Skip to content

JOBUZO

  • News
  • Indonesia
  • Toggle search form
Hacking group claims theft of 1 billion records from Salesforce customer databases

Hacking group claims theft of 1 billion records from Salesforce customer databases

Posted on 3 October 2025 By jobuzo

A notorious predominantly English-speaking hacking group has launched a website to extort its victims, threatening to release about a billion records stolen from companies who store their customers’ data in cloud databases hosted by Salesforce.

The loosely organized group, which has been known as Lapsus$, Scattered Spider and ShinyHunters, have published a dedicated data leak site on the dark web, called Scattered LAPSUS$ Hunters. 

The website, first spotted by threat intelligence researchers on Friday and seen by TechCrunch, aims to pressure victims into paying the hackers to avoid having their stolen data published online. 

“Contact us to regain control on data governance and prevent public disclosure of your data,” reads the site. “Do not be the next headline. All communications demand strict verification and will be handled with discretion.”

Over the last few weeks, the ShinyHunters gang allegedly hacked dozens of high-profile companies by breaking into their cloud-based databases hosted by Salesforce. 

Image Credits:TechCrunch (screenshot)

Insurance giant Allianz Life, Google, fashion conglomerate Kering, the airline Qantas, carmaking giant Stellantis, credit bureau TransUnion, and the employee management platform Workday, among several others, have confirmed their data was stolen in these mass hacks.

News :<div>12 weeks' jail for school IT support technician who took upskirt videos of teachers</div>

The hackers’ leak site lists several alleged victims, including FedEx, Hulu (owned by Disney), and Toyota Motors, none of which responded to a request for comment on Friday.

It’s not clear if the companies known to have been hacked but not listed on the hacking group’s leak site have paid a ransom to the hackers to prevent their data from being published. When reached by TechCrunch, a representative from ShinyHunters said, “there are numerous other companies that have not been listed,” but declined to say why.

At the top of the site, the hackers mention Salesforce and demand that the company negotiate a ransom, threatening that otherwise “all your customers [sic] data will be leaked.” The tone of the message suggests that Salesforce has not yet engaged with the hackers.

A spokesperson for Salesforce did not respond to TechCrunch’s outreach or questions about the breach.

For weeks, security researchers have speculated that the group, which has historically eschewed a public presence online, was planning to publish a data leak website to extort its victims. 

Historically, such websites have been associated with foreign, often Russian-speaking, ransomware gangs. In the last few years, these organized cybercrime groups have evolved from stealing, encrypting their victim’s data and then privately asking for a ransom, to simply threatening to publish the stolen data online unless they get paid. 

News :Migrant acquitted in first trial over US border military zones

Updated with comment from ShinyHunters.

Hacking group claims theft of 1 billion records from Salesforce customer databases


News

Post navigation

Previous Post: New deep tech fund Wave Function Ventures raises $15 million
Next Post: Apple removes ICEBlock from the App Store after Trump administration’s demand

Related Posts

Would Harry Jowsey Join 'The Traitors'? He Says...(Exclusive) Would Harry Jowsey Join ‘The Traitors’? He Says…(Exclusive) News
American Idol's Carrie Underwood Reacts to Criticism of How She Judges Contestants American Idol’s Carrie Underwood Reacts to Criticism of How She Judges Contestants News
Did Pope Leo find his voice in Africa? Or did the world finally hear him? Did Pope Leo find his voice in Africa? Or did the world finally hear him? News

Latest

  • When DWTS’ Alan Bersten Realized He, Emma Slater Could Be More Than Friends
  • OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks
  • What to expect from WWDC 2026: Siri’s highly anticipated revamp and Apple Intelligence updates
  • U.S. job market posts surprising increase in May, but prospects unclear amid price hikes
  • ‘World crying for peace’: Pope Leo kicks off Spain trip with fiery plea to leaders
  • Drone strike on central Sudan market kills 11: rights group
  • U.S. attacks Iranian sites after Iran launches drones, in latest Gulf flare-up
  • Baby killed in West Bank after Israeli troops open fire on a car, Palestinian health officials say
  • West Ham joint-chairman quits ahead of ‘historic allegations’ to be made against him
  • Sherpa believed to be dead crawls back to Everest Base Camp after nearly a week missing

Copyright © 2025 JOBUZO. Disclaimers | Privacy Policies

Powered by PressBook Masonry Blogs