Scattered LAPSUS$ Hunters Claim Salesforce Breach, 1B Records, 39 Firms Listed
ID: f3856edc-e7fd-5eac-bb26-03fdd3eece48
STIX ID: report--f3856edc-e7fd-5eac-bb26-03fdd3eece48
Feed Name: HackRead
A criminal group styling itself "Scattered LAPSUS$ Hunters" launched a leak site claiming a mid‑2024 breach of Salesforce that resulted in ~989 million records (multiple terabytes) from 39 organisations being stolen and offered for sale; the group demands negotiations by October 10, 2025 and alleges exposure of sensitive PII (SSNs, driver’s licenses, dates of birth) while inviting legal firms and promising forensic documentation. The site lists victim companies and claimed data volumes, asserts Salesforce failed to enforce MFA and allowed OAuth-based intrusions, and provides a tuta.io contact and verification process; however, the claims are not independently verified and Salesforce has publicly stated there is no evidence its platform was compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
