Executive Summary
In October 2024, the cybercriminal collective Scattered Lapsus$ Hunters resurfaced with a dedicated leak site, threatening to publish stolen data related to Salesforce customers if their extortion demands were not met. This group, an alliance of threat actors including Scattered Spider, Lapsus$, and ShinyHunters, allegedly compromised Salesforce environments through social engineering—specifically vishing IT support personnel to obtain credentials and, in parallel campaigns, exploiting OAuth token theft. The attackers claimed to possess approximately one billion records from 39 prominent organizations, including sensitive personally identifiable information (PII) like Social Security and driver’s license numbers.
This incident underscores the increased targeting of SaaS platforms via identity and access manipulation, as well as the growing sophistication of multinational threat actor collaborations. It signals elevated risk for organizations relying on cloud applications and highlights the necessity of enforcing multi-factor authentication and vigilant third-party access controls.
Why This Matters Now
The Salesforce breach campaign demonstrates the urgent need for robust identity protection and third-party risk management, as threat actors increasingly weaponize social engineering and exploit access gaps in cloud ecosystems. With extortion threats and regulatory action looming, organizations must swiftly reassess SaaS security posture and incident readiness.
Attack Path Analysis
The attackers began by conducting vishing attacks to trick IT support staff into providing access to Salesforce environments, then leveraged these credentials or OAuth token theft for elevated access. After securing privileged access, they moved laterally within connected SaaS or cloud services and applications to identify valuable data. The adversaries established command and control via persistent sessions and cloud-native OAuth mechanisms. Large volumes of sensitive data were exfiltrated from Salesforce, including PII, and the threat group extorted victims by threatening public exposure, leading to significant reputational and regulatory impact.
Kill Chain Progression
Initial Compromise
Description
Social engineering via vishing targeted IT support to obtain valid credentials or convince personnel to provide access to Salesforce environments.
MITRE ATT&CK® Techniques
Spearphishing (Voice)
Valid Accounts
Modify Authentication Process: Web Service
Cloud Accounts
Use Alternate Authentication Material: OAuth Tokens
Account Discovery
Data from Cloud Storage
Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Multi-factor Authentication for Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.2
CISA Zero Trust Maturity Model v2.0 – Identity Management and Authentication
Control ID: Identity - Authentication and Authorization
NIS2 Directive – User Access and Privilege Management
Control ID: Art. 21(2)(d)
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 9
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Salesforce data extortion exposes SaaS platforms to social engineering attacks, OAuth token theft, and regulatory compliance violations affecting customer trust and operations.
Computer/Network Security
Security firms like Palo Alto Networks and Zscaler targeted via compromised OAuth tokens, highlighting vulnerabilities in third-party integrations and authentication systems.
Financial Services
Data extortion targeting PII including Social Security numbers creates severe regulatory exposure under compliance frameworks like PCI DSS and privacy regulations.
Airlines/Aviation
Qantas Airways breach demonstrates aviation sector vulnerability to vishing attacks and SaaS compromise, risking passenger data and operational security systems.
Sources
- Scattered Lapsus$ Hunters Returns With Salesforce Leak Sitehttps://www.darkreading.com/cyberattacks-data-breaches/scattered-lapsus-hunters-returns-salesforce-leak-siteVerified
- Salesforce says some of its customers’ data was accessed after Gainsight breachhttps://techcrunch.com/2025/11/20/salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach/Verified
- Hacking group claims theft of 1 billion records from Salesforce customer databaseshttps://techcrunch.com/2025/10/03/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases/Verified
- Salesforce says it won’t pay extortion demand in 1 billion records breachhttps://arstechnica.com/security/2025/10/salesforce-says-it-wont-pay-extortion-demand-in-1-billion-records-breach/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, granular egress controls, encrypted traffic visibility, and cloud-native threat detection would have significantly reduced an attacker’s ability to escalate privileges, move laterally, exfiltrate data, and maintain persistence. Implementing microsegmentation and outbound filtration could have contained the incident before extensive data loss and extortion occurred.
Control: Multicloud Visibility & Control
Mitigation: Rapid identification of anomalous access attempts or new OAuth connections.
Control: Zero Trust Segmentation
Mitigation: Limits blast radius by enforcing least privilege and segmenting identity-based access.
Control: East-West Traffic Security
Mitigation: Stops unauthorized lateral traffic by inspecting internal flows.
Control: Threat Detection & Anomaly Response
Mitigation: Detects anomalous remote session behavior and persistent unauthorized access.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized outbound transfer of sensitive data.
Limits the operational and business impact by reducing attack surface and duration.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Marketing Campaigns
- Customer Support Services
Estimated downtime: 7 days
Estimated loss: $5,000,000
The breach led to unauthorized access to sensitive customer data, including personally identifiable information (PII) such as names, email addresses, phone numbers, and in some cases, Social Security numbers and driver's license numbers. This exposure poses significant risks of identity theft and financial fraud for affected individuals.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and identity-based policies to restrict lateral movement and privilege escalation in cloud and SaaS environments.
- • Deploy centralized multicloud visibility and real-time threat detection to identify anomalous access and credential use immediately.
- • Tighten egress filtering at application and network layers to block unauthorized data exfiltration from cloud applications.
- • Apply east-west traffic controls and microsegmentation to limit internal traversal between users, applications, and cloud workloads.
- • Integrate inline response automation via Cloud Native Security Fabric to rapidly contain and disrupt attacks before data loss and extortion can occur.



