Full Breakdown
Massive Data Breach Claims by Scattered LAPSUS$ Hunters Targeting Salesforce Customers
10/5/2025, 1:27:45 PM
Overview of the Cyber Attack
A cybercriminal group known as Scattered LAPSUS$ Hunters has claimed responsibility for stealing nearly one billion records from companies utilizing Salesforce's cloud technology. This group, linked to a series of ransomware attacks on British retailers including Marks & Spencer, Co-op, and Jaguar Land Rover, alleges that it obtained sensitive personal information through social engineering tactics, specifically voice phishing (vishing). The hackers have launched a dark web leak site, threatening to release the stolen data unless a ransom is paid by October 10, 2025.
Methodology of the Attack
The attackers did not breach Salesforce's systems directly. Instead, they exploited vulnerabilities in the security practices of Salesforce customers. According to a hacker identified as "Shiny," the group used vishing to impersonate IT support personnel, convincing employees to grant access to Salesforce-linked tools. This manipulation allowed the attackers to utilize a modified version of Salesforce’s Data Loader tool, enabling them to extract large volumes of data from compromised systems.
Companies Affected
The breach reportedly impacts numerous high-profile companies, including Google, Toyota, FedEx, Disney, and Home Depot. Specific incidents have been confirmed by Allianz Life, which reported a breach affecting 1.4 million customers, and TransUnion, which disclosed that 4.4 million records were compromised. Other companies like Qantas and Stellantis have also acknowledged similar breaches.
Official Responses
Salesforce has firmly denied any compromise of its platform, stating, “At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology.” The company has emphasized its commitment to customer security and is working with affected organizations to provide support.
Criticism & Opposition
Despite Salesforce's assurances, cybersecurity experts have raised concerns about the adequacy of the company's security measures. Reports suggest that the group’s tactics highlight significant vulnerabilities in the reliance on third-party cloud services, particularly in the retail sector. Critics argue that Salesforce could enhance its security protocols to better protect customer data from social engineering attacks.
Conflicting Reports & Gaps
While Scattered LAPSUS$ Hunters claims to have stolen nearly one billion records, the authenticity of this figure remains unverified. Additionally, it is unclear whether all the companies listed on the hackers' leak site are indeed Salesforce clients. Law enforcement has arrested four individuals in connection with related cyberattacks, but it remains uncertain if these arrests are linked to the current claims.
What's Next
The situation continues to evolve, with ongoing investigations by British authorities and cybersecurity experts. The potential for further data leaks and the implications for affected companies are significant, raising questions about the future of data security in cloud environments.
Verbatim Quotes
- “ “At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology.” — Salesforce Spokesperson
- “The leverage is not the disruption of systems but the public exposure of stolen data, which can lead to customer backlash, regulatory fines, and severe reputational damage.” — Cybersecurity Expert
This incident underscores the persistent risks associated with social engineering and the vulnerabilities inherent in third-party cloud services, prompting calls for enhanced security measures across the industry.
