Hackers Launch Leak Portal to Publish Data Stolen from Salesforce Instances
A hacker group known as "Scattered Lapsus$ Hunters" has launched an extortionware portal targeting victims for the delisting and purported deletion of stolen data. This group has focused primarily on Salesforce datasets, leveraging intrusions achieved…
A hacker group known as "Scattered Lapsus$ Hunters" has launched an extortionware portal targeting victims for the delisting and purported deletion of stolen data. This group has focused primarily on Salesforce datasets, leveraging intrusions achieved through social engineering, OAuth abuse, and supply chain compromise.
The campaign has evolved from initial voice-phishing attacks that exploited Salesforce integrations to a broader data-theft operation involving Salesloft's Drift ecosystem. Attackers utilized OAuth tokens to gain broad API access across multiple platforms.
Late 2024: Attackers used social engineering to add malicious integrations to Salesforce, granting API access for data exfiltration. The FBI warned of campaigns targeting Salesforce data from major enterprises. March–June 2025: Intruders compromised Salesloft’s GitHub environment, manipulated repositories, and accessed the Drift application's AWS environment. They exploited OAuth tokens to access Salesforce at scale. June–August 2025: Google published an advisory on the malicious Salesforce integrations. OAuth tokens were actively used to extract Salesforce data from victims. August 20–26, 2025: Salesloft disclosed the Drift incident, and Google released a technical analysis of the data-theft mechanics. September 2025: The group announced a brief operational pause, yet activity linked to Salesforce data persisted. October 3, 2025: The group launched a TOR-hosted extortion portal listing alleged Salesforce customers and exfiltrated data volumes, with an October 10 deadline for payment.
Extortionware Portal and Ramifications
The leak site catalogs organizations and the volume of Salesforce data allegedly stolen, capitalizing on the critical nature of customer and deal metadata. This highlights the risks associated with broad third-party integration and flexible APIs.
Attackers utilized OAuth tokens to gain broad API access across multiple platforms.
The incident underscores the importance of integration governance in enterprise data defense. Practices such as OAuth scope minimization, least privilege, token rotation, and continuous monitoring are essential controls.
Salesforce has indicated no platform compromise or vulnerability exploitation. The impact is attributed to social engineering, OAuth token abuse, and supply chain weaknesses, rather than a core Salesforce flaw.
The platform's extensive data aggregation and exposure via integrations centralize its role in the incident's impact.
Based on reporting by GBHackers.
