New Hacker Alliance Trinity of Chaos Leaked 39 Companies Data Including Google, CISCO and Others
The emergence of the ransomware group Trinity of Chaos has significantly impacted the cybersecurity landscape. This group has launched a data leak site containing sensitive information from 39 major corporations. Trinity of Chaos is believed to comprise…
The emergence of the ransomware group Trinity of Chaos has significantly impacted the cybersecurity landscape. This group has launched a data leak site containing sensitive information from 39 major corporations. Trinity of Chaos is believed to comprise members from known groups such as Lapsus$, Scattered Spider, and ShinyHunters, indicating a notable evolution in cybercriminal organization and capabilities.
The group operates as a hybrid threat actor, combining ransomware tactics with data extortion methodologies. They have established a Data Leak Site (DLS) on the TOR network to showcase their operational sophistication. Instead of announcing new attacks, they reveal previously undisclosed breaches, sharing data samples to validate their claims and apply pressure on victims to comply with their demands.
This collective has issued ultimatums to affected companies following their previous exploitation of Salesforce instances. They threaten to release large amounts of data if their negotiation demands are not met. Their operations reportedly began as early as 2019, showcasing extensive experience and a well-established infrastructure.
The scope of the Trinity of Chaos breach includes prominent technology companies such as Google and Cisco, alongside other major corporations like Toyota Motor Corporation, FedEx, Disney/Hulu, Home Depot, Marriott, and McDonald's. The group has set an October 10 deadline for negotiations, employing pressure tactics typical of ransomware operations.
The emergence of the ransomware group Trinity of Chaos has significantly impacted the cybersecurity landscape.
Exploitation of Salesforce Infrastructure
Trinity of Chaos has demonstrated sophisticated attack methods focused on exploiting Salesforce instances through compromised Salesloft Drift AI chat integration. The leaked data primarily contains personally identifiable information (PII), indicating that the stolen records originate from targeted Salesforce environments.
The group employs vishing attacks and steals OAuth tokens for Salesloft's Drift AI chat integration, highlighting a targeted approach to exploiting cloud platforms. This technique has prompted the Federal Bureau of Investigation to issue a warning to monitor potential Salesforce environment infiltrations.
The stolen data includes sensitive customer information, internal communications, loyalty program details, and extensive activity histories, providing the group with intelligence for future operations. The collective claims to possess over 1.5 billion records from 760 companies, showcasing their systematic approach to data aggregation and monetization.
Based on reporting by Cyber Security News.
