New Salesforce Extortion Campaign Could Impact 1 Billion Records
Cybercriminals connected to a recent string of ransomware attacks on major British retailers have claimed to have stolen nearly 1 billion records from companies that store customer data in cloud databases hosted by Salesforce. The same hacking collective—known by aliases such as Lapsus$, Scattered Spider, and ShinyHunters—launched a dark web site called Scattered LAPSUS$ Hunters in early October to extort victims, threatening to publish stolen information unless a ransom is paid. The hackers’ site, first spotted by threat researchers and reported by TechCrunch October 3, demands ransom payments from companies to prevent the release of stolen data. The group alleges it has breached the databases of dozens of major companies—including Allianz Life, Google, Kering, Qantas, Stellantis, TransUnion, and Workday—by exploiting access to Salesforce-based environments. Other high-profile names such as FedEx, Hulu, and Toyota Motors also appear on the leak site. While some organ...