logo

Salesforce Extortion Accelerates With New Leak Site | UpGuard

ID: 9d5bc97e-e49b-513c-acf1-8d35dc514a33

STIX ID: report--9d5bc97e-e49b-513c-acf1-8d35dc514a33

Feed Name: UpGuard Blog

Threat Score
78/100

Date Published: 2025-10-07

Date Updated: 2026-05-01

...
...

This report documents a coordinated extortion campaign by the Scattered Lapsus$ Hunters: attackers used voice-phishing to install malicious Salesforce integrations and compromised Salesloft’s GitHub/AWS environment to obtain OAuth tokens, enabling large-scale exfiltration of Salesforce customer data from multiple organizations and publication of an extortion portal demanding payment for data deletion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.