After a year of dormancy, the notorious ShinyHunters cybercriminal group has resurged with sophisticated attacks targeting Salesforce platforms across major organizations, including Google.
ReliaQuest’s investigation reveals compelling evidence of potential collaboration with the Scattered Spider collective, marked by shared tactics, synchronized campaigns, and overlapping infrastructure that could reshape the threat landscape for enterprises worldwide.
Tactical Evolution Points to Criminal Partnership
ShinyHunters has dramatically shifted from its traditional credential theft and database exploitation methods to adopt Scattered Spider’s signature social engineering techniques.

The group now employs highly targeted vishing campaigns where attackers impersonate IT support staff to manipulate employees into authorizing malicious “connected apps” disguised as legitimate Salesforce tools.
These attacks leverage Okta-themed phishing pages during vishing calls and utilize VPN obfuscation through Mullvad VPN for data exfiltration from victims’ Salesforce instances.
This tactical evolution represents a significant departure from ShinyHunters’ previous modus operandi and aligns closely with The Com collective’s established methods.
Supporting evidence emerged from a BreachForums user with the alias “Sp1d3rhunters,” a portmanteau of both group names, who claimed the organizations “are the same” and “have always been the same.”
This account, created in May 2024, later leaked Ticketmaster breach data previously advertised by ShinyHunters, suggesting collaboration dating back to July 2024.
Infrastructure Analysis Reveals Targeting Patterns
ReliaQuest’s domain investigation uncovered a coordinated cluster of ticket-themed phishing domains registered between June 20-30, 2025, including ticket-lvmh[.]com, ticket-dior[.]com, and ticket-louisvuitton[.]com.
These domains shared critical registry characteristics: registration through GMO Internet, temporary email addresses via mailshan[.]com, and Cloudflare-masked nameservers.
All domains hosted Okta-branded phishing pages promoting access to a “Ticket Dashboard,” matching recent reports of attackers rebranding malicious Salesforce Data Loader applications as “My Ticket Portal” during social engineering campaigns.
Additional impersonating domains like ticket-nike[.]com and dashboard-salesforce[.]com were registered using identical infrastructure, indicating an extensive, ongoing operation.
Financial Sector Emerges as Primary Target
Domain registration analysis of over 700 suspicious domains reveals a strategic shift toward financial institutions.
Since July 2025, domain registrations targeting financial companies increased 12%, while registrations targeting technology firms decreased 5%.
This trend suggests ShinyHunters and affiliated groups are prioritizing banks, insurance companies, and financial services for their high-value data and payment capabilities.

The coordinated nature of these campaigns, combined with the technical sophistication of their social engineering tactics, positions this potential alliance as a significant threat to enterprise security.
Organizations should prioritize defense against vishing, credential harvesting, and domain impersonation tactics while monitoring for suspicious Salesforce connected app authorizations and anomalous data access patterns.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates