Cloud Threat Horizons Report H1 2026

Read the H1 2026 Threat Horizons report from Google Cloud’s Office of the CISO. Get strategic intel on collapsing threat windows and identity risk.

Google Cloud
ShinyHunters Wage Broad Corporate Extortion Spree - A cybercriminal group that used voice phishing attacks to siphon more than a billion reco... https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #scatteredlapsus$hunters #oraclee-businesssuite #crimsoncollective #neer-do-wellnews #alittlesunshine #charlescarmakal #latestwarnings #thecomingstorm #cve-2025-61882 #austinlarsen #shinyhunters #ransomware #salesforce #salesloft #asyncrat #unc6040 #unc6395
ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security

ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security

Hacker behaupten: "Wir haben 1,5 Milliarden Salesforce-Datensätze"

Die Gruppe Shinyhunters scheint über die Angriffe auf Salesforce-Instanzen an eine grosse Datenmenge gelangt zu sein.

"The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

[...]

In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company.

ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms."

Read more of Lawrence Abrams' great reporting on Bleeping Computer:
https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/

#Salesforce #Salesloft #Oauth #Drift #databreach #ransom #ShinyyHunters #ScatteredSpider #LAPSUS$ #UNC6040 #UNC6395

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

BleepingComputer
Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion
#UNC6040 #UNC6395
https://www.ic3.gov/CSA/2025/250912.pdf
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations' Salesforce environments to steal data and extort victims.

BleepingComputer
FBI Warns of Salesforce attacks by UNC6040 and UNC6395

The U.S. FBI issued a flash alert to warn of malicious activities carried out by two cybercriminal groups tracked as UNC6040 and UNC6395.

Security Affairs

In 2025, UNC6395 struck Salesloft’s Drift, exposing Salesforce data and Google Workspace emails. From malicious IPs to SOQL queries, learn how this stealth attack unfolded and get Mandiant-backed strategies to lock down your integrations. Protect your business—read the full story now.

#SecurityLand #BreachBreakdown #Cybersecurity #Salesforce #SalesloftDrift #DataBreach #CyberAttack #UNC6395 #Mandiant

Read More: https://www.security.land/unc6395-stealth-attack-how-the-salesloft-drift-breach-shook-salesforce-users/

The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft – Krebs on Security