Person signing paperwork at a desk with documents and a pen
Photo via Unsplash

TL;DR: ShinyHunters breached Kemper Corporation (one of the largest U.S. insurance companies) through its Salesforce account, stealing 29GB of data. The haul includes over 13 million Salesforce records: employee names, emails, job titles, internal documents, and Stripe payment logs with customer names and transaction amounts. ShinyHunters gave Kemper until April 14 to pay. Kemper didn't. The data hit the dark web on April 15. Law firms are already launching class action investigations.

ShinyHunters' Insurance Payday

On April 12, 2026, ShinyHunters posted on their dark web site claiming they'd breached Kemper Corporation. The ransom note was blunt: "Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way" [1].

Kemper didn't pay. On April 15, ShinyHunters published the stolen data.

The attack vector? Salesforce. Again. ShinyHunters used social engineering to trick Kemper employees into revealing their Salesforce login credentials, then used that access to vacuum up 29GB of data from the insurer's CRM infrastructure [2].

Kemper's official statement is the standard corporate breach playbook: "We recently became aware of a cybersecurity incident and immediately began a thorough investigation with the help of third-party cybersecurity experts, and notified law enforcement. There has been no disruption to our operations or our ability to serve our customers" [2].

No disruption to operations. Just 13 million records on the open internet.

What ShinyHunters Got

Security researchers who analyzed the leaked dataset found a mix of employee and customer data [2]:

  • Employee PII: full names, email addresses, job roles
  • Internal corporate documents: strategy files, operational records
  • Employee training materials: some dating back to 2021
  • Stripe payment logs: customer names, transaction amounts, timestamps, and payment status

One thing researchers didn't find in the samples they analyzed: credit card numbers or bank account details. That's the sliver of good news. But customer names tied to specific transaction amounts and dates? That's still a gift for phishing operations. A scammer who knows you paid Kemper $487.32 on March 3rd for your auto policy sounds a lot more convincing than a generic "update your payment information" email.

The Salesforce Problem: Company #30-Something

If you've been following our ShinyHunters coverage, the attack pattern is painfully familiar. Social engineer an employee. Steal their Salesforce credentials. Extract everything the CRM can see. Demand ransom. Dump it all when the company doesn't pay.

Kemper joins a growing list of ShinyHunters' Salesforce victims in 2026 alone:

McGraw-Hill

13.5 million records via Salesforce misconfiguration. 100GB dumped after missed ransom deadline. Full coverage.

TransUnion

Credit bureau breached through Salesforce supply chain. Consumer credit data exposed. Full coverage.

Canada Life

5.6 million Salesforce records stolen from one of Canada's largest insurers. Full coverage.

The common thread isn't a Salesforce platform vulnerability. Salesforce itself hasn't been compromised. The problem is how companies configure and protect their Salesforce access: weak credentials, no MFA enforcement, over-permissioned accounts, employees who can be social-engineered into giving up their logins.

ShinyHunters isn't exploiting a bug. They're exploiting human nature. And it keeps working.

Why Kemper Matters

Kemper Corporation isn't a small insurer. They serve over 5 million policyholders across the U.S., offering auto, homeowners, life, and health insurance, primarily to customers in underserved markets [3]. They reported $4.5 billion in revenue in 2025.

Insurance companies sit on some of the most sensitive personal data anywhere: names, addresses, Social Security numbers, health conditions, driving records, claims histories, financial information. Whether ShinyHunters accessed that deeper trove (beyond the Salesforce CRM data they've published) is still unclear. Kemper's investigation is "ongoing."

What's already clear: the data that was published gives attackers enough to build highly targeted phishing campaigns against Kemper's customers. "We noticed an issue with your recent payment of $X on [date]" hits different when $X and [date] are real.

Lawyers Are Already Circling

Law firm Edelson Lechtzin LLP announced an investigation into the Kemper breach on April 22, a week after the data hit the dark web [4]. They're looking into potential class action claims on behalf of individuals whose personal information was exposed.

Kemper has also been sued directly. Law360 reported at least one lawsuit filed over the 13-million-record hack [5]. Given ShinyHunters' track record and the scale of the leak, more lawsuits are likely incoming.

The legal exposure for Kemper is significant. As an insurer, they're held to higher data protection standards than most companies. State insurance regulators have their own cybersecurity requirements, and a breach of this size through a preventable social engineering attack is going to draw scrutiny.

If You're a Kemper Customer or Employee

Watch for Targeted Phishing

Scammers now potentially have your name, email, and payment history with Kemper. Be extremely skeptical of any communications about your insurance policy. Call Kemper directly using the number on your policy card.

Monitor Your Accounts

Check your Kemper account for unauthorized changes. If your email was in the leak, check other accounts that use the same email. Enable MFA everywhere you can.

Freeze Your Credit

If you're a Kemper customer and your name plus financial transaction data was exposed, a credit freeze at all three bureaus (Equifax, Experian, TransUnion) costs nothing and blocks new accounts opened in your name.

Employees: Change Everything

If you work at Kemper, assume your corporate credentials are compromised. Change passwords on every system, especially any that share credentials with your Salesforce account. Report suspicious emails to your security team.

ShinyHunters Isn't Slowing Down

Kemper is at least the 30th company ShinyHunters has hit through Salesforce-related attacks in 2026. The gang's playbook is public knowledge at this point. Security researchers have documented it. We've covered it extensively. Companies know the risk.

And yet here we are, with another insurance company (a company that sells risk management) failing to manage the risk of a social engineering attack on their own Salesforce accounts. Kemper joins Canada Life as the second major insurer breached by ShinyHunters this year.

If your company uses Salesforce, enforce MFA on every account. Implement phishing-resistant authentication. Restrict API access to the minimum necessary. Train employees to recognize social engineering. Do it today. ShinyHunters already has their list of targets, and they're working through it methodically.

References

  1. DeXpose: ShinyHunters Breach Kemper Corporation: Data at Risk (April 2026)
  2. Cybernews: Over 13M Kemper Corporation records leaked on the dark web, hackers claim (April 2026)
  3. SC Media: ShinyHunters alleges Kemper Corporation hack, exposes over 13M records (April 2026)
  4. PR Newswire: Kemper Corporation Data Breach: Edelson Lechtzin LLP Launches Investigation (April 2026)
  5. Law360: Kemper Sued Over Hack Of More Than 13M Records (April 2026)