Hacking group claims theft of 1 billion records from Salesforce customer databases
salesforcesalesforce(US:CRM) TechCrunch·2025-10-03 13:17

Core Points - A hacking group has launched a website to extort victims, threatening to release approximately one billion records stolen from companies using Salesforce cloud databases [1][2] - The group, known as Lapsus$, Scattered Spider, and ShinyHunters, aims to pressure victims into paying to avoid public disclosure of their stolen data [2][3] - High-profile companies such as Allianz Life, Google, Kering, Qantas, Stellantis, TransUnion, and Workday have confirmed data theft, with additional victims including FedEx, Hulu, and Toyota Motors [5][6] Company Impact - The hackers have specifically targeted Salesforce, demanding ransom negotiations and threatening to leak customer data if not engaged [7] - The lack of response from Salesforce regarding the breach raises concerns about the company's engagement with the hackers and its data security measures [7][8] - The emergence of this extortion tactic reflects a shift in cybercrime, moving from traditional ransomware methods to public threats of data publication [9]