Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Extortion Group Launches Salesforce Data Leak

October 6, 2025
Reading Time: 4 mins read
in Incidents
Discord Reveals Data Breach Incident

A new data leak site has been launched by a group of cybercriminals calling themselves Scattered Lapsus$ Hunters, which includes members of the well-known ShinyHunters, Scattered Spider, and Lapsus$ groups. The site publicly lists 39 companies, including major brands like FedEx, Google, Home Depot, and Disney/Hulu, and features samples of data allegedly stolen from their Salesforce instances. The group is demanding that these companies pay a ransom by an October 10 deadline to prevent the full public release of their data. According to a representative from ShinyHunters, these companies were contacted prior to the launch of the site but chose to ignore their demands, prompting this public extortion campaign.

The cybercriminals have also issued a direct ultimatum to Salesforce itself, demanding a ransom to prevent the leak of all impacted customer data, which they claim amounts to roughly one billion records. In exchange for payment, the group has offered to cease all negotiations with individual companies and promised not to target them again. In a further threat, they warned that if Salesforce does not pay, they will assist law firms in pursuing civil lawsuits against the company. The group also claims that Salesforce failed to adequately protect its customers’ data in accordance with the European General Data Protection Regulation (GDPR).

The Scattered Lapsus$ Hunters have been conducting these attacks against Salesforce customers since the beginning of the year, using voice phishing to trick employees into linking a malicious application to their company’s Salesforce account. This gave the attackers access to company databases, which they then used to extort victims. The group noted that even if a single company was targeted, the stolen data often contained information for multiple subsidiaries, significantly increasing the impact of the breaches. The security firm Mandiant has been tracking these attacks under the name UNC6395, although they have not yet officially linked them to this specific group.

In addition to the current wave of attacks, the extortion group claims to have stolen sensitive information—including passwords and AWS access keys—from over 760 companies that use Salesloft’s Drift AI chat integration with Salesforce. The group, through a Telegram channel, announced that they will launch a separate data leak site on October 10 to extort these victims. Companies like Google, Palo Alto Networks, and Cloudflare are among those allegedly affected by this second campaign. The group has offered a concession: if a company pays a ransom during the current extortion phase, it will not be targeted again in the upcoming Salesloft campaign.

Salesforce has released a statement acknowledging the extortion attempts but maintains that its platform has not been compromised and that the activity is not related to any known vulnerabilities. The company says it is working with external experts and authorities to investigate and is supporting the affected customers. However, the cybercriminals’ public actions and claims of having breached major corporations continue to raise concerns for businesses worldwide.

Reference:

  • Extortion Group Targets Dozens of Companies in Salesforce Breaches
Tags: cyber incidentsCyber Incidents 2025Cyber threatsOctober 2025
ADVERTISEMENT

Related Posts

Discord Reveals Data Breach Incident

Discord Reveals Data Breach Incident

October 6, 2025
Discord Reveals Data Breach Incident

Abracadabra Hit by Third DeFi Hack

October 6, 2025
Hackers Target Oracle Apps For Extortion

Hackers Target Oracle Apps For Extortion

October 3, 2025
Hackers Target Oracle Apps For Extortion

Hospital Cyberattack Leaks Patient Data

October 3, 2025
Hackers Target Oracle Apps For Extortion

UK Renault Dacia Customer Data Stolen

October 3, 2025
Smishing targets routers in Belgium 2025

Dealership Software Breach Hits 766k

October 2, 2025

Latest Alerts

Oracle Issues Security Alert

Hackers Exploit Zimbra Zero Day Flaw

CISA Adds New Flaws to KEV Catalog

Facebook Scams Target Seniors With Malware

Android Spyware Poses As Signal And Totok

Chrome Update Fixes 21 Security Flaws

Subscribe to our newsletter

    Latest Incidents

    Discord Reveals Data Breach Incident

    Abracadabra Hit by Third DeFi Hack

    Extortion Group Launches Salesforce Data Leak

    Hackers Target Oracle Apps For Extortion

    UK Renault Dacia Customer Data Stolen

    Hospital Cyberattack Leaks Patient Data

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial