Trinity of Chaos Leaks Data from 39 Companies — Google, Cisco Among Targets
A newly formed ransomware group, the Trinity of Chaos, has launched a data leak site (DLS) on the TOR network, revealing the stolen records of 39 major corporations, including Google Adsense, CISCO, Toyota, FedEx, and Disney/Hulu.
A newly formed ransomware group, the Trinity of Chaos, has launched a data leak site (DLS) on the TOR network, revealing the stolen records of 39 major corporations, including Google Adsense, CISCO, Toyota, FedEx, and Disney/Hulu.
This alliance includes threat actors from Lapsus$, Scattered Spider, and ShinyHunters, indicating a shift toward traditional ransomware extortion methods, raising concerns across various industries.
The Trinity of Chaos first emerged by merging the reputations and technical skills of these notorious groups. While no new intrusions have been reported, the group released previously unavailable data samples from past breaches, displaying proof of the exfiltrated records.
In one highlighted case, the group threatened Salesforce after allegedly exploiting its instances via stolen OAuth tokens linked to Salesloft’s Drift AI chat integration. Salesforce downplayed these claims but acknowledged potential compromises of customer environments. The threat actors claimed to have sought negotiations with the company to avoid disclosure, citing GDPR obligations and warning of “criminal negligence charges” if regulators were informed.
Marketing materials posted with the DLS emphasize the group's expertise in high-value corporate data acquisition and strategic breach operations, citing their experience across sectors such as automotive, financial, insurance, technology, telecommunications, and ISPs.
The group claims operations dating back to 2019, highlighting the sophistication of its long-term intrusion campaigns. Past victims whose data samples were shared include Vietnam Airlines and the National Credit Information Center of Vietnam, with over 160 million records exposed.
During this period, the group, operating under the alias "1973cn," may have also been involved in attacks at Noi Bai Airport and Tan Son Nhat Airport.
The Trinity of Chaos first emerged by merging the reputations and technical skills of these notorious groups.
The alliance has claimed responsibility for breaches of Aeroméxico in July 2025 and Jaguar Land Rover, disrupting vehicle production and retail activities in September. Resecurity’s threat intelligence team validated these breaches and provided technical indicators for detection and response.
Corporations and Negotiation Deadlines
On October 3, 2025, the DLS listed 39 organizations required to enter ransom negotiations by October 10 to prevent further data publication. Affected entities include global brands such as UPS, Home Depot, Marriott, McDonald’s, Adidas, Cartier, Chanel, and IKEA. Stellantis confirmed a breach affecting its North American customer data in September, attributing it to a third-party provider compromise.
Victims face potential regulatory inquiries, legal actions, and reputational damage, particularly in regions with strict privacy laws. Google's corporate Salesforce instance was reportedly compromised in early June, impacting Google AdWords users and digital media partners worldwide, although Google did not specify the affected service initially.
In Cisco’s case, leaked Salesforce records revealed internal communications and customer information, including data on law enforcement and military personnel from agencies such as the FBI, DHS, and NASA, as well as international defense organizations.
Actors provided an official contact email previously circulated on Dark Web forums and Telegram channels, instructing victims to use corporate email addresses to verify identity and discuss ransom terms.
Alongside the DLS launch, the group reactivated its Telegram presence under “SLSH 6.0 Part 3,” promising to expand the leak site after October 10 to include over 1.5 billion records from 760 companies if demands are unmet.
Cybersecurity experts warn that the publication of these records could fuel large-scale social engineering, phishing campaigns, and identity theft.
The leaked data sets, heavily populated with personally identifiable information (PII) but lacking passwords, provide significant opportunities for malicious actors seeking to craft targeted exploits or AI-driven attacks.
The FBI’s flash warning on the exploitation of Salesforce and Salesloft integrations underscores the urgency for organizations to audit their cloud environments and implement robust monitoring.
Industry analysts also note the unfortunate timing of the DLS debut during the U.S. government shutdown, potentially hindering federal agencies’ ability to respond to cybercrime.
Organizations are working to contain the fallout, engage forensic teams, and bolster defenses against further DDoS or extortion attempts. As the Trinity of Chaos alliance signals its intention not to re-ransom cooperative victims, the coming weeks will test the measures major corporations will take to safeguard sensitive data and preserve customer trust.
Based on reporting by GBHackers.
