Hackers claim to have stolen over a billion Salesforce records – and are demanding nearly $1 billion not to leak them




  • Scattered Lapsus$ Hunters launch data leak site to pressure victims into ransom negotiations
  • Attackers exploited Salesloft’s Drift app to access Salesforce customer data, not Salesforce itself
  • Victims include Cloudflare, Zscaler, Tenable; Salesforce denies platform compromise or active vulnerabilities

Scattered Lapsus$ Hunters, a team-up of infamous hacking groups Scattered Spider, Lapsus$, and Shiny Hunters, has apparently created a standalone data leak and extortion page in order to pressure its victims into paying their ransom demands.

Earlier in 2025, news broke that the attackers managed to breach a third-party app – Salesloft’s Drift integration – and steal OAuth and refresh tokens. Then, they used the tokens to call the app customers’ Salesforce APIs and exfiltrate data such as customer contact records, case objects, and similar. Salesforce itself was not breached, but the data hosted by the clients was nabbed anyway.


https://cdn.mos.cms.futurecdn.net/U3nMoaJ3iNrFx8Qwkwmw7d-940-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img