logo

ShinyHunters launches Salesforce data leak site to extort 39 victims

ID: b01c7d2e-8735-51e7-838b-5bb6484c2035

STIX ID: report--b01c7d2e-8735-51e7-838b-5bb6484c2035

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-03

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

An extortion group calling itself "Scattered Lapsus$ Hunters" (claiming ties to ShinyHunters, Scattered Spider, and Lapsus$) launched a public data-leak site listing 39 victim companies and posting stolen Salesforce data samples to extort payments before a deadline; the campaign leverages voice phishing, malicious OAuth apps, and stolen OAuth tokens to access and steal customer data, with the actors claiming up to ~1 billion records impacted across multiple waves (including Salesloft/Drift-related thefts); Salesforce states no indication of platform compromise while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.