Swearingen v. Salesforce and Air France exposes cost of token abuse
ID: 0d4ceb07-a2cd-5395-9ae7-0b6b69ef5117
STIX ID: report--0d4ceb07-a2cd-5395-9ae7-0b6b69ef5117
Feed Name: ThreatLocker Blog
Swearingen v. Salesforce Inc. and Air France alleges that attackers exploited OAuth tokens and phishing applications to breach Salesforce in May 2025, exposing sensitive data for more than one million individuals (including Social Security numbers) and prompting notifications to affected Air France customers; the complaint frames Salesforce as a hub whose compromise can ripple to customer "spokes," cites a claimed link to UNC6395, and includes timeline, legal claims, and recommended security controls alongside vendor (ThreatLocker) mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
