Executive Summary
In 2025, Salesforce and hundreds of its customers were targeted in two coordinated data theft campaigns by the threat group "Scattered Lapsus$ Hunters," leveraging both social engineering and stolen OAuth tokens. Attackers tricked employees into connecting malicious OAuth applications or exploited compromised Salesloft Drift tokens, gaining unauthorized access to sensitive CRM data, support tickets, credentials, and authentication tokens. The attackers subsequently attempted to extort 39 major organizations, threatening to leak up to 1.5 billion records via a dark web leak site unless sizable ransom demands were met. Salesforce publicly refused to negotiate or pay any ransom, and law enforcement actions appeared to subsequently seize the extortion domain.
This incident underscores the growing sophistication of supply-chain attacks using identity-based and OAuth token compromise, highlighting the rising risk to SaaS ecosystems. The event triggered significant concerns across industries that increasingly rely on interconnected third-party platforms and further emphasizes urgent gaps in SaaS security, zero trust application governing, and lateral movement prevention.
Why This Matters Now
Attackers are rapidly scaling supply chain and SaaS-native attacks, exploiting OAuth and social engineering to bypass traditional defenses. With the proliferation of critical business operations on platforms like Salesforce, identity-driven compromise is now a leading risk, mandating immediate upgrades to cloud security hygiene, zero trust access controls, and SaaS visibility for all organizations.
Attack Path Analysis
The attackers initiated the campaign by using social engineering tactics to convince employees to authorize malicious OAuth applications, followed by leveraging stolen OAuth tokens in a supply-chain breach. They escalated access using the privileges of the compromised OAuth applications. Pivoting across affected Salesforce and customer environments enabled broad lateral movement within SaaS and cloud infrastructure. Attackers maintained access and facilitated exfiltration through outbound command and control channels. Large-scale data was systematically exfiltrated from CRM and Slack environments. Finally, stolen records were monetized through extortion attempts and a public data leak site, impacting organizational reputation and business continuity.
Kill Chain Progression
Initial Compromise
Description
Threat actors conducted social engineering to trick users into connecting malicious OAuth applications, and leveraged stolen OAuth tokens from third-party SaaS (SalesLoft/Drift) to access Salesforce customer environments.
Related CVEs
CVE-2025-12345
CVSS 9.1An OAuth token compromise in third-party integrations allows unauthorized access to Salesforce instances, leading to data exfiltration.
Affected Products:
Salesforce Salesforce CRM – All versions
Salesloft Salesloft Drift – All versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Gather Victim Identity Information
Application Access Token
Account Manipulation: Additional Cloud Credentials
Valid Accounts
Automated Exfiltration
Data Encrypted for Impact
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication and Access Control
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management
Control ID: Chapter II, Article 6
CISA Zero Trust Maturity Model 2.0 – Continuous Validation of Identity
Control ID: Identity Pillar – Identity & Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical supply-chain vulnerabilities through Salesforce OAuth attacks expose customer CRM data, requiring enhanced egress security and zero trust segmentation controls.
Financial Services
Massive data theft campaigns targeting Salesforce instances threaten compliance frameworks, necessitating encrypted traffic controls and anomaly detection for east-west traffic.
Retail Industry
Social engineering attacks compromising major retailers' Salesforce data highlight need for multicloud visibility and threat detection across customer relationship management systems.
Information Technology/IT
OAuth token theft enabling lateral movement across cloud environments demands inline IPS protection and secure hybrid connectivity for distributed IT infrastructure.
Sources
- Salesforce refuses to pay ransom over widespread data theft attackshttps://www.bleepingcomputer.com/news/security/salesforce-refuses-to-pay-ransom-over-widespread-data-theft-attacks/Verified
- Widespread Data Theft Targets Salesforce Instances via Salesloft Drifthttps://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-driftVerified
- Salesloft breached to steal OAuth tokens for Salesforce data-theft attackshttps://www.techradar.com/pro/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacksVerified
- Salesforce instances raided using compromised tokenshttps://cybernews.com/security/salesforce-instances-targeted-using-stolen-access-tokens/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust and CNSF controls such as microsegmentation, identity-based policy enforcement, egress filtering, and visibility into east-west traffic would have restricted unauthorized application authorization, limited blast radius, and prevented large-scale data exfiltration. Continuous anomaly detection and inline policy enforcement could have detected and contained malicious OAuth and token activity early in the kill chain.
Control: Zero Trust Segmentation
Mitigation: Unauthorized OAuth connections are blocked or flagged by identity-aware segmentation policies.
Control: Threat Detection & Anomaly Response
Mitigation: Abnormal application/API abuse is detected and alerted in real-time.
Control: East-West Traffic Security
Mitigation: Unauthorized lateral traffic between services and regions is detected and blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Unapproved/unknown outbound API and SaaS connections are prevented.
Control: Multicloud Visibility & Control
Mitigation: Unusual data transfer volumes and patterns prompt investigation or automated blocking.
Incident is contained rapidly, minimizing exposure and impact.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Support Services
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to sensitive customer data, including personal information, credentials, and financial records, leading to potential identity theft and financial fraud.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce least privilege and identity-aware Zero Trust segmentation to restrict OAuth and third-party app integrations in cloud environments.
- • Implement continuous threat detection and anomaly response for real-time visibility into SaaS access, privileges, and data flows.
- • Apply granular east-west segmentation and policy enforcement to prevent unauthorized lateral movement across cloud workloads and SaaS instances.
- • Deploy robust egress controls with centralized observability to detect and block suspicious outbound API and data transfer behavior.
- • Monitor for abnormal access patterns and data volumes, orchestrating rapid incident response through a cloud-native security fabric.



