The Containment Era is here. →Explore

Executive Summary

In 2025, Salesforce and hundreds of its customers were targeted in two coordinated data theft campaigns by the threat group "Scattered Lapsus$ Hunters," leveraging both social engineering and stolen OAuth tokens. Attackers tricked employees into connecting malicious OAuth applications or exploited compromised Salesloft Drift tokens, gaining unauthorized access to sensitive CRM data, support tickets, credentials, and authentication tokens. The attackers subsequently attempted to extort 39 major organizations, threatening to leak up to 1.5 billion records via a dark web leak site unless sizable ransom demands were met. Salesforce publicly refused to negotiate or pay any ransom, and law enforcement actions appeared to subsequently seize the extortion domain.

This incident underscores the growing sophistication of supply-chain attacks using identity-based and OAuth token compromise, highlighting the rising risk to SaaS ecosystems. The event triggered significant concerns across industries that increasingly rely on interconnected third-party platforms and further emphasizes urgent gaps in SaaS security, zero trust application governing, and lateral movement prevention.

Why This Matters Now

Attackers are rapidly scaling supply chain and SaaS-native attacks, exploiting OAuth and social engineering to bypass traditional defenses. With the proliferation of critical business operations on platforms like Salesforce, identity-driven compromise is now a leading risk, mandating immediate upgrades to cloud security hygiene, zero trust access controls, and SaaS visibility for all organizations.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach revealed weaknesses in identity-based access controls, OAuth token governance, and lateral movement prevention, calling into question compliance with NIST, HIPAA, PCI DSS, and Zero Trust standards for data security.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust and CNSF controls such as microsegmentation, identity-based policy enforcement, egress filtering, and visibility into east-west traffic would have restricted unauthorized application authorization, limited blast radius, and prevented large-scale data exfiltration. Continuous anomaly detection and inline policy enforcement could have detected and contained malicious OAuth and token activity early in the kill chain.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Unauthorized OAuth connections are blocked or flagged by identity-aware segmentation policies.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Abnormal application/API abuse is detected and alerted in real-time.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Unauthorized lateral traffic between services and regions is detected and blocked.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Unapproved/unknown outbound API and SaaS connections are prevented.

Exfiltration

Control: Multicloud Visibility & Control

Mitigation: Unusual data transfer volumes and patterns prompt investigation or automated blocking.

Impact (Mitigations)

Incident is contained rapidly, minimizing exposure and impact.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
  • Support Services
Operational Disruption

Estimated downtime: 10 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to sensitive customer data, including personal information, credentials, and financial records, leading to potential identity theft and financial fraud.

Recommended Actions

  • Enforce least privilege and identity-aware Zero Trust segmentation to restrict OAuth and third-party app integrations in cloud environments.
  • Implement continuous threat detection and anomaly response for real-time visibility into SaaS access, privileges, and data flows.
  • Apply granular east-west segmentation and policy enforcement to prevent unauthorized lateral movement across cloud workloads and SaaS instances.
  • Deploy robust egress controls with centralized observability to detect and block suspicious outbound API and data transfer behavior.
  • Monitor for abnormal access patterns and data volumes, orchestrating rapid incident response through a cloud-native security fabric.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image