Amdocs A.I CyberSecurity Scoring
Amdocs
Company Information
Website:https://www.amdocs.com/about
Employees number:35,119
Number of followers:1,253,339
NAICS:5112
Industry Type:Software Development
Homepage:amdocs.com
Amdocs Risk Score (AI oriented)
Between 700 and 749
AmdocsSoftware Development
Updated:
03/04/2026
03/04/2026
721/1000
Moderate
Ba
Amdocs Global Score (TPRM)
xxxx
AmdocsSoftware Development
Score locked

AmdocsModerate
Current Score
721Ba (MODERATE)
01000
1 incidents
-56 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
720
MAY 2026
721
APRIL 2026
721
MARCH 2026
776
Breach
10 Mar 2026 • Amdocs
Salesforce, Snowflake, Okta, Sony, LastPass and AMD: Salesforce Customer Data Breach Linked to ShinyHunters
ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft
720
CRITICAL-56
SALLASAMDSNOSONOKT1773153462
ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft
The hacking group ShinyHunters has claimed responsibility for stealing data from approximately 100 major companies by exploiting misconfigurations in Salesforce’s Experience Cloud platform. According to reports, the group accessed information from around 400 websites and organizations, including high-profile targets like Snowflake, Okta, LastPass, Sony, AMD, and Salesforce itself.
Salesforce confirmed that a "known threat actor group" is actively scanning public-facing Experience Cloud sites portals used for customer, partner, and employee interactions due to overly permissive guest user configurations. The company clarified that the issue stems from customer-defined guest user profiles, not a vulnerability in Salesforce’s core platform.
### How the Attack Works
Experience Cloud sites can be configured to allow guest users (unauthenticated visitors) to view public pages and submit forms. However, if these guest profiles are granted excessive permissions, attackers can query and extract CRM data that was never intended to be public.
ShinyHunters reportedly used a modified version of AuraInspector, an open-source tool originally designed by Mandiant to detect misconfigurations in Salesforce’s Aura endpoints. The altered tool enables mass scanning of public-facing sites, extracting data when guest permissions are too broad.
### ShinyHunters’ Track Record
Active since 2019, ShinyHunters has been linked to numerous high-profile breaches, often employing "pay or leak" tactics demanding ransoms to prevent data exposure. Recent incidents include the 2024 Snowflake breach, as well as attacks on universities and consumer platforms, leveraging phishing, social engineering, and SaaS misconfigurations.
### The Broader Risk of Misconfiguration
This incident highlights a persistent cybersecurity challenge: misconfiguration remains a leading attack vector. While SaaS platforms like Salesforce offer robust security controls, human error in permission settings can expose sensitive data. Experience Cloud’s flexibility designed for public-facing portals becomes a liability when guest user profiles are improperly configured, allowing unauthorized access to CRM records.
### Salesforce’s Response & Mitigation Steps
Salesforce has urged customers to:
- Audit guest user permissions across all Experience Cloud sites.
- Set default external access to "private" to block unauthenticated queries.
- Disable guest access to public APIs and remove API-enabled permissions from guest profiles.
- Monitor logs for unusual activity, such as large-scale scanning attempts.
The incident underscores the need for ongoing security reviews rather than one-time configurations, as cloud environments evolve and threat actors refine their tactics. With regulatory scrutiny and reputational risks escalating, enterprises must treat access control and governance as continuous priorities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
776
JANUARY 2026
776
DECEMBER 2025
776
NOVEMBER 2025
776
OCTOBER 2025
776
SEPTEMBER 2025
776
AUGUST 2025
776
JULY 2025
776
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Amdocs ??
What was Amdocs's A.I Rankiteo Cyber Score in May 2026 ??
What was Amdocs's A.I Rankiteo Cyber Score in April 2026 ??
What was Amdocs's A.I Rankiteo Cyber Score in March 2026 ??
What was Amdocs's A.I Rankiteo Cyber Score in February 2026 ??
What was Amdocs's A.I Rankiteo Cyber Score in January 2026 ??
What was Amdocs's A.I Rankiteo Cyber Score in December 2025 ??
What was Amdocs's A.I Rankiteo Cyber Score in November 2025 ??
What was Amdocs's A.I Rankiteo Cyber Score in October 2025 ??
What was Amdocs's A.I Rankiteo Cyber Score in September 2025 ??
What was Amdocs's A.I Rankiteo Cyber Score in August 2025 ??
What was Amdocs's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Amdocs's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Amdocs ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Amdocs's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?