Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Salesforce Refuses To Pay Ransom

October 8, 2025
Reading Time: 3 mins read
in Incidents
DraftKings Warns Of Account Breaches

Salesforce has officially stated it won’t negotiate with or pay a ransom to the threat actors responsible for a widespread data theft campaign that affected many of its customers this year. The company sent an email to its clients warning them that “credible threat intelligence” indicated the hackers planned to leak the stolen data, a statement which was also confirmed to BleepingComputer. This decision comes after a group called “Scattered Lapsus$ Hunters” launched a data leak site on a domain named after the notorious BreachForums hacking site, attempting to extort 39 companies whose data was compromised. These companies included major brands like FedEx, Disney, Google, Cisco, and many others.

The hackers claimed to have stolen nearly one billion data records, threatening to release them publicly unless a ransom was paid by either individual companies or Salesforce on behalf of all impacted customers. The stolen data came from two separate campaigns that occurred in 2025. The first wave of attacks, starting in late 2024, involved social engineering where hackers impersonated IT support staff to trick employees into connecting a malicious application to their company’s Salesforce instance. This allowed them to download and steal databases, which were then used for extortion. This initial campaign impacted companies such as Google, Cisco, and several LVMH subsidiaries.

A second data-theft campaign began in early August 2025, with the hackers using stolen SalesLoft Drift OAuth tokens to access customers’ CRM environments and steal data. The primary goal of these attacks was to steal support ticket data and scan it for sensitive information like credentials and API tokens. One of the hackers, known as ShinyHunters, claimed to have stolen about 1.5 billion records from over 760 companies during this campaign. Many major tech and cybersecurity firms, including Google, Cloudflare, and Palo Alto Networks, confirmed they were impacted by this supply-chain attack.

Initially, the recently launched data leak site was used to extort companies affected by the first social engineering attacks, with the threat actors planning to target those from the SalesLoft attacks after October 10th. However, the website has since been shut down. The domain’s nameservers now point to Cloudflare servers previously used by the FBI for domain seizures. This suggests law enforcement may have intervened, bringing the extortion attempt to an end, at least for now. This incident highlights the growing sophistication of cybercriminals and the difficult decisions companies face when targeted by such attacks.

Reference:

  • Salesforce Refuses To Pay Ransom After Widespread Data Theft Attacks
Tags: cyber incidentsCyber Incidents 2025Cyber threatsOctober 2025
ADVERTISEMENT

Related Posts

DraftKings Warns Of Account Breaches

DraftKings Warns Of Account Breaches

October 8, 2025
DraftKings Warns Of Account Breaches

Doctors Imaging Data Breach Hits 171K

October 8, 2025
Red Hat Data Breach Escalates Further

Red Hat Data Breach Escalates Further

October 7, 2025
Red Hat Data Breach Escalates Further

Threat Actors Claim Huawei Breach

October 7, 2025
Red Hat Data Breach Escalates Further

FC Barcelona Instagram Hacked By Scam

October 7, 2025
Discord Reveals Data Breach Incident

Discord Reveals Data Breach Incident

October 6, 2025

Latest Alerts

Microsoft Ties Storm 1175 To Medusa

Google Chrome RCE Flaw Details Leak

Redis Use After Free Bug Enables RCE

XWorm 6.0 Returns With New Plugins

Steam And Microsoft Warn Of Unity Flaw

Rhadamanthys Stealer Evolves Again

Subscribe to our newsletter

    Latest Incidents

    DraftKings Warns Of Account Breaches

    Doctors Imaging Data Breach Hits 171K

    Salesforce Refuses To Pay Ransom

    Red Hat Data Breach Escalates Further

    FC Barcelona Instagram Hacked By Scam

    Threat Actors Claim Huawei Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial