Executive Summary
In May 2025, the ShinyHunters/Scattered LAPSUS$ Hunters cybercrime coalition initiated a coordinated data extortion campaign against numerous Fortune 500 companies, exploiting voice phishing tactics to compromise Salesforce portals. Attackers tricked privileged users into connecting malicious applications, leading to the theft of over a billion customer records across companies such as Toyota, FedEx, Disney/Hulu, and UPS. Following the attacks, ShinyHunters launched a public shaming and extortion blog, threatening to publish the stolen data unless victims surrendered to ransom demands. Multiple related incidents included attacks on Red Hat's GitLab servers and Discord via a third-party support contractor, impacting sensitive business and PII data. Law enforcement action traced the threats to a blend of established groups, operating globally and leveraging emerging zero-day exploits.
This breach underscores the increasing sophistication and scale of identity-driven and extortion-centered cyberattacks targeting cloud SaaS platforms. It coincides with a resurgence in social engineering, as threat actors exploit both technical vulnerabilities and human factors. The event highlights the urgency for robust controls around SaaS access, third-party risk, and east-west data movement visibility.
Why This Matters Now
This incident reflects a new wave of targeted extortion campaigns leveraging both technical vulnerabilities and advanced social engineering to penetrate trusted SaaS and cloud services. The rapid and public escalation of victim shaming, combined with ongoing exploitation of authentication tokens and zero-days, signals urgent pressure for enterprises to strengthen SaaS security, monitor internal data flows, and address compliance gaps in the face of emergent threat actor collaboration.
Attack Path Analysis
ShinyHunters initiated their campaign with targeted voice phishing to compromise identities and OAuth integrations into corporate SaaS (e.g., Salesforce), as well as exploiting a critical zero-day (CVE-2025-61882) for initial access. After establishing footholds, they abused stolen tokens and misconfigurations for privilege escalation within both cloud portals and infrastructure repositories. The attackers then laterally moved by pivoting through interconnected services and accounts, harvesting more secrets, code repositories, and sensitive data. They maintained covert command and control channels using malware (ASYNCRAT) and possibly abused SaaS/OAuth frameworks. Sensitive data, tokens, and business records were exfiltrated via outbound channels and covert exports. The final impact was large-scale data extortion campaigns, public shaming, and threats of data publication across hundreds of victim organizations.
Kill Chain Progression
Initial Compromise
Description
The attackers used sophisticated voice phishing and social engineering to trick users into authorizing malicious apps in Salesforce, and also exploited the CVE-2025-61882 Oracle E-Business Suite vulnerability for unauthenticated remote code execution.
Related CVEs
CVE-2025-61882
CVSS 9.8An unauthenticated remote code execution vulnerability in Oracle E-Business Suite's Concurrent Processing component allows attackers to fully compromise the system.
Affected Products:
Oracle E-Business Suite – 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
User Execution: Malicious File
Modify Authentication Process: Web Portal
Valid Accounts
Data from Cloud Storage Object
Exfiltration Over C2 Channel
Data Encrypted for Impact
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Authentication Management
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9(2)
CISA ZTMM 2.0 – Identity Verification and Phishing Resistance
Control ID: Identity Pillar - 1.2
NIS2 Directive – Incident Handling and Reporting
Control ID: Article 21(2)(e)
GDPR – Personal Data Breach Notification
Control ID: Articles 33 & 34
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical exposure through Salesforce, Oracle E-Business Suite zero-day, and GitLab repositories containing authentication tokens, source code, and customer secrets requiring immediate segmentation.
Financial Services
High-value targets for data extortion with extensive Salesforce customer data, payment card information, and compliance violations across HIPAA, PCI-DSS frameworks.
Information Technology/IT
Infrastructure compromise through voice phishing, malicious authentication tokens, and east-west traffic exploitation demanding enhanced zero trust network segmentation and visibility.
Transportation
Major logistics companies like FedEx and UPS targeted for customer data theft, requiring encrypted traffic protection and egress security policy enforcement.
Sources
- ShinyHunters Wage Broad Corporate Extortion Spreehttps://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/Verified
- Oracle Security Alert Advisory - CVE-2025-61882https://www.oracle.com/security-alerts/alert-cve-2025-61882.htmlVerified
- NVD - CVE-2025-61882https://nvd.nist.gov/vuln/detail/CVE-2025-61882Verified
- Hacking group claims theft of 1 billion records from Salesforce customer databases | TechCrunchhttps://techcrunch.com/2025/10/03/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, east-west traffic security, egress filtering, and real-time threat detection at both the cloud and SaaS layers would have sharply limited attacker movement and prevented or observed bulk exfiltration. CNSF-aligned controls targeting workload isolation, encrypted traffic, policy-driven egress, and threat response provide key choke points to break the attack chain against hybrid and multi-cloud extortion campaigns.
Control: Threat Detection & Anomaly Response
Mitigation: Baselined anomaly detection could flag unusual SaaS OAuth app authorizations or abnormal server exploitation.
Control: Zero Trust Segmentation
Mitigation: Identity-based policy enforcement narrows token blast radius and reduces cross-app privilege escalation.
Control: East-West Traffic Security
Mitigation: Internal movement between workloads, clouds, and SaaS APIs flagged and constrained at granular level.
Control: Inline IPS (Suricata)
Mitigation: Signature and anomaly-based IPS blocks known malware C2 channels and malicious payloads in line.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data flows are filtered and subject to policy enforcement, preventing unauthorized exfiltration.
Comprehensive incident traceability and unified response to limit overall breach consequences.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Data Analytics
Estimated downtime: 7 days
Estimated loss: $5,000,000
Approximately 1 billion records containing sensitive Personally Identifiable Information (PII) were exfiltrated, including customer names, contact details, and potentially financial information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation and least-privileged access across all user-to-app and workload-to-workload paths to limit credential and token abuse vectors.
- • Enforce real-time threat and anomaly detection to swiftly identify and respond to unusual app authorizations, server exploit attempts, or policy violations.
- • Deploy granular east-west traffic controls and inline IPS within and between cloud, SaaS, and hybrid environments to contain lateral movement and C2 activity.
- • Apply robust egress filtering and encrypted traffic controls to prevent unauthorized data export and detect covert exfiltration channels.
- • Centralize cloud and SaaS visibility, control, and forensics to support rapid breach response, compliance reporting, and operational recovery.



