Scattered Lapsus$ Hunters Launched a New Leak Site to Release Data Stolen from Salesforce Instances
A cybercriminal collective identified as Scattered Lapsus$ Hunters has initiated a leak site dedicated to publishing data exfiltrated from Salesforce instances. This development marks a significant advancement in their ransomware-as-a-service operations,…
A cybercriminal collective identified as Scattered Lapsus$ Hunters has initiated a leak site dedicated to publishing data exfiltrated from Salesforce instances. This development marks a significant advancement in their ransomware-as-a-service operations, targeting one of the most widely used customer relationship management platforms globally.
The group comprises well-known threat actors such as ShinyHunters, Scattered Spider, and Lapsus$. Their collaboration represents a consolidation of cybercriminal expertise, focusing on high-value targets to maximize potential ransom payments.
The launch of their extortionware portal via the TOR Onion network lists affected Salesforce customers, detailing the extent of data allegedly stolen. This action underscores their understanding of the platform's critical business value and the sensitivity of customer data it houses.
According to UpGuard analysts, the group threatens public exposure of the stolen data unless payment demands are met, with an initial deadline set for Tue, Oct 10, 2025. This marks a significant milestone in the commercialization of data theft, leveraging stolen information for systematic extortion.
The group comprises well-known threat actors such as ShinyHunters, Scattered Spider, and Lapsus$.
The attack campaign involved sophisticated technical execution, beginning with social engineering tactics that exploited human vulnerabilities. The group employed vishing techniques, impersonating IT support personnel to install malicious Salesforce integrations, thereby gaining API-level access to target systems.
OAuth Token Exploitation and Persistence Mechanisms
The attackers executed a sophisticated attack vector by compromising Salesloft's GitHub repositories and exploiting valid OAuth integration tokens to maintain persistent access to Salesforce environments. Following initial access to Salesloft’s corporate GitHub account, likely through social engineering, they downloaded repository contents, created unauthorized user accounts, and established custom workflows to facilitate continuous access.
The attackers discovered embedded AWS credentials within the compromised repositories, enabling access to Salesloft Drift's cloud infrastructure. They identified and exfiltrated OAuth tokens belonging to Salesloft Drift clients, repurposing legitimate credentials for widespread data theft.
This method highlights how attackers can exploit interconnected SaaS platforms for lateral movement across multiple organizations via a single compromised integration provider. The persistence mechanism utilized the OAuth authorization framework, complicating detection for security teams, as malicious activity was disguised as legitimate API calls.
By using valid integration tokens, the attackers could maintain access despite potential discovery and remediation of initial entry points, underscoring the importance of comprehensive token management and monitoring in enterprise environments.
Based on reporting by Cyber Security News.
