Salesforce-Datenklau: Cybergangs erpressen namhafte Unternehmen auf Leaksite

Cyberkriminelle erpressen auf einer Leaksite im Darknet 39 namhafte Unternehmen. Deren Daten haben sie aus Salesforce kopiert.

heise online

#Salesforce says it won’t pay #extortion demand in 1 billion records #breach

The threat group behind the campaign is calling itself #ScatteredLAPSUS$ Hunters, a mashup of three prolific data-extortion actors: #ScatteredSpider , #LAPSuS$ , and #ShinyHunters. #Mandiant, meanwhile, tracks the group as #UNC6040, because the researchers so far have been unable to positively identify the connections.
#privacy #security

https://arstechnica.com/security/2025/10/salesforce-says-it-wont-pay-extortion-demand-in-1-billion-records-breach/

Salesforce says it won’t pay extortion demand in 1 billion records breach

Scattered LAPSUS$ Hunters gave Salesforce until Friday to pay or else.

Ars Technica
ShinyHunters Wage Broad Corporate Extortion Spree - A cybercriminal group that used voice phishing attacks to siphon more than a billion reco... https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/ #scatteredlapsus$hunters #oraclee-businesssuite #crimsoncollective #neer-do-wellnews #alittlesunshine #charlescarmakal #latestwarnings #thecomingstorm #cve-2025-61882 #austinlarsen #shinyhunters #ransomware #salesforce #salesloft #asyncrat #unc6040 #unc6395
ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security

ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security

Hacker behaupten: "Wir haben 1,5 Milliarden Salesforce-Datensätze"

Die Gruppe Shinyhunters scheint über die Angriffe auf Salesforce-Instanzen an eine grosse Datenmenge gelangt zu sein.

"The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

[...]

In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company.

ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms."

Read more of Lawrence Abrams' great reporting on Bleeping Computer:
https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/

#Salesforce #Salesloft #Oauth #Drift #databreach #ransom #ShinyyHunters #ScatteredSpider #LAPSUS$ #UNC6040 #UNC6395

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

BleepingComputer

So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

#Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

My reports:
https://databreaches.net/2025/09/11/exclusive-high-end-fashion-retailers-gucci-balenciaga-brion-and-alexander-mcqueen-hit-by-salesforce-attacks/

https://databreaches.net/2025/09/15/update-kering-confirms-gucci-and-other-brands-hacked-claims-no-conversations-with-hackers/

@euroinfosec @zackwhittaker

Exclusive: High-end fashion retailers Gucci, Balenciaga, Brion, and Alexander McQueen hit by Salesforce attacks – DataBreaches.Net

Those readers who aren't A-listers (including yours truly) may never have heard of Kering , but you may have heard of their high-end fashion brands: Gucci. Yves

DataBreaches.Net

Last week, I broke the story about Gucci and other Kering brands being hacked by ShinyHunters as part of the Salesforce campaign. In my reporting, I included chat logs and other exclusive details. You can read my original reporting here: https://databreaches.net/2025/09/11/exclusive-high-end-fashion-retailers-gucci-balenciaga-brion-and-alexander-mcqueen-hit-by-salesforce-attacks/

There is now an update that refutes Kering's reported claim today that they didn't have any conversations with the hackers. I also highlight their failures to be more transparent about the incidents:
https://databreaches.net/2025/09/15/update-kering-confirms-gucci-and-other-brands-hacked-claims-no-conversations-with-hackers/

#databreach #Salesforce #ShinyHunters #Gucci #Brioni #Balenciaga #KERING #AlexanderMcQueen #UNC6040

Exclusive: High-end fashion retailers Gucci, Balenciaga, Brion, and Alexander McQueen hit by Salesforce attacks – DataBreaches.Net

Those readers who aren't A-listers (including yours truly) may never have heard of Kering , but you may have heard of their high-end fashion brands: Gucci. Yves

DataBreaches.Net
Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion
#UNC6040 #UNC6395
https://www.ic3.gov/CSA/2025/250912.pdf
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations' Salesforce environments to steal data and extort victims.

BleepingComputer