This massive breach has impacted dozens of organizations, including Google, Cloudflare, and several major cybersecurity companies.

A spokesperson for the cybercriminal group ShinyHunters detailed to Bleeping Computer on September 17, 2025, the massive hack of Salesforce, the customer relationship management (CRM) platform. Initiated in early 2025, the cyberattack exploited compromised OAuth tokens used by Salesloft Drift, an AI-powered chatbot integrated into the CRM.

This entry point allowed attackers to steal large volumes of data from Salesforce client companies between August 8 and August 18, 2025. Among the victims are Google, Cloudflare, and cybersecurity companies CyberArk, Proofpoint, and Palo Alto Networks, as well as Zscaler, Tenable, Elastic, JFrog, Nutanix, Qualys, Rubrik, and Cato Networks.

The cybercriminal consortium Scattered Lapsus$ Hunters — which brings together the English-speaking groups ShinyHunters, Scattered Spider, and Lapsus$ — has claimed responsibility for the breach. According to the ShinyHunters spokesperson, the operation led to the theft of 1.5 billion Salesforce records.

Google Threat Intelligence (GTI) attributed the attack to two groups it labeled UNC6040 and UNC6395. The FBI had issued an alert regarding these groups in early September 2025.

On September 18, 2025, fourteen cybercriminal groups — including Scattered Spider and Lapsus$ — announced they were suspending communications on Telegram, suggesting a pause in their activities. On the same day, British police revealed the arrest of two teenagers suspected of being members of Scattered Spider.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.