Morton v. Salesforce and TransUnion puts SaaS trust on trial
ID: 7f8a9722-c411-5485-a2cc-0cd0658181dc
STIX ID: report--7f8a9722-c411-5485-a2cc-0cd0658181dc
Feed Name: ThreatLocker Blog
This analysis summarizes the Morton v. Salesforce class-action complaint which alleges a 2025 wave of voice‑phishing 'hub‑and‑spoke' attacks that tricked employees into authorizing attacker‑controlled Salesforce tooling, enabling large‑scale CRM exfiltration and pivots into connected SaaS (including a TransUnion incident affecting approximately 4.46 million individuals); the piece distinguishes defendant-confirmed facts from plaintiff allegations and recommends technical and governance controls to mitigate similar SaaS token‑theft and lateral‑movement risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
