GENEVA, 21 AUG 2026 — An extortion group claimed in early August that it had taken more than 25 million Salesforce records from Alcon. The data it subsequently published contained 218,000 unique email addresses.
Those two numbers are three weeks and two orders of magnitude apart, and only one of them can be checked.
What was claimed and what appeared
ShinyHunters listed the Swiss eye-care company on 2 August, alleging more than 25 million Salesforce records containing some personally identifiable information, and gave until 4 August for contact before publication.
The data later published is described as containing 218,000 unique email addresses alongside largely corporate contact fields — names, telephone numbers and physical addresses. The same campaign listed Questel and Lumenis.
The claimed number is a negotiating position
An extortion listing is not a disclosure. It is an opening bid, written by the party with the most to gain from it sounding large, published on a site whose purpose is to make a company answer the phone.
Nothing constrains that number. Nobody audits it, the victim usually cannot rebut it without confirming details it is still investigating, and journalists reporting the listing have only the criminal's word for the figure. Twenty-five million is what gets quoted; two hundred and eighteen thousand is what turned up.
The gap does not automatically mean the attackers were lying, though they might have been. A customer relationship system can hold dozens of records for each person, so 25 million rows might correspond to 218,000 contacts. Attackers also tend to claim everything they could access, not just what they copied, or they may publish only a sample.
The point is that the initial number is unknowable from the outside. It should be reported as a claim, not a fact.
Reporters keep printing the big number for a structural reason, not a lazy one. The initial claim is a ready-made news story: a named victim, a deadline, a dramatic figure. The correction, if it ever comes, is a quiet update to a database weeks later. One of those propagates and the other does not, and the difference is not about anybody's diligence.
The asymmetry runs one way, and it is worth being explicit about who benefits. A company that disputes a claimed figure has to explain how it knows, which means describing its own logging and forensic position in public while an investigation is running. An attacker who inflates a figure faces no such cost. So the incentive structure reliably produces a large unchallenged number and a small verified one arriving later, and anybody building a risk picture from headlines is building it from the first.
The verified data is corporate, which changes the harm
Names, work email addresses, telephone numbers and physical addresses of business contacts are not nothing, and they are a different category of harm from health or financial records.
This kind of list is a toolkit for targeted phishing. An attacker with a verified list of a company's business contacts — correct names, correct addresses — can create a convincing pretext based on a known supplier relationship. The risk shifts from the breached company to its partners and customers.
Because Alcon is in the healthcare sector, the first question is always about patient data. Nothing in the published files indicates it was involved; the fields look strictly corporate. Without a clear statement, however, people will assume the worst.
The two-day deadline, from a Sunday to a Tuesday, was also telling. It is not a realistic window for negotiation; a large multinational cannot convene the right people that quickly, as the attackers surely know. A deadline that short is designed to produce publication rather than payment, and publication is what generates the pressure for the next victim on the list.
Three victims, one platform, one method
That Alcon, Questel and Lumenis were all targeted in the same campaign points to the bigger picture.
We reported in June on the same group using voice phishing to reach Salesforce environments at Charter and Carnival, and in May on a claim of 275 million records from Instructure Canvas. The campaign has been running for months, the target is consistently a widely used software-as-a-service platform, and the entry route has consistently been people rather than software.
This is an access problem, not a patching problem. A vishing call that tricks an employee into approving a connected app or reading out a code bypasses technical defenses entirely. The effective controls are unglamorous: restricting which applications can connect, limiting how much any single integration can export, and setting up alerts for bulk data retrieval.
The platform's own security is largely not the variable. What differs between the companies that lose data this way and those that do not is how much a single authorised session is permitted to take.
Why regional companies should read this as an inventory problem
Southeast Asian enterprises use the same platforms, frequently with more integrations and less oversight of them, because a customer relationship system accumulates connected tools the way a phone accumulates apps.
The practical question is not about the platform's security, but your own inventory. How many third-party applications hold a token to your instance? Who approved them? Is the person who approved them still with the company? What are the export limits? This is the terrain where these attacks are won or lost, and most organisations cannot map it in an afternoon.
The regulatory position is thinner here too. A campaign hitting companies across several jurisdictions produces notification duties that depend on where the affected people are, and a business contact list spanning ten ASEAN markets is a notification problem before it is a security one.
What remains unconfirmed
So far, Alcon has not publicly confirmed a breach, described its scope, or disputed the claim. The figures in circulation still originate entirely with the attacker.
It also remains unclear how the attackers got in, though voice phishing was used in earlier incidents from this campaign. We do not know if regulators or affected individuals have been notified, what the relationship is between the 25 million records claimed and the 218,000 published, whether more data will follow, or if a payment was made.
What to watch for
A statement from the company would be the first thing to look for. Silence is normal during an investigation, but it leaves the attacker's number as the only one on the record.
Then watch whether the published set grows. Extortion groups routinely release in stages, and a second tranche would tell you whether the original claim was inflated or merely unpublished.
Finally, look at the connected-application problem in your own shop. The campaign has now run for months against a consistent target using a consistent method, which is about as much warning as this class of attack ever gives.