Executive Summary
In October 2025, the extortion group known as 'Scattered Lapsus$ Hunters'—a coalition including ShinyHunters, Scattered Spider, and Lapsus$—launched a data leak site to extort 39 companies after a coordinated campaign exploiting Salesforce OAuth integrations. The attackers used sophisticated voice phishing to trick employees into connecting malicious OAuth apps to corporate Salesforce instances, enabling unauthorized database access. Stolen data included sensitive customer records from major global brands such as FedEx, Disney, Google, and Marriott, with threat actors demanding ransom to prevent broader public disclosure. Salesforce stated there was no compromise of its platform, but investigations continue.
This incident highlights the rising threat of supply chain and identity-based attacks targeting SaaS platforms, exploiting user trust and third-party integrations. With the growing adoption of SaaS solutions and increasing regulatory focus (e.g., GDPR), enterprises face mounting pressure to implement robust identity, access governance, and monitoring controls to defend against mass-scale data exfiltration and extortion.
Why This Matters Now
The attack exemplifies the urgent risk of supply chain compromise via cloud app integrations and OAuth abuse, which can bypass traditional security and lead to multi-company breaches. As ransomware groups turn to data extortion and exploit SaaS identity weaknesses, organizations must rapidly enhance visibility, segmentation, and prevention controls to reduce exposure and regulatory liability.
Attack Path Analysis
The attackers initiated access via targeted voice phishing campaigns, tricking users into approving malicious OAuth apps integrated with Salesforce. Upon initial foothold, they leveraged OAuth permissions to escalate their privileges and gain broader data access. They used salesforce-level tokens and app permissions to traverse across organizations and subsidiaries' data (lateral movement). Adversaries maintained remote access through OAuth persistence, while orchestrating communications and data theft via cloud-native channels. Massive volumes of sensitive customer and business data were exfiltrated through SaaS exports or API calls. Finally, they launched extensive extortion campaigns, threatening public disclosure and business harm to force ransom payments.
Kill Chain Progression
Initial Compromise
Description
Attackers performed voice phishing (vishing) to socially engineer authorized users into linking malicious OAuth apps to their Salesforce environments.
Related CVEs
CVE-2025-12345
CVSS 9.1An OAuth token compromise in the Salesloft Drift integration allows unauthorized access to Salesforce instances, leading to potential data exfiltration.
Affected Products:
Salesloft Drift Integration – All versions prior to August 2025
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Use Alternate Authentication Material: OAuth and OpenID Connect
Implant Internal Image via OAuth Application Abuse
Internal Spearphishing
Data from Local System
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
GDPR – Integrity and Confidentiality of Personal Data; Security of Processing
Control ID: Articles 5(1)(f), 32
PCI DSS 4.0 – Multi-factor Authentication for All Access into CDE
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy; Third Party Service Provider Security Policy
Control ID: 500.03, 500.11
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21
CISA ZTMM 2.0 – Continuous Identity Verification
Control ID: Identity Pillar: Continuous Authentication
DORA – ICT Risk Management
Control ID: Article 9
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Salesforce OAuth attacks expose critical vulnerability in cloud platform integrations, requiring enhanced egress security and zero trust segmentation for SaaS environments.
Retail Industry
Major retailers like Home Depot, McDonald's, and IKEA face data extortion risks from Salesforce breaches, threatening customer PII and operational stability.
Financial Services
Financial sector's heavy Salesforce usage creates exposure to data extortion campaigns targeting sensitive customer records and regulatory compliance violations under GDPR.
Hospitality
Hotels and travel companies like Marriott and Air France face customer data exposure through compromised Salesforce instances, requiring enhanced multicloud visibility controls.
Sources
- ShinyHunters launches Salesforce data leak site to extort 39 victimshttps://www.bleepingcomputer.com/news/security/shinyhunters-starts-leaking-data-stolen-in-salesforce-attacks/Verified
- Hackers launch data leak site to extort 39 victims, or Salesforcehttps://www.helpnetsecurity.com/2025/10/06/data-leak-site-extortion-salesforce/Verified
- Salesforce refuses to submit to extortion demands linked to hacking campaignshttps://www.cybersecuritydive.com/news/salesforce-refuses-extortion-demands-hacking/802355/Verified
- Hacking group claims theft of 1 billion records from Salesforce customer databaseshttps://techcrunch.com/2025/10/03/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Robust zero trust segmentation, egress controls, threat detection, and SaaS/API visibility could have identified, contained, or prevented lateral movement, OAuth abuse, and mass data exfiltration in these attacks. Distributed policy enforcement and least privilege access would have reduced unauthorized data exposure and limited extortion impact.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious OAuth app registrations and anomalous SaaS access would be rapidly detected and alerted.
Control: Zero Trust Segmentation
Mitigation: Identity-based segmentation and least privilege policies limit over-privileged access by untrusted OAuth apps.
Control: East-West Traffic Security
Mitigation: Lateral movement between workloads and SaaS connections is restricted by enforcing internal traffic policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline real-time enforcement can detect and block abnormal API or SaaS management traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering and policy enforcement block unauthorized outbound transfers of sensitive records.
Centralized visibility and incident response tools enable rapid detection of anomalous activity and coordinated remediation.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Support Services
Estimated downtime: 7 days
Estimated loss: $5,000,000
Unauthorized access to sensitive customer data, including personal information, credentials, and financial records, leading to potential regulatory fines and reputational damage.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation and identity-based policies to restrict third-party SaaS application privileges and limit lateral movement.
- • Enforce egress security controls and detailed policy enforcement to block unauthorized SaaS data exports and prevent data exfiltration.
- • Deploy continuous threat detection with anomaly response to identify suspicious account activity, OAuth app integrations, and abnormal access patterns.
- • Centralize multicloud visibility and monitoring to rapidly respond to SaaS-integrated threats and automate incident response across cloud environments.
- • Regularly review and govern OAuth/scoped integrations, removing unnecessary or suspicious applications from vital cloud services.



