The ShinyHunters extortion group says it has stolen over 1.5 billion Salesforce records from 760 companies by exploiting compromised Drift OAuth tokens linked to Salesloft.
For the past year, attackers have used social engineering and malicious OAuth apps to infiltrate Salesforce environments, exfiltrating data and extorting victims with ransom demands to prevent leaks. The campaigns are tied to groups operating under the names ShinyHunters, Scattered Spider, and Lapsus$, now calling themselves “Scattered Lapsus$ Hunters.” Google tracks them as UNC6040 and UNC6395.
In March, one actor reportedly breached Salesloft’s GitHub repo, locating secrets—including OAuth tokens for Drift and Drift Email—using the TruffleHog tool. These platforms link Drift AI chat and email services with Salesforce, enabling attackers to extract massive amounts of CRM data.
According to ShinyHunters, the stolen data spans Salesforce objects including approximately 250 million from the Account, 579 million from Contact, 171 million from Opportunity, 60 million from User, and about 459 million records from the Case Salesforce tables.
As evidence, the group shared a file listing Salesloft’s breached source code folders.
Google Mandiant reports that attackers searched stolen Case data for secrets such as AWS keys, Snowflake tokens, and other credentials, allowing further intrusions. Victims allegedly include Google, Cloudflare, Palo Alto Networks, Zscaler, Tenable, CyberArk, Elastic, Qualys, Nutanix, Proofpoint, BeyondTrust, Rubrik, Cato Networks, and others.
The FBI recently issued an advisory on UNC6040/6395, warning of ongoing campaigns and sharing IOCs.
Meanwhile, threat actors claiming affiliation with Scattered Spider announced on Telegram they were “going dark,” boasting of breaches at Google’s Law Enforcement Request System (LERS) and the FBI’s eCheck platform. Google later confirmed only that a fraudulent LERS account had been created, but no data was accessed.
Salesforce urges customers to mitigate risks by enforcing multi-factor authentication (MFA), applying the principle of least privilege, and closely managing connected applications.














Comments