the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Hackers threaten 1B records from Salesforce breach

ArticlesNewsletters
ArticlesNewsletters
cybersecurity

Hackers threaten 1B records from Salesforce breach

English-speaking group launches extortion site targeting major companies' data

by The Tech Buzz

PUBLISHED: Fri, Oct 3, 2025, 1:44 PM UTC | UPDATED: Thu, Sep 3, 2026, 4:58 PM UTC

Add as a preferred source on Google
Hackers threaten 1B records from Salesforce breach

A notorious hacking collective known as ShinyHunters has launched a dark web extortion site, threatening to release roughly one billion customer records stolen from companies using Salesforce's cloud databases. The brazen move marks a dangerous escalation in enterprise cybersecurity threats, with Fortune 500 companies like FedEx, Qantas, and TransUnion caught in the crosshairs.

The cybersecurity landscape just got significantly more dangerous. A loosely organized English-speaking hacking group that's operated under multiple aliases - Lapsus$, Scattered Spider, and ShinyHunters - has taken their extortion game public with a dedicated dark web leak site called 'Scattered LAPSUS$ Hunters.'

The site, discovered by threat intelligence researchers Friday and verified by TechCrunch, reads like a corporate negotiation gone rogue: 'Contact us to regain control on data governance and prevent public disclosure of your data. Do not be the next headline. All communications demand strict verification and will be handled with discretion.'

What makes this particularly alarming is the scope. Over recent weeks, the group has systematically breached dozens of high-profile companies by exploiting their Salesforce cloud database configurations. The victim list reads like a Fortune 500 directory: insurance giant Allianz Life, tech behemoth Google, luxury conglomerate Kering, airline Qantas, automaker Stellantis, credit bureau TransUnion, and HR platform Workday.

But the hackers aren't stopping there. Their leak site also names FedEx, Hulu (owned by Disney), and Toyota Motors as additional targets - none of which responded to requests for comment Friday.

Advertisement

The most brazen element? The hackers are directly targeting Salesforce itself. At the top of their extortion site, they demand the cloud giant negotiate a ransom, threatening that otherwise 'all your customers data will be leaked.' The aggressive tone suggests Salesforce hasn't engaged with the group's demands.

Salesforce representatives didn't respond to multiple requests for comment about the breach or the hackers' ultimatum.

This represents a fundamental shift in cybercrime tactics. Historically, such public extortion sites were the domain of Russian-speaking ransomware cartels who operated in the shadows. But this English-speaking group is borrowing those playbook pages while targeting the enterprise cloud infrastructure that powers modern business.

Security researchers have been tracking this evolution for weeks. The ShinyHunters collective, which previously maintained a low profile, appears to have embraced the public pressure model that's proven effective for traditional ransomware operations. Instead of just encrypting data and demanding payment, they're threatening public exposure - a nuclear option in an era where data breaches can topple stock prices and trigger regulatory investigations.

What's particularly concerning is the targeting methodology. Rather than going after individual companies, the group has focused on Salesforce's cloud infrastructure, creating a multiplier effect where one successful breach impacts dozens of enterprise customers simultaneously.

Advertisement

The billion-record claim, if accurate, would rank among the largest data breaches in corporate history. For context, the 2017 Equifax breach exposed 147 million records, while the 2019 Capital One incident affected 100 million customers.

Several companies on the confirmed victim list have already disclosed the breaches to regulators and customers, but the emergence of this extortion site raises questions about which organizations might have quietly paid ransoms to avoid public disclosure.

The timing couldn't be worse for enterprise cloud security. As companies increasingly migrate sensitive operations to platforms like Salesforce, the attack surface expands exponentially. One misconfigured database or compromised credential can expose millions of customer records across multiple organizations.

This isn't just another data breach - it's a fundamental challenge to the enterprise cloud model. By targeting the infrastructure provider rather than individual companies, these hackers have found a way to maximize impact with minimal effort. The question now isn't whether more breaches will follow, but whether cloud providers like Salesforce can shore up defenses fast enough to prevent copycats. For enterprise customers, the message is clear: your data security is only as strong as your cloud provider's weakest link.

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

ShinyHunters hacking group launched an extortion site threatening to release 1 billion customer records stolen from Salesforce cloud databases. The breach affects major companies including Google, Qantas, TransUnion, and FedEx through compromised Salesforce configurations.

Hackers claim to have stolen approximately 1 billion customer records from companies using Salesforce cloud databases. If accurate, this would rank among the largest corporate data breaches in history, exceeding the 2017 Equifax breach of 147 million records.

Confirmed victims include Google, Qantas, TransUnion, Stellantis, Allianz Life, Kering, and Workday. Additional targets named by hackers include FedEx, Hulu (Disney), and Toyota Motors. The breach exploited Salesforce cloud database configurations across Fortune 500 companies.

It's a dark web leak site launched by ShinyHunters demanding ransom payments to prevent public data disclosure. The site directly threatens Salesforce, warning 'all your customers data will be leaked' unless the company negotiates with the hackers.

The ShinyHunters group systematically exploited Salesforce cloud database configurations rather than targeting individual companies. This multiplier effect allowed one successful infrastructure breach to impact dozens of enterprise customers simultaneously through misconfigured databases or compromised credentials.

Unlike traditional ransomware that encrypts data, this English-speaking group uses public extortion threatening data exposure. They target cloud infrastructure providers rather than individual companies, creating massive multiplier effects where one breach impacts multiple Fortune 500 enterprises.

More in cybersecurity

How To Prevent Account Takeover?

How To Prevent Account Takeover?

Coupang CEO Resigns After 34M Customer Data Breach

Coupang CEO Resigns After 34M Customer Data Breach

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes Customer Info in App Config Error

Petco Data Breach Exposes Customer Info in App Config Error

Marquis Ransomware Attack Hits 400K+ Bank Customers

Marquis Ransomware Attack Hits 400K+ Bank Customers

Okta beats Q3 earnings as AI agent push drives growth

Okta beats Q3 earnings as AI agent push drives growth

More Articles

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Dec 2

Coupang Data Breach Hits 34M Users in Months-Long Attack

Coupang Data Breach Hits 34M Users in Months-Long Attack

Dec 1

London Councils Hit by Major Cyberattack, Emergency Plans Activated

London Councils Hit by Major Cyberattack, Emergency Plans Activated

Nov 26

Tyler Technologies jury system bug exposed juror data across US

Tyler Technologies jury system bug exposed juror data across US

Nov 26

Major Banks Assess Data Theft After SitusAMC Breach

Major Banks Assess Data Theft After SitusAMC Breach

Nov 24

Corporate America ditches passwords as 92% of CISOs go passwordless

Corporate America ditches passwords as 92% of CISOs go passwordless

Nov 23