On 1 August 2026, the extortion group ShinyHunters listed Alcon Inc., the Geneva-headquartered eye care company best known for its contact lenses, surgical equipment and vision care products sold in more than 180 countries, on its dark web leak site. The group claims to hold more than 25 million records extracted from Alcon's Salesforce environment, including personally identifiable information tied to patients, customers and staff, alongside a cache of internal corporate files. ShinyHunters set a deadline of 4 August 2026 for Alcon to make contact. That date has come and gone. Alcon has issued no public statement, filed no regulatory disclosure, and confirmed nothing.
The listing follows a pattern that has become numbingly familiar in 2026. Since January, Google's Threat Intelligence Group and Microsoft have separately documented ShinyHunters and the overlapping actor cluster tracked as UNC6671 running an industrialised campaign against Salesforce customers, using vishing calls to talk employees into handing over access rather than exploiting any flaw in Salesforce itself. An attacker calls an employee, often on a personal mobile number with the company's real help desk line spoofed on the display, and claims to be IT support resolving an urgent security issue. The call ends with the employee approving a connected app that looks like a legitimate Salesforce tool, or clicking through a single sign-on prompt on a page built to intercept the credential and the multi-factor code behind it.
Once that approval is granted, the attacker holds a live OAuth token or an authenticated session with the same privileges as the employee who approved it. No password needs to be guessed and no vulnerability needs to be found. The token lets the operator query the Salesforce API directly, and a bulk export of records that would once have taken a database administrator days to justify can be pulled out in an afternoon, indistinguishable in the logs from ordinary business use until the leak site listing appears.
Alcon is not an isolated case. The same fortnight produced leak-site listings for Questel, a Paris-based intellectual property services firm, with 21 million records claimed, and Lumenis, an Israeli medical device maker, with 1.1 million records and 176 gigabytes of internal files. Earlier in the year the identical method was used, according to public reporting, against Medtronic, Fluke Corporation, Charter Communications, Carnival Corporation and Madison Square Garden, among dozens of others. Google has tracked more than $10.6 million in Bitcoin ransom payments to wallets linked to the wider campaign between January and May 2026 alone.
The defences that failed here were not weak by conventional standards. Alcon, like most companies of its size, runs single sign-on, multi-factor authentication and a security operations team monitoring its cloud environment. None of that stops a legitimate, authenticated user from approving a request that looks routine. The control gap sits earlier than detection: the moment an employee grants a new application access to the CRM, or approves an authentication prompt for a caller they believe is internal IT, that action executes immediately and irreversibly, with no independent check on whether the person on the other end of the line is who they claim to be.
A Salesforce connected-app approval or a bulk data export is an execution event. Under GoFirm, before an employee can approve that kind of request, a confirmation goes out of band, direct to the named authority for that system, on their own registered device, requiring a biometric confirmation before the action is allowed to proceed. If no confirmation arrives, the approval is blocked and the export never runs.
A vishing call, however convincing the caller sounds and however accurately they spoof the help desk number, cannot produce a biometric confirmation on the real employee's registered device from a different room, a different country or a script. The execution boundary holds regardless of how credible the impersonation appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. GalaxyWarden. 2026. Alcon Inc. Listed by ShinyHunters Ransomware Group. GalaxyWarden, 2 August 2026.
2. BreachNews. 2026. ShinyHunters Lists Questel, Alcon, and Lumenis on Leak Site With New Extortion Claims. BreachNews, 2 August 2026.
3. Microsoft Security Blog. 2026. Defending SaaS-based applications against ShinyHunters OAuth abuse. Microsoft, 13 July 2026.
4. Lakshmanan, R. 2026. UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data. The Hacker News, 7 August 2026.
Back to Blog
Case Studies·4 min read
ShinyHunters claims 25 million Alcon records. Alcon has said nothing for a week.
By GoFirm
