Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Scattered Lapsus$ Hunters Launched a New Leak Site to Release Data Stolen from Salesforce Instances

A cybercriminal collective identified as Scattered Lapsus$ Hunters has initiated a leak site dedicated to publishing data exfiltrated from Salesforce instances. This development marks a significant advancement in their ransomware-as-a-service operations,…

A cybercriminal collective identified as Scattered Lapsus$ Hunters has initiated a leak site dedicated to publishing data exfiltrated from Salesforce instances. This development marks a significant advancement in their ransomware-as-a-service operations, targeting one of the most widely used customer relationship management platforms globally.

The group comprises well-known threat actors such as ShinyHunters, Scattered Spider, and Lapsus$. Their collaboration represents a consolidation of cybercriminal expertise, focusing on high-value targets to maximize potential ransom payments.

The launch of their extortionware portal via the TOR Onion network lists affected Salesforce customers, detailing the extent of data allegedly stolen. This action underscores their understanding of the platform's critical business value and the sensitivity of customer data it houses.

According to UpGuard analysts, the group threatens public exposure of the stolen data unless payment demands are met, with an initial deadline set for Tue, Oct 10, 2025. This marks a significant milestone in the commercialization of data theft, leveraging stolen information for systematic extortion.

The group comprises well-known threat actors such as ShinyHunters, Scattered Spider, and Lapsus$.
Nathan Cole · Thehackingpost

The attack campaign involved sophisticated technical execution, beginning with social engineering tactics that exploited human vulnerabilities. The group employed vishing techniques, impersonating IT support personnel to install malicious Salesforce integrations, thereby gaining API-level access to target systems.

OAuth Token Exploitation and Persistence Mechanisms

The attackers executed a sophisticated attack vector by compromising Salesloft's GitHub repositories and exploiting valid OAuth integration tokens to maintain persistent access to Salesforce environments. Following initial access to Salesloft’s corporate GitHub account, likely through social engineering, they downloaded repository contents, created unauthorized user accounts, and established custom workflows to facilitate continuous access.

The attackers discovered embedded AWS credentials within the compromised repositories, enabling access to Salesloft Drift's cloud infrastructure. They identified and exfiltrated OAuth tokens belonging to Salesloft Drift clients, repurposing legitimate credentials for widespread data theft.

Advertisement

This method highlights how attackers can exploit interconnected SaaS platforms for lateral movement across multiple organizations via a single compromised integration provider. The persistence mechanism utilized the OAuth authorization framework, complicating detection for security teams, as malicious activity was disguised as legitimate API calls.

By using valid integration tokens, the attackers could maintain access despite potential discovery and remediation of initial entry points, underscoring the importance of comprehensive token management and monitoring in enterprise environments.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories