advertise with THRYV News — medium rectangle placement available