Salesforce Communities Security Risks

Explore top LinkedIn content from expert professionals.

Summary

Salesforce Communities, also known as Experience Cloud, allow organizations to create online portals for customers and partners, but misconfigured guest user settings can expose sensitive data to unauthorized access. Recent breaches have highlighted that security risks often stem from improperly set permissions, not from flaws in the Salesforce platform itself.

  • Review guest access: Regularly check what unauthenticated visitors can view or do in your community sites to prevent accidental exposure of sensitive information.
  • Disable unnecessary API: Turn off API access in the guest user profile unless it is absolutely required, as this closes a common door for attackers.
  • Audit forgotten sites: Routinely inspect old or unused portals and connected apps to ensure they don't have outdated or risky configurations.
Summarized by AI based on LinkedIn member posts
  • View profile for Jordan Nelson
    Jordan Nelson Jordan Nelson is an Influencer

    CEO @ Simply Scale • Salesforce Consulting for Tech Companies

    103,696 followers

    400 Salesforce orgs got breached over the last month. All from a setting someone forgot to check. ShinyHunters ran a mass scan of Experience Cloud sites and found 300 to 400 orgs with the same misconfiguration. FINRA issued a cybersecurity alert about it this week. Here's the part every RevOps leader needs to hear: 👉 This is NOT a Salesforce platform vulnerability. It's a guest user config mistake. Any org could have it right now. Yours included. WHAT ACTUALLY HAPPENED? Salesforce Experience Cloud lets you spin up: portals partner portals customer communities help centers Each one gets a "guest user" profile. That profile controls what an unauthenticated visitor can see and do. If it's too permissive attackers can: read records Query data Pivot deeper No credentials needed. That's exactly what ShinyHunters exploited. At scale. WHY THIS KEEPS HAPPENING: Guest user access gets set once...then forgotten. Most orgs we audit have at least 1 over permissive guest profile. Usually from: A portal built 2 years ago for a project that shipped once A partner community nobody maintains A "temporary" community site that never got turned off Nothing looks broken. So nobody looks. Until 400 companies get breached in a month. 3 THING TO CHECK TODAY: You don't need your security team for this. 1. Turn off API access for your guest users 2. Lock down external sharing on sensitive objects 3. Audit what your guest user profile can actually read Each one takes minutes. Together they close the door ShinyHunters walked through. If you want the exact step-by-step guide audit checklist, I linked it below. THE BIG TAKEAWAY: Salesforce isn't the problem. Config drift is. The companies getting breached this month Are not running old software or skipping patches. They just never looked. Your org is 15 minutes away from knowing if you're safe. Go look. .... 👉 Audit Checklist: https://lnkd.in/gUvrWnvK 👉 Want us to audit for you? https://lnkd.in/gkHUrfXj

  • View profile for Jared Anders

    YTD: 22,366 Burpees | We Make Salesforce Rock | Husband | Father | Future Santa | Host of While You Were Pooping Podcast 💩🎙️ | Director of Marketing

    7,452 followers

    300+ companies just got hacked through Salesforce Experience Cloud. But none of them had a Salesforce bug. Attackers aren't breaking into the platform. They're walking through doors your org left wide open. I've been digging into the ShinyHunters campaign and the PipeLeak vulnerability. Here's what keeps coming up: - Guest user profiles with access to Account, Contact, Opportunity objects. Attackers query CRM data directly through the guest endpoint. No login. No credentials. - Connected Apps from three years ago that nobody remembers adding and nobody has ever audited. - Agentforce treating untrusted form data as part of its system context. A lead form with a hidden payload becomes an exfiltration vector. The uncomfortable part: most orgs have at least one of these problems right now. And they don't know it. I just wrote a deep dive on exactly what's being exploited and what you need to do about it. Link in the comments.

  • View profile for Matt Meyers (CTA)

    Founder & CEO EzProtect | DF and TDX Speaker | Best-Selling Author 📕 - Securing Salesforce Digital Experiences

    6,772 followers

    ShinyHunters just threatened Ameriprise Financial Services, LLC with a Salesforce data leak... And they have now hit financial institutions three times in the past two weeks alone. On March 22, 2026, ShinyHunters posted a ransom demand on the dark web claiming to possess Ameriprise Financial's Salesforce customer records and over 200GB of internal SharePoint data. Ameriprise manages $1.17 trillion in assets and has not publicly confirmed or denied the breach. No sample data has been published, so the scope cannot be independently verified. What is verified is the pattern behind it. Financial services represents one of the largest industry segments in the Salesforce ecosystem and in the U.S. and UK especially, it is increasingly rare for a large financial institution not to have some Salesforce footprint. That concentration has made financial services organizations a primary target. Ameriprise was preceded this month by ShinyHunters claims against Mercer Advisors and Beacon Pointe Advisors. The attack method is the same one running across hundreds of organizations since September 2025 — exploiting overly permissive Experience Cloud guest user configurations to query Salesforce objects without ever logging in. Salesforce confirmed on March 11, 2026 that the activity is not due to any vulnerability inherent to the platform — the investigation confirms it relates to a customer-configured guest user setting. Pro-tip directly from Salesforce's own security advisory? The highest-impact single change you can make is to disable the "API Enabled" permission in the guest user profile's System Permissions. This closes the Aura endpoint to unauthenticated API queries, which is the exact vector used in this campaign. Salesforce You do this in Setup, by navigating to your site's Guest User Profile and unchecking API Enabled under System Permissions. Salesforce strongly recommends disabling this permission unless guest users explicitly need API access, and advises testing the change in a sandbox first to understand the impact. But this is just one of many potential attack vectors. Wondering what a breach could cost your org? We built a calculator specifically for Salesforce leaders based off of years of research and data points from enterprise to federal orgs: https://lnkd.in/gB6H26Dd #Salesforce #FinTech #SalesforceThreatProtection

Explore categories