Hackers claim to have stolen over a billion Salesforce Records – and requires nearly $ 1 billion not to leak them


  • Scattered Lapsus $ Hunters launches data leakage space to push victims for ransom negotiations
  • Attackers utilized Salesloft’s operation -App to access Salesforce -Kundetata, not Salesforce
  • Victims include cloudflare, zscaler, durable; SALESFORCE denies platform comprois or active vulnerabilities

Scattered lapsus $ hunters, a team -up of notorious hacking groups scattered spider, lapsus $ and shiny hunters, apparently created an independent data leak and extortion to push his victims to pay their ransom.

Earlier in 2025, news broke out that attackers managed to break a third -party app – Salesloft’s operating integration – and steal OAuth and Refresh -Tokens. Then they used tokens to call the app customers’ Salesforce APIs and Exfiltrate data such as customer contact records, case objects and the like. Salesforce itself was not broken, but the data that hosted the clients was still fooled.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top