ShinyHunters launches Salesforce data leak site to extort 39 victims
ID: b01c7d2e-8735-51e7-838b-5bb6484c2035
STIX ID: report--b01c7d2e-8735-51e7-838b-5bb6484c2035
Feed Name: Bleeping Computer
An extortion group calling itself "Scattered Lapsus$ Hunters" (claiming ties to ShinyHunters, Scattered Spider, and Lapsus$) launched a public data-leak site listing 39 victim companies and posting stolen Salesforce data samples to extort payments before a deadline; the campaign leverages voice phishing, malicious OAuth apps, and stolen OAuth tokens to access and steal customer data, with the actors claiming up to ~1 billion records impacted across multiple waves (including Salesloft/Drift-related thefts); Salesforce states no indication of platform compromise while investigations continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
