Fluke Corporation
ShinyHunters claims 100+ GB including 21 million Salesforce records from 75-year-old test equipment manufacturer. Customer PII from professional equipment purchasers exposed.
What happened?
ShinyHunters claimed a breach at Fluke Corporation, a 75-year-old manufacturer of electronic test and measurement equipment. The claimed data includes over 100 gigabytes with 21 million Salesforce records and customer PII.
ShinyHunters has been relentless in 2026—PeopleSoft exploits, Salesforce compromises, healthcare targets. Their methodology adapts to wherever customer data lives, and CRM platforms hold extensive customer intelligence.
What data was actually inside?
21 million Salesforce records suggests comprehensive CRM data. Customer contacts, sales histories, support cases, business relationships spanning decades of equipment sales and service. Professional customers purchasing multimeters, oscilloscopes, thermal cameras.
Fluke's customers are businesses: electricians, engineers, manufacturers, utilities, technology companies. B2B customer data reveals organizational relationships, purchasing patterns, and technical requirements.
Who gets hurt and how?
Professional equipment purchasers. Businesses whose procurement relationships and technical requirements are exposed. Engineers and technicians whose contact information enables targeted phishing based on actual equipment purchases.
B2B data enables business-to-business social engineering. Phishing that references real orders, real support tickets, real equipment specifications. The legitimacy of the data makes fraudulent communications convincing.
What did they think they were doing right?
Fluke is owned by Fortive Corporation, which manages multiple industrial technology businesses. Enterprise CRM platforms like Salesforce are standard infrastructure. Security resources exist at the parent company level.
Manufacturing companies often don't consider themselves high-value targets. They make things, not data. But CRM systems accumulate customer intelligence over years. Support tickets contain technical details. Sales records contain procurement processes. The data value emerges from aggregation.
What did they not know about their own data?
21 million records across 75 years of customer relationships. Equipment registrations, warranty claims, service requests, sales interactions. CRM platforms accumulate data designed to never be deleted—historical context for future relationships.
Without active retention policies, the data grows indefinitely. Every interaction, every email, every support ticket. 21 million records represents the full history of customer relationships, not just current business.
If you use Salesforce, you probably have the same data types—emails, names, addresses, phone numbers. Do you know which fields contain PII?
What does attribution look like the morning after?
ShinyHunters is a known entity. Attribution is clear. The question is response: customer notifications, regulatory compliance, business relationship impact. 21 million records across professional customers requires substantial communication.
Fortive must assess whether other subsidiaries face similar risks. A breach at one business raises questions about security posture across the portfolio. Portfolio companies share infrastructure and sometimes access.
What would have changed the outcome?
CRM data lifecycle management—limiting accumulation to operationally necessary records rather than indefinite retention of 75 years of customer history.
CRM platforms are designed to remember everything. That's valuable for customer relationships. It becomes liability when attackers extract it all. Retention policies that expire old records, archive historical data separately, and minimize what's accessible from production systems reduce breach scope.
Fluke Corporation found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.