On 1 July 2026, the extortion group ShinyHunters listed Fluke Corporation, the Everett, Washington-based manufacturer of electronic testing and measurement equipment owned by Fortive Corporation, on its dark web leak site. The listing followed what the group described as an extended, failed ransom negotiation. According to ShinyHunters, the intrusion began with a vishing call: an operator phoned an employee, posing as internal IT support, and walked them through what looked like a routine single sign-on re-authentication.
The method matches a pattern ShinyHunters has run against more than a hundred organisations in 2026. An operator, using VoIP infrastructure and in some cases AI-assisted conversational scripts, calls an employee and directs them to a phishing page branded to look like the company's own Okta login. As the employee enters credentials and a multi-factor code on the call, the attacker relays each value in real time, capturing the session before the employee has hung up. Once inside, the attacker enrols its own device as a trusted MFA method, giving it standing access that survives the original phone call by hours or weeks.
At Fluke, that captured Okta session reportedly opened a direct line into the company's Salesforce instance, the customer relationship management platform used to track sales, service, and support records across Fluke's global industrial, electrical, and healthcare customer base. ShinyHunters claims to have exported more than 100GB of data from that environment, including in excess of 21 million records containing personally identifiable information. No ransomware was deployed. No file was encrypted. The entire operation, by the group's own account, consisted of one phone call and one export.
Neither Fluke nor Fortive has confirmed the breach, disputed ShinyHunters' figures, or issued a public statement at the time of writing. That silence leaves the scale of the claimed loss unverified, but it does not change the shape of the risk: 21 million records of customer and business data, sitting on a criminal leak site, with the threat of publication now that negotiations have reportedly collapsed. For a company whose customer base spans industrial, electrical, and healthcare engineering firms worldwide, the downstream exposure, from targeted phishing against Fluke's own customers to competitive intelligence in the hands of a data broker, extends well beyond Fluke's own walls.
The defences that failed here were not weak by conventional standards. Salesforce access was gated behind Okta single sign-on and multi-factor authentication, the combination most enterprises treat as sufficient. Both worked exactly as designed. The employee authenticated correctly, the MFA code was valid, and the session that followed was, from the system's perspective, entirely legitimate. The control that was missing sat one step further downstream: nothing checked, at the moment a bulk export of 21 million records began, whether the named authority over that Salesforce environment had actually approved it.
A Salesforce export of that scale is an execution event. Before an employee, or an attacker holding that employee's session, can pull tens of millions of records out of a CRM environment, GoFirm sends a real-time push notification to the named data owner's registered device, requiring a biometric confirmation before the export is allowed to proceed. The confirmation happens out of band, on a separate channel from the one the attacker controls. A vishing call can capture a password. It can capture a one-time code read aloud over the phone. It cannot capture a fingerprint or face scan on a device it does not hold.
That is the boundary ShinyHunters' method cannot cross. The group can clone a login page, relay a code in real time, and even enrol a rogue MFA device, all without the named authority ever knowing a call took place. What it cannot do is produce a biometric confirmation on that authority's own phone, at the moment the export executes, over a channel the attacker never touched. A vishing call, however convincing, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References:
1. BreachNews, "ShinyHunters Adds Ingram Content Group, Fluke to Leak Site," 1 July 2026
2. RedPacket Security, "[SHINYHUNTERS] - Ransomware Victim: Fluke Corporation," July 2026
3. Rescana, "ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack," 2026
4. RH-ISAC, "Okta Warns Users of Custom Vishing Kits Potentially Affiliated with ShinyHunters," 2026
