Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Launch Leak Portal to Publish Data Stolen from Salesforce Instances

A hacker group known as "Scattered Lapsus$ Hunters" has launched an extortionware portal targeting victims for the delisting and purported deletion of stolen data. This group has focused primarily on Salesforce datasets, leveraging intrusions achieved…

A hacker group known as "Scattered Lapsus$ Hunters" has launched an extortionware portal targeting victims for the delisting and purported deletion of stolen data. This group has focused primarily on Salesforce datasets, leveraging intrusions achieved through social engineering, OAuth abuse, and supply chain compromise.

The campaign has evolved from initial voice-phishing attacks that exploited Salesforce integrations to a broader data-theft operation involving Salesloft's Drift ecosystem. Attackers utilized OAuth tokens to gain broad API access across multiple platforms.

Late 2024: Attackers used social engineering to add malicious integrations to Salesforce, granting API access for data exfiltration. The FBI warned of campaigns targeting Salesforce data from major enterprises. March–June 2025: Intruders compromised Salesloft’s GitHub environment, manipulated repositories, and accessed the Drift application's AWS environment. They exploited OAuth tokens to access Salesforce at scale. June–August 2025: Google published an advisory on the malicious Salesforce integrations. OAuth tokens were actively used to extract Salesforce data from victims. August 20–26, 2025: Salesloft disclosed the Drift incident, and Google released a technical analysis of the data-theft mechanics. September 2025: The group announced a brief operational pause, yet activity linked to Salesforce data persisted. October 3, 2025: The group launched a TOR-hosted extortion portal listing alleged Salesforce customers and exfiltrated data volumes, with an October 10 deadline for payment.

Extortionware Portal and Ramifications

The leak site catalogs organizations and the volume of Salesforce data allegedly stolen, capitalizing on the critical nature of customer and deal metadata. This highlights the risks associated with broad third-party integration and flexible APIs.

Attackers utilized OAuth tokens to gain broad API access across multiple platforms.
Noah Redmond · Thehackingpost

The incident underscores the importance of integration governance in enterprise data defense. Practices such as OAuth scope minimization, least privilege, token rotation, and continuous monitoring are essential controls.

Salesforce has indicated no platform compromise or vulnerability exploitation. The impact is attributed to social engineering, OAuth token abuse, and supply chain weaknesses, rather than a core Salesforce flaw.

Advertisement

The platform's extensive data aggregation and exposure via integrations centralize its role in the incident's impact.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories