Your prospect list might already be sitting in a hacker's leak site
ShinyHunters published a corpus of business contacts stolen from Fluke Corporation's CRM. What that means for cold email lists that overlap with breach data.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
On July 2, 2026, the extortion group ShinyHunters added Fluke Corporation, the US industrial test-and-measurement equipment maker, to its data-leak site. According to security researchers who reviewed the listing, the group claimed to have pulled more than 21 million Salesforce records and over 100 gigabytes of data out of Fluke’s CRM before ransom negotiations collapsed and the corpus was published.
Read that stat block again and notice what kind of data it is. This isn’t a leak of consumer logins or medical records. It’s business contact information — the exact category of data that ends up in a B2B sales or marketing list. Names, work emails, phone numbers, physical addresses, tied to a support-case history that shows which of those contacts were actively engaged with a vendor. If you sourced any part of a prospect list from a data provider, a scraped directory, or an old export that’s changed hands a few times, there’s a real, non-zero chance some of those exact addresses are now sitting in a corpus like this one too.
Why this is a different problem than “was I breached”
Most breach coverage is written for the company that got hit, or the individual whose password needs changing. This one is worth reading from a third angle: what happens to the people whose contact information ends up published, when someone else — not them, not the breached company — later sends them a cold email.
This is the same broader pattern behind a comparable CRM-adjacent breach earlier this year: business contact data has a long shelf life once it’s out, and it circulates well past the news cycle of the original incident. Fluke’s isn’t an isolated event, either — trade-press coverage of ShinyHunters’ broader 2025-2026 campaign against companies running Salesforce lists dozens of other named targets, spanning nearly every industry. Business contact data is being extracted from CRMs at a steady clip right now, and every batch of it eventually finds its way into the same underground marketplaces that feed spam operations, phishing kits, and, yes, low-quality bulk-email tools that don’t check where a list came from.
This is a campaign, not an incident
Fluke is one name in a much longer list. The same extortion group behind the Fluke listing began a wave of Salesforce-linked breaches in mid-2025 using a voice-phishing technique — calling employees and talking them into connecting a malicious app to their company’s Salesforce portal — and by that October, investigative reporting from Krebs on Security had already tied the campaign to a long roster of household names: Google, Cisco, Adidas, Allianz Life, Farmers Insurance, Workday, several LVMH brands including Dior, Louis Vuitton, and Tiffany & Co., and dozens more spanning retail, travel, and logistics. By early 2026, the same group had shifted technique again, targeting misconfigured Salesforce Experience Cloud portals directly rather than relying on phone-based social engineering to get in.
Two things are worth sitting with in that timeline. First, the technique keeps evolving — voice phishing, then portal misconfiguration, then whatever comes next — while the target keeps being the same kind of system: a CRM holding exactly the business contact records that fuel legitimate outbound sales. Second, and more relevant to anyone building a list: every one of those companies’ customer and prospect contact records is now part of the same pool of already-exposed business data that a purchased or scraped list might overlap with. The pool isn’t shrinking. It’s been growing steadily for well over a year, one CRM at a time.
What this means for how you build a list, not just how you protect one
The Klue breach post on this blog covered the vendor-side lesson: audit your own OAuth-connected tools, scope every integration’s permissions, don’t let a forgotten credential sit active for years. This one is the flip side, aimed at the list itself:
- Where a contact list came from matters more than how big it is. A list built from verified opt-ins, enrichment run at send time, and your own qualified outbound research carries a fundamentally different risk profile than one bought or scraped in bulk, where you have no idea how many addresses have already cycled through breaches like Fluke’s.
- Old exports are a liability, not a free asset. A spreadsheet of contacts pulled two or three years ago and never refreshed is exactly the kind of source most likely to overlap with addresses that have shown up in multiple breach corpora since — list decay compounds with breach exposure, not separately from it.
- Verify before you send, every time, not just once. Email verification at the point of sending catches dead addresses and typos, but it’s also your last checkpoint before a message reaches an inbox you have no visibility into the recent history of. A clean, current, permission-based list is the single best hedge against sending into an address that’s already burned out on unsolicited mail.
None of this means you need to personally audit whether each of your contacts has ever appeared in a breach — that’s not realistic. It means treating list hygiene as an ongoing discipline rather than a one-time import step, because the pool of already-exposed business contacts online only grows, and it grows specifically from incidents like this one.
Where Norbelys builds this in
Norbelys’s audience management is built around the assumption that a list is never “done” — segments stay dynamic, verification runs against your actual audience rather than a stale snapshot, and suppression lists carry forward automatically so an address that’s bounced, complained, or unsubscribed doesn’t quietly resurface in a future campaign because it lived in a different spreadsheet. That’s a meaningfully different starting point than a static CSV import you clean once and forget, and it’s exactly the discipline this kind of breach makes worth taking seriously.
If a chunk of your current list traces back to a purchased or scraped source and you’re not confident in its hygiene, that’s worth fixing before your next send, not after your reply rate tells you something’s wrong. See what verification and list management look like on every Norbelys plan — it’s included at every tier, not an upsell once your deliverability is already suffering. Start building your next campaign on a list you actually trust.
Breach-exposed contact data — quick answers
What happened with the Fluke Corporation breach?
On July 2, 2026, ShinyHunters listed Fluke Corporation on its extortion leak site, claiming to have taken more than 21 million Salesforce records — including over 800,000 unique business email addresses — and published over 100GB of data after ransom negotiations reportedly collapsed.
Is this connected to other 2025-2026 breaches involving Salesforce?
Trade-press reporting places it within a broader campaign by the ShinyHunters extortion group targeting companies running Salesforce, with dozens of other named organizations across multiple industries listed over the same period.
How does a breach like this affect cold email specifically, if my list wasn't stolen?
Breached business contacts circulate in underground marketplaces well past the original incident and often end up on low-quality bulk lists. An address that's been exposed multiple times tends to be more spam-fatigued and more scrutinized by mailbox providers, making legitimate outreach to it measurably harder — regardless of whether the sender's own systems were ever compromised.
What's the practical takeaway for building a prospect list?
Favor verified, recently-sourced contacts over purchased or scraped bulk lists, treat old exports as a liability rather than a free asset, and verify addresses at the point of sending rather than only at import time.