This is what a real attack feels like from inside a Salesforce org.
Matt Meyers, CTA, Founder and CEO of EzProtect, walks through a Salesforce digital experience form where an attacker poses as a legitimate local business and applies for a small business loan. The contact name looks real. The email and phone look real. The submission includes a phishing link, and it attaches loan documents that are actually an executable file. The form creates a Case, and an agent opens the attachment the way any agent would. Within seconds the machine locks, a ransom demand appears, and the attacker owns everything that person can reach. Matt then runs the identical scenario with EzProtect enabled, and the file download is permanently blocked before the agent ever touches it.
The stakes reach past the incident itself. After a cyberattack, 33 percent of organizations reported that directors or executives faced loss of employment or position, according to the Fortinet 2025 Cybersecurity Skills Gap Report. Files cannot execute inside Salesforce. The damage starts the moment someone downloads one.
Salesforce added native file malware scanning in the Summer ’26 release, and it is on by default. It flags only the files it deems most likely to be malicious, and Salesforce recommends a partner solution for more stringent enterprise ready scanning. As of Summer ’26, native scanning still does not scan URLs or links in any field or object. It still identifies files by declared extension and MIME type, both of which an attacker can alter, so it still does not read true file type. It still covers files of 100 MB or smaller while Experience Cloud accepts uploads up to 10 GB. It still allows API uploads into the org first and scans them afterward. We uploaded a real trojan to the Summer ’26 scanner and the file went through, while EzProtect caught and blocked it.
EzProtect reads every file and every link and holds it until scanning proves it safe, which takes seconds. Detection runs on multiple layers, combining signature matching against a database of more than 50 million viruses, behavioral analysis in an isolated sandbox for zero-day and unknown threats, and true file type detection that reads actual file content rather than trusting the extension. Coverage extends across Experience Cloud, Email-to-Case, Chatter, Slack, WhatsApp, and API. Malicious URLs are scanned across fields and objects against live threat intelligence and rewritten automatically. Results surface in native Salesforce dashboards. Files are encrypted in transit and deleted after scanning, and no human at EzProtect ever touches customer data.
Book a 30-minute demo and see exactly how the Salesforce scanner holds up against EzProtect in your org.