Executive Summary
In June 2024, automaker Stellantis confirmed that a cybersecurity incident impacted some of its North American customers after attackers compromised a third-party service provider’s platform integrated with their Salesforce infrastructure. The breach exposed sensitive customer data, though financial and highly confidential information reportedly remained secure. The attackers exploited weaknesses in the external vendor’s environment to gain unauthorized access, demonstrating the risks inherent in today's interconnected supply chains. Stellantis responded by notifying affected customers, engaging security experts, and working closely with the vendor to contain and investigate the incident.
This breach highlights the ongoing surge of supply chain and third-party risks as enterprises rely on hosted platforms like Salesforce for mission-critical operations. The event underscores the increasing sophistication of attackers targeting SaaS ecosystems and underscores the need for robust supplier security controls and monitoring.
Why This Matters Now
Enterprises are increasingly reliant on third-party SaaS platforms and integrations, making supply chain attacks a top current threat. The Stellantis breach demonstrates how vulnerabilities in partners or vendors can undermine even mature organizations. Rapid regulatory scrutiny and reputational impacts make strengthening third-party security posture an urgent strategic priority.
Attack Path Analysis
Attackers gained initial access to a third-party provider's Salesforce environment through compromised credentials or misconfiguration. They then escalated their access within the platform, likely acquiring higher privileges or further access to customer data. Using these privileges, the attackers laterally accessed different data sets or services linked to the environment. A command and control channel was established to maintain persistence and exfiltrate stolen data covertly. Sensitive customer information was exfiltrated from the Salesforce platform. The impact was realized as Stellantis confirmed the breach and data loss affecting North American customers.
Kill Chain Progression
Initial Compromise
Description
Attackers compromised the third-party Salesforce environment, possibly via exposed credentials, API keys, or misconfiguration.
Related CVEs
CVE-2025-43697
CVSS 7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data.
Affected Products:
Salesforce OmniStudio (DataMapper) – before Spring 2025
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Trusted Relationship
Valid Accounts
Application Layer Protocol: Web Protocols
Data from Information Repositories
Transfer Data to Cloud Account
Data Manipulation
Brute Force
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Third-Party Service Provider Due Diligence
Control ID: 12.8.2
NYDFS 23 NYCRR 500 – Third-Party Service Provider Security Policy
Control ID: 500.11
DORA (Digital Operational Resilience Act) – ICT Third-Party Risk Management
Control ID: Article 28
CISA Zero Trust Maturity Model 2.0 – Continuous Third-Party Risk Monitoring
Control ID: Pillar: Supply Chain / Asset Management
NIS2 Directive – Supply Chain Security Policies
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Automotive
Direct impact from Stellantis breach exposes customer data vulnerabilities in third-party integrations, requiring enhanced zero trust segmentation and encrypted traffic controls.
Computer Software/Engineering
Salesforce platform compromise demonstrates critical need for multicloud visibility, egress security controls, and threat detection in SaaS provider ecosystems.
Financial Services
Third-party data breaches threaten customer financial information, requiring strengthened vendor risk management and compliance with PCI/HIPAA encryption standards.
Manufacturing
Supply chain data exposure risks operational security, demanding east-west traffic monitoring and kubernetes security for industrial automation systems integration.
Sources
- Automaker giant Stellantis confirms data breach after Salesforce hackhttps://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/Verified
- Automaker giant Stellantis says customers’ personal data stolen during breachhttps://techcrunch.com/2025/09/22/automaker-giant-stellantis-says-customers-personal-data-stolen-during-breach/Verified
- Stellantis compromised by ShinyHunters’ Salesforce hackhttps://www.scworld.com/brief/stellantis-compromised-by-shinyhunters-salesforce-hackVerified
- Stellantis confirms data leak via Salesforcehttps://hackyourmom.com/en/novyny/stellantis-pidtverdyla-vytik-danyh-cherez-salesforce/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF controls such as Zero Trust Segmentation, egress policy enforcement, and multicloud visibility could have limited attacker movement, detected anomalies, and prevented unauthorized exfiltration. Distributed enforcement of segmentation and traffic monitoring across SaaS and cloud services would have constrained data access and signaled abnormal behaviors.
Control: Multicloud Visibility & Control
Mitigation: Suspicious access attempts would be quickly detected and alerted upon.
Control: Zero Trust Segmentation
Mitigation: Access to sensitive data would be restricted by least privilege segmentation.
Control: East-West Traffic Security
Mitigation: Lateral traversal would be detected and blocked.
Control: Threat Detection & Anomaly Response
Mitigation: Abnormal communication patterns and C2 channels are flagged in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data transfers to unapproved destinations are blocked or closely monitored.
Attack impact is limited by distributed, real-time alarm generation and containment.
Impact at a Glance
Affected Business Functions
- Customer Service Operations
Estimated downtime: N/A
Estimated loss: $5,000,000
Unauthorized access to customer contact information, including names, email addresses, and phone numbers. No financial or sensitive personal data was compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and role-based access controls for all third-party SaaS integrations.
- • Deploy egress filtering and DNS/FQDN-based policy enforcement to block unauthorized data exports.
- • Establish centralized visibility and anomaly detection across all cloud and SaaS environments for rapid threat identification.
- • Continuously monitor and limit east-west (internal) traffic between workloads, services, and external providers.
- • Implement real-time, distributed enforcement using cloud-native security fabric to autonomously respond to suspicious behaviors and contain breaches.



