Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
underground-data-leakthird-party-vendor-breachmass-credential-exposurecybercrime-service-ecosystem

Scattered LAPSUS$ Hunters Data Leaks from Salesforce Breaches

Updated 3mo agoFirst seen Oct 12, 20253 sources

A hacking group known as Scattered LAPSUS$ Hunters publicly released data stolen from the Salesforce environments of multiple companies, including Qantas and Vietnam Airlines. The group had previously threatened to leak data unless Salesforce or the affected companies paid a ransom, but the deadline passed without payment, prompting the attackers to publish data from six of the 39 companies they claimed to have compromised. The initial leaks included data from Qantas, Albertsons, GAP, Vietnam Airlines, Fujifilm, and Engie Resources. Qantas received significant media attention due to a court injunction it obtained in an attempt to prevent the use or dissemination of the stolen data, but the injunction proved ineffective as the data was still widely distributed. The attackers used multiple platforms to share the stolen information, including an onion site, a clear net forum, and a new clear net leak site, making the data accessible to a broad audience. For Vietnam Airlines, the breach resulted in the exposure of 7.5 million unique customer email addresses, along with names, phone numbers, dates of birth, and loyalty program membership numbers. The breach of Vietnam Airlines' Salesforce environment reportedly occurred in June 2025, but the data was not publicly released until October. The group’s leak strategy included charging for access to the data on some platforms, while later making it freely available on others. Despite initial claims of a massive leak affecting 39 companies, only six organizations' data was actually released, leading to speculation about the group’s motives and capabilities. The attackers communicated with followers via Telegram, providing updates and alternative download links when their primary leak site experienced technical issues. The incident highlighted the limitations of legal measures such as injunctions in preventing the spread of stolen data once it is in the hands of threat actors. Media and security experts, including Troy Hunt, provided commentary on the situation, emphasizing the inevitability of the data’s release and the challenges faced by affected organizations. The breach underscores the risks associated with third-party cloud platforms like Salesforce and the importance of robust security controls and incident response plans. Companies affected by the breach were advised to notify impacted customers, recommend password changes, and implement additional security measures such as two-factor authentication. The event also demonstrated the evolving tactics of cybercriminal groups in monetizing and publicizing stolen data, as well as the ongoing threat posed by supply chain and third-party breaches.

Share:
Scattered LAPSUS$ Hunters Data Leaks from Salesforce Breaches
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 18, 20263mo ago

Vietnam Airlines breach was added to Have I Been Pwned

Have I Been Pwned published an entry for the Vietnam Airlines data breach, identifying it as part of the October 2025 public release of data stolen from Salesforce instances. The listing summarized the exposed customer data and attributed the release to Scattered LAPSUS$ Hunters.

Oct 12, 20258mo ago

Threat actors said no further Salesforce-related leaks would occur

Following the initial releases, Scattered LAPSUS$ Hunters claimed it could not leak more data and said nothing else would be published, while leaving the broader victim listings and samples online. This marked a de-escalation from earlier expectations of a much larger leak.

Group publicly released data for six companies including Vietnam Airlines

After the ransom deadline passed, the group leaked data for only six companies: Qantas, Albertsons, GAP, Vietnam Airlines, Fujifilm, and Engie Resources. The Vietnam Airlines data included 7.3 million unique customer email addresses along with names, phone numbers, dates of birth, and loyalty program membership numbers.

Scattered LAPSUS$ Hunters threatened Salesforce and listed 39 companies

A hacking group calling itself Scattered LAPSUS$ Hunters threatened Salesforce with a ransom deadline and claimed to hold data tied to Salesforce and its customers. The group listed 39 companies on its leak site as alleged victims.

Jun 1, 20251y ago

Vietnam Airlines' Salesforce environment was breached

Vietnam Airlines was identified as one of multiple organizations whose Salesforce environments were compromised. The breach of Vietnam Airlines' Salesforce instance occurred in June 2025.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Affected products
2 linked
LimewireTelegram
Organizations
12 linked
QantasSalesforceFujifilmPluralsightMalwarebytesScattered Lapsus$ HuntersAT&TAlbertsonsMicrosoft CorporationEngie ResourcesGapVietnam Airlines
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.