Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationunderground-data-leakmass-credential-exposurethird-party-vendor-breach

Salesforce Data Breach and Ransomware Group Data Leak Site Targeting Salesloft Drift Integrations

Updated 3mo agoFirst seen Oct 3, 202519 sources

A ransomware group known as Scattered Lapsus$ Hunters, also referred to as ShinyHunters, has launched a darkweb data-leak site to pressure victims of a significant Salesforce data breach into paying extortion demands. The group claims to have stolen 1.5 billion Salesforce records from 760 companies that integrated their Salesforce customer relationship management (CRM) software with the Salesloft Drift artificial intelligence chatbot. The leak site, which debuted on a Friday, lists 39 victim organizations, including major brands such as Cisco, Disney, KFC, Ikea, Marriott, McDonald's, Walgreens, Albertsons, and Saks Fifth Avenue. The attackers are demanding separate ransoms from Salesforce itself to prevent the release of data pertaining to the remaining 721 affected companies. Samples of the stolen data published by the group include extensive personally identifiable information (PII), such as names, dates of birth, nationalities, passport numbers, full contact information, and employment histories. Cybersecurity researcher Milivoj Rajić has tested multiple samples of the leaked data and confirmed their validity, indicating the breach is authentic and the data is genuine. Additional compromised data includes shipping information, marketing lead data, customer support case records, chat transcripts, flight details, and car ownership records. The attack specifically targeted organizations that had integrated Salesforce with the Salesloft Drift AI chatbot, suggesting a possible exploitation of integration points or third-party application vulnerabilities. The public exposure of such a large volume of sensitive data significantly increases the risk of identity theft, fraud, and further targeted attacks against both individuals and organizations. The ransomware group’s strategy of publishing a leak site and naming high-profile victims is designed to maximize pressure and reputational damage, thereby increasing the likelihood of ransom payments. The incident highlights the risks associated with third-party integrations in cloud environments, especially when sensitive customer data is involved. Security teams at affected organizations are likely conducting forensic investigations, assessing the scope of the breach, and notifying impacted customers. The breach underscores the importance of robust access controls, regular security assessments of third-party integrations, and rapid incident response capabilities. Salesforce and Salesloft Drift users are advised to review their security configurations and monitor for suspicious activity. The event has drawn significant attention from the cybersecurity community due to the scale of the breach and the high-profile nature of the victims. Organizations are being urged to remain vigilant and to implement additional security measures to protect against similar attacks in the future.

Share:
Salesforce Data Breach and Ransomware Group Data Leak Site Targeting Salesloft Drift Integrations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Oct 13, 20258mo ago

Scattered Lapsus$ Hunters leaked stolen Salesforce customer data

Following the takedown of its leak site and victims' refusal to pay, the group released stolen data from Salesforce customers publicly. Reporting identified at least six affected companies, including Albertsons, Engie Resources, Fuji Film, The Gap, Qantas, and Vietnam Airlines.

Oct 7, 20259mo ago

Leak site was taken offline, possibly after FBI disruption

After the extortion campaign escalated, the group's data leak site was taken offline, with reporting suggesting possible law enforcement intervention. Later coverage explicitly described the disruption as an FBI action against the breach site.

Salesforce said it would not pay and denied platform compromise

Salesforce publicly stated it would not negotiate with or pay the extortionists. The company said it found no indication that the Salesforce platform itself had been compromised or that the activity stemmed from a known Salesforce vulnerability.

Oct 6, 20259mo ago

Threat actors set Oct. 10 deadline and crowdsourced harassment

The group threatened to publish all stolen data by October 10, 2025 unless its demands were met, and began offering small Bitcoin payments to supporters who harassed executives at alleged victim organizations. It also threatened to target listed customers if Salesforce did not engage.

Oct 3, 20259mo ago

Scattered Lapsus$ Hunters launched a Salesforce leak site

The extortion group reemerged with a dark web leak site listing 39 organizations allegedly affected in the Salesforce-related data theft campaign. The group claimed it had stolen up to roughly 1 to 1.5 billion records from hundreds of companies and used the site to pressure victims into paying.

Google and Salesforce published defensive guidance for the campaign

Google/Mandiant and Salesforce released a defensive framework to help organizations harden Salesforce environments, improve logging, and detect abuse tied to the ongoing intrusions. Guidance also emphasized stronger help-desk verification and protection against social engineering.

FBI and Google identified token abuse affecting Salesloft-linked customers

U.S. authorities and Google warned that attackers were using stolen OAuth tokens from the Salesloft Drift Email AI chatbot integration to access Salesforce instances. Reporting said the campaign affected hundreds of organizations, with Google estimating impact to roughly 700 Salesloft customers.

Aug 1, 202511mo ago

Salesforce customer intrusions began via social engineering and stolen tokens

Google threat intelligence reported that attacks against Salesforce customer environments began in early August 2025. The activity was linked to campaigns tracked as UNC6040 and UNC6395, involving vishing and abuse of stolen OAuth tokens associated with the Salesloft Drift app.

Mar 1, 20251y ago

Salesloft GitHub compromise exposed secrets and OAuth tokens

Salesloft disclosed that its GitHub account was compromised between March and June 2025, allowing attackers to steal secrets from private source code, including OAuth tokens tied to the Drift Salesforce integration. Those stolen tokens were later used to access customer Salesforce environments.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

94 LINKEDOpen in app
Affected products
5 linked
GithubGithubOracle E-Business SuiteTelegramAmazon Web Services
Organizations
82 linked
SalesforceGoogleThe Walt Disney CompanyScattered Lapsus$ HuntersfbiDriftQantasAlbertsons CompaniesFedexGapFujifilmHave I Been PwnedApollo Information SystemsBlack DuckOSORidge SecurityAlbertsonsEngie ResourcesFuji FilmThe Gap, Inc.Vietnam AirlinesSalesloftOracleCisco SystemsBleepingComputerPalo Alto NetworksWalgreensSaks Fifth AvenueMcDonald'sIkeaMarriott InternationalShutterstockZscalerTenableQualysOktaCloudflareInformation Security Media GroupResecurityProofpointMicrosoft CorporationGitHubChanelBreachForumsKFCAmazonThe RegisterTransUnionRed HatCrimson CollectiveBeyondtrustThe ComAmazon Web ServicesKeringJfrogElasticNutanixLapsus$SOCRadarHBO MaxCato NetworksDiorUnited Parcel ServiceToyota Motor CorporationBugcrowdFarmers InsuranceMuddled LibraBling LibraAir France & KLMLouis VuittonWorkdayRH-ISACThe Home DepotCartierCyberarkTruffleHogAdidasShinyHuntersInstacartRubrikTiffany & CoAllianz Life
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Salesforce Data Breach and Ransomware Group Data Leak Site Targeting Salesloft Drift Integrations | Mallory