It's a pattern — and it's hitting manufacturing, food and beverage, healthcare, and financial services organizations right now.
Sysco — the $81 billion food distributor supplying hospitals, schools, and restaurants across 90 countries — was hit by the Qilin ransomware gang. Before they could fully respond, a second threat actor, ShinyHunters, claimed to have stolen 61 million Salesforce records from the same company. Two separate extortion campaigns. One target. Weeks apart.
This isn't a Sysco problem. It's a pattern — and it's hitting manufacturing, food and beverage, healthcare, and financial services organizations right now.
Qilin alone claimed 18 manufacturing and energy victims in a single 24-hour window this week. ShinyHunters has been running a sustained campaign exploiting misconfigured Salesforce instances across hundreds of organizations. These groups don't discriminate by size. They automate, scan for exposure, and move fast.
The question isn't whether you have security tools. It's whether they'd actually catch this.
Ask your team these four questions before your next board meeting:
1. If Qilin or ShinyHunters used their current attack techniques against your network today — would your detection rules fire?
2. Do you have visibility into your Salesforce environment for anomalous access or data exfiltration?
3. If you were breached right now, how long would it take you to know?
4. Are you monitoring for lateral movement between IT and OT, or only at the perimeter?
If any of those answers are uncertain, that uncertainty is the vulnerability.
Find out where your vulnerabilities are — before attackers do.
Schedule a 30-minute intro call so we can go over your current posture. No pitch. No obligation. Just findings.
Subscribe to our newsletter to keep you updated on the latest cybersecurity insights & resources.
One follow-up from a security expert—no spam, ever.
Enter your details below to download the PDF.