The Containment Era is here. →Explore

Executive Summary

In October 2025, the extortion group known as 'Scattered Lapsus$ Hunters'—a coalition including ShinyHunters, Scattered Spider, and Lapsus$—launched a data leak site to extort 39 companies after a coordinated campaign exploiting Salesforce OAuth integrations. The attackers used sophisticated voice phishing to trick employees into connecting malicious OAuth apps to corporate Salesforce instances, enabling unauthorized database access. Stolen data included sensitive customer records from major global brands such as FedEx, Disney, Google, and Marriott, with threat actors demanding ransom to prevent broader public disclosure. Salesforce stated there was no compromise of its platform, but investigations continue.

This incident highlights the rising threat of supply chain and identity-based attacks targeting SaaS platforms, exploiting user trust and third-party integrations. With the growing adoption of SaaS solutions and increasing regulatory focus (e.g., GDPR), enterprises face mounting pressure to implement robust identity, access governance, and monitoring controls to defend against mass-scale data exfiltration and extortion.

Why This Matters Now

The attack exemplifies the urgent risk of supply chain compromise via cloud app integrations and OAuth abuse, which can bypass traditional security and lead to multi-company breaches. As ransomware groups turn to data extortion and exploit SaaS identity weaknesses, organizations must rapidly enhance visibility, segmentation, and prevention controls to reduce exposure and regulatory liability.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

By using social engineering and voice phishing, threat actors tricked employees into authorizing malicious OAuth applications, providing them with privileged access to Salesforce databases and integrated platforms.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Robust zero trust segmentation, egress controls, threat detection, and SaaS/API visibility could have identified, contained, or prevented lateral movement, OAuth abuse, and mass data exfiltration in these attacks. Distributed policy enforcement and least privilege access would have reduced unauthorized data exposure and limited extortion impact.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Suspicious OAuth app registrations and anomalous SaaS access would be rapidly detected and alerted.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based segmentation and least privilege policies limit over-privileged access by untrusted OAuth apps.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between workloads and SaaS connections is restricted by enforcing internal traffic policies.

Command & Control

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline real-time enforcement can detect and block abnormal API or SaaS management traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress filtering and policy enforcement block unauthorized outbound transfers of sensitive records.

Impact (Mitigations)

Centralized visibility and incident response tools enable rapid detection of anomalous activity and coordinated remediation.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
  • Support Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to sensitive customer data, including personal information, credentials, and financial records, leading to potential regulatory fines and reputational damage.

Recommended Actions

  • Implement zero trust segmentation and identity-based policies to restrict third-party SaaS application privileges and limit lateral movement.
  • Enforce egress security controls and detailed policy enforcement to block unauthorized SaaS data exports and prevent data exfiltration.
  • Deploy continuous threat detection with anomaly response to identify suspicious account activity, OAuth app integrations, and abnormal access patterns.
  • Centralize multicloud visibility and monitoring to rapidly respond to SaaS-integrated threats and automate incident response across cloud environments.
  • Regularly review and govern OAuth/scoped integrations, removing unnecessary or suspicious applications from vital cloud services.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image