The Containment Era is here. →Explore

Executive Summary

In mid-2025, a coordinated cybercriminal campaign led by UNC6395 and affiliates of Muddled Libra targeted Salesforce tenants via a multi-stage supply chain attack stemming from infiltrated third-party integrations such as Salesloft and Drift. Attackers used advanced social engineering and process exploitation rather than technological vulnerabilities to gain access to Salesforce customer data—including sensitive records like accounts, contacts, and opportunities. The operation highlighted the growing focus on data theft extortion tactics and the use of encrypted communications, with threat actors actively marketing stolen data through Telegram channels under monikers like "Scattered LAPSUS$ Hunters." The impact has been significant for retailers and digital platform users, driving urgent defensive and policy changes at Salesforce and affected enterprises.

This incident underscores an accelerating threat shift in 2025: attackers are increasingly leveraging social engineering and the SaaS supply chain to circumvent traditional defenses, monetizing access through extortion rather than ransomware. The event has intensified industry efforts to tighten access controls and enforce encryption, amid persistent regulatory and law enforcement actions.

Why This Matters Now

The surge in data theft-extortion attacks exploiting trusted platforms like Salesforce signals an urgent need for stronger SaaS security, real-time monitoring, and policy enforcement. As cybercriminal groups adapt quickly to access restrictions, organizations face heightened risk of customer data loss, reputational damage, and compliance violations if proactive controls are not implemented immediately.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed weaknesses in SaaS application access controls, supply chain management, and ineffective monitoring of third-party integrations—areas covered by PCI DSS, HIPAA, and NIST frameworks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF-aligned controls such as Zero Trust Segmentation, egress security, encryption, multicloud visibility, and inline threat prevention would have severely constrained the adversary's ability to move laterally, exfiltrate data, or operate undetected by segmenting sensitive applications, enforcing least privilege, and monitoring for anomalous data flows.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Abnormal login attempts and new SaaS integrations would be rapidly detected and alerted.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Movement from compromised identities is limited due to identity-based segmentation and least privilege.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between workloads or regions is prevented by microsegmentation and internal flow controls.

Command & Control

Control: Cloud Firewall (ACF) & Inline IPS (Suricata)

Mitigation: C2 traffic is detected, blocked, or alerted on via egress filtering and signature-based inspection.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized data exfiltration is detected and prevented at egress points.

Impact (Mitigations)

Extortion-related threats and post-exfil anomaly are detected and responded to rapidly.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
  • Marketing
Operational Disruption

Estimated downtime: 10 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to sensitive customer data, including personal information and credentials, leading to potential identity theft and financial fraud.

Recommended Actions

  • Enforce Zero Trust Segmentation and least privilege to restrict movement and access across sensitive workloads and SaaS platforms.
  • Implement egress filtering, inline IPS, and centralized monitoring to detect and prevent data exfiltration and command & control activities.
  • Leverage multicloud visibility solutions to baseline normal activity, rapidly detect anomalous logins, and flag unauthorized SaaS integrations.
  • Apply policy-based encryption to protect data-in-transit—including SaaS to SaaS and cross-region flows—against interception or packet sniffing.
  • Strengthen incident response processes and threat detection tooling to reduce dwell time from initial compromise to extortion or data leakage.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image