Salesforce refuses to pay ransom over widespread data theft attacks
ID: 9738d6a0-bf7e-5ae3-9554-b69d93b792db
STIX ID: report--9738d6a0-bf7e-5ae3-9554-b69d93b792db
Feed Name: Bleeping Computer
Threat Score
Salesforce customers were impacted by two 2025 campaigns that stole large volumes of CRM and support-ticket data via social engineering (malicious OAuth apps) and stolen SalesLoft/Drift OAuth tokens; threat actors including ShinyHunters and a group calling themselves Scattered Lapsus$ Hunters claimed up to ~1–1.5 billion records across hundreds of companies and launched an extortion/data-leak site to pressure victims and Salesforce for payment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
