Hackers claim 1 billion record mega-breach in Salesforce attack

Hackers claim 1 billion record mega-breach in Salesforce attack
Experts say the cyber-criminal coalition's latest threat, which names Alllianz Life and other giant firms, marks a tactical shift from traditional ransomware to public extortion.
OCT 03, 2025

A sprawling coalition of hackers styling themselves as Scattered LAPSUS$ Hunters has claimed responsibility for one of the largest alleged data thefts in recent years, asserting that nearly one billion records have been siphoned from companies relying on Salesforce, the dominant US cloud software provider.

The group’s revelation, paired with the launch of a dark-web extortion portal, takes aim at multinational corporations and financial institutions that depend heavily on Salesforce to run customer operations.

Salesforce, which provides cloud-based customer relationship management tools to retailers, banks, insurers and wealth managers, has rejected the suggestion that its own platform was breached.

“At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology,” a company spokesperson told TechCrunch.

A coordinated campaign

The self-branded “hunters” are linked to familiar names in cybercrime – ShinyHunters, Scattered Spider and the remnants of the Lapsus$ collective. Security analysts say the group has shifted away from traditional ransomware and toward public extortion: rather than encrypting systems, they threaten to release data unless companies comply with ransom demands.

The attackers’ tactics rely less on exploiting coding flaws and more on human manipulation. In recent months, researchers say, the hackers used “vishing” – voice-based phishing calls – convincing employees to provide access credentials or authorize rogue applications.

In some cases, investigators at Google’s Threat Intelligence Group observed employees tricked into downloading a doctored version of Salesforce’s own Data Loader, a tool designed for bulk data imports.

High-profile victims

The dark-web portal created by the group lists dozens of household names, from Allianz Life – which disclosed a breach affecting nearly 1.5 million persons to the Office of the Maine Attorney General this week – to Google, Qantas, Toyota and Workday.

Extortion notices reviewed by multiple cybersecurity outlets cite companies across sectors – retail, airlines, automotive, finance – underscoring the reach of the campaign.

Brands from FedEx and Home Depot to McDonald’s, Marriott, Cartier, and Disney’s Hulu unit also appear on the site, though several have declined public comment.

Within the wealth space, Salesforce's reach through its Salesforce Financial Services Cloud and Salesforce Sales Cloud systems accounted for just over 10% of market share among advisors in the CRM space, according to the most recent T3 Advisortech survey this year.  

The hackers claim to hold personal and corporate records numbering in the billions. Samples of data tied to at least 39 enterprises have been released, with the threat of full disclosure if no settlement is reached by October 10.

In a post aimed directly at Salesforce, the group demanded payment to halt publication of client data, warning that otherwise “all your customers data will be leaked.”

A regulatory and legal cloud

Beyond the immediate ransom threats, the hackers have suggested they may assist in legal action against Salesforce itself, citing obligations under Europe’s General Data Protection Regulation.

“Your organisation can prevent the release of this data, regain control over the situation and all operations remain stable as always,” the group wrote in one notice, while hinting that noncompliance could lead to civil exposure for Salesforce.

For financial services providers – particularly US wealth managers and insurers that have adopted Salesforce Financial Services Cloud or overlays such as Practifi and Salentica – the stakes are acute.

Firms like RBC Wealth Management, US Bank, and Pacific Life have publicly described using Salesforce to centralize client data, meaning a breach of customer instances could spill sensitive investment and planning information into criminal hands.

A second front: AI vulnerabilities

Compounding unease, Salesforce only days earlier disclosed a separate issue: a flaw dubbed “ForcedLeak” in its Agentforce AI platform. That bug, now patched, could have allowed attackers to exfiltrate CRM data through maliciously crafted inputs.

Though unrelated to the current extortion campaign, the incident highlights the widening attack surface as financial firms increasingly experiment with AI agents layered atop their CRM systems.

Latest News

Estate planning gaps leave families facing steep probate costs, new report finds
Estate planning gaps leave families facing steep probate costs, new report finds

With trillions of dollars set to change hands, new data suggests probate costs and delays are becoming a bigger factor in estate planning decisions.

Orion, RFG moves take aim at onboarding and transition speed
Orion, RFG moves take aim at onboarding and transition speed

Orion and RFG Advisory tackle account-opening delays with new updates as custodial integrations reshape how fast advisors can move client assets.

Corient adds $5B New York multi-family office Seven Bridges
Corient adds $5B New York multi-family office Seven Bridges

The deal extends the acquisitive mega-RIA's rapid 2026 expansion as industry consolidation hits record levels nationwide

Navigating the straight
Navigating the straight

As recent Middle East tensions put the Strait of Hormuz back in focus, a structured process with purpose can help protect investors against their natural self-sabotaging tendencies in choppy markets.

Commonwealth-affiliated Longwave hires from LPL-affiliated firm amid Pacific Northwest expansion
Commonwealth-affiliated Longwave hires from LPL-affiliated firm amid Pacific Northwest expansion

ESG-focused Longwave Financial, approaching $1B AUM, acquired Seattle-based MG Financial and hired a client services manager from an LPL-affiliated firm.

SPONSORED Direct indexing webinar targets tax-loss harvesting amid market swings

Northern Trust’s Ken Lassner shows advisors how to convert volatility into after-tax portfolio gains

SPONSORED Who builds the income when the pension disappears?

Dan Biagini of American Equity says the steady decline of pensions, longer lifespans and a reset in interest rates are rewriting how advisors build retirement income