{"id":5887,"date":"2025-08-05T10:03:36","date_gmt":"2025-08-05T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/05\/fashion-giant-chanel-hacked-in-wave-of-salesforce-attacks\/"},"modified":"2025-08-05T10:03:36","modified_gmt":"2025-08-05T10:03:36","slug":"fashion-giant-chanel-hacked-in-wave-of-salesforce-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/05\/fashion-giant-chanel-hacked-in-wave-of-salesforce-attacks\/","title":{"rendered":"Fashion Giant Chanel Hacked in Wave of Salesforce Attacks"},"content":{"rendered":"<p>    Fashion Giant Chanel Hacked in Wave of Salesforce Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>French luxury fashion house Chanel has become the latest victim in a sophisticated cybercrime campaign targeting major corporations through their Salesforce customer relationship management systems.<\/p>\n<p>The company confirmed on July 25, 2025, that unauthorized threat actors had breached a database containing personal information of U.S. customers who contacted their client care center.<\/p>\n<p>The breach exposed limited but sensitive customer data, including names, email addresses, mailing addresses, and phone numbers of individuals who had contacted Chanel\u2019s U.S. client care center.<\/p>\n<p>Importantly, no financial information, payment data, or internal operational systems were compromised in the attack, according to the WWD <a href=\"https:\/\/wwd.com\/business-news\/retail\/chanel-data-break-u-s-client-database-1238026491\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a>.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizwRzs9XSHOO-ijWZZ7btjPTSoKGK4TH_GX6QCliopn6iREu-iVn8St87by6Jxp81cC2aAu87E4zQcecOUd0XXXhNOMHhR0BdfWHekgoG4EsmXmGyAJMjqV1C6EKf21rC8Fouxrn5eVS8Co-XWG7FTgveq2jPzuAdIJvvVlqM1wqtQ4Xha2LpDYLszaT3w\/s16000\/shiny%2520hunters%2520.webp?ssl=1\" alt=\"Fashion Giant Chanel Hacked - Customers Personal Data Exposed\"><figcaption class=\"wp-element-caption\">Timeline of Major Companies Affected by ShinyHunters Salesforce Campaign (May-July 2025)<\/figcaption><\/figure>\n<p>The Chanel breach represents just one incident in a sweeping cybercrime wave orchestrated by the notorious ShinyHunters extortion group, which has been systematically targeting Salesforce instances across multiple industries since early 2025.<\/p>\n<p>The campaign has affected an unprecedented roster of major brands, including Qantas, <a href=\"https:\/\/cybersecuritynews.com\/allianz-life-insurance-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Allianz Life<\/a>, LVMH subsidiaries <a href=\"https:\/\/cybersecuritynews.com\/louis-vuitton-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">Louis Vuitton<\/a> and <a href=\"https:\/\/cybersecuritynews.com\/customers-personal-financial-data-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\">Dior<\/a>, Tiffany &amp; Co., and Adidas.<\/p>\n<p>This coordinated assault demonstrates the evolving threat landscape where cybercriminals are increasingly focusing on cloud-based customer relationship management platforms rather than attempting to breach companies\u2019 primary security defenses directly.<\/p>\n<p>The attacks have spanned multiple countries, affecting customers in the United States, the United Kingdom, South Korea, Turkey, Italy, and Sweden.<\/p>\n<p>The ShinyHunters group, tracked by Google\u2019s Threat Intelligence Group as UNC6040, has employed highly sophisticated <a href=\"https:\/\/cybersecuritynews.com\/tag\/and-voice-phishing\/\" target=\"_blank\" rel=\"noreferrer noopener\">voice phishing<\/a> (vishing) techniques to compromise Salesforce environments.<\/p>\n<p>The attackers impersonate IT support personnel in convincing telephone calls to employees, typically targeting English-speaking staff at multinational corporations.<\/p>\n<p>During these <a href=\"https:\/\/cybersecuritynews.com\/tag\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> attacks, victims are manipulated into visiting Salesforce\u2019s connected app setup page and authorizing a malicious version of the legitimate Data Loader application.<\/p>\n<p>The fraudulent app is often rebranded under names like \u201cMy Ticket Portal\u201d to avoid suspicion while granting attackers extensive access to query and exfiltrate sensitive customer data directly from Salesforce environments.<\/p>\n<p><strong>The attack methodology follows a consistent pattern:<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>Attackers conduct reconnaissance using automated phone systems to gather internal company information.<\/li>\n<li>They then engage targets directly, posing as internal IT support staff.<\/li>\n<li>Victims are guided through seemingly legitimate processes to install the malicious connected app.<\/li>\n<li>Once authorized, the app enables bulk data extraction using Salesforce\u2019s own Data Loader functionality.<\/li>\n<li>Attackers often move laterally to compromise additional cloud services like Okta and Microsoft 365.<\/li>\n<\/ul>\n<p>The campaign has demonstrated particular success against the fashion and luxury goods sector, with multiple LVMH brands falling victim within weeks of each other.<\/p>\n<p>Allianz Life Insurance reported that the July 16 attack affected the majority of its 1.4 million U.S. customers, while <a href=\"https:\/\/cybersecuritynews.com\/qantas-airlines-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Qantas<\/a> disclosed that up to 6 million customer records were potentially compromised.<\/p>\n<p>Chanel has begun directly notifying affected customers and has engaged external cybersecurity specialists to conduct a thorough investigation of the incident.<\/p>\n<p>The company has also reported the breach to relevant law enforcement agencies and data protection authorities as required by applicable regulations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 95%,rgb(169,184,195) 100%)\"><code><strong>Integrate <strong>ANY.RUN TI Lookup<\/strong> with your SIEM or SOAR To Analyses Advanced Threats<\/strong> -&gt; <strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=atricle&amp;utm_campaign=want-to-detect-incidents-before&amp;utm_content=plans1&amp;utm_term=290725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try 50 Free Trial Searches<\/a> <\/strong><\/code><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chanel-hacked\/\">Fashion Giant Chanel Hacked in Wave of Salesforce Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chanel-hacked\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fashion Giant Chanel Hacked in Wave of Salesforce Attacks French luxury fashion house Chanel has become the latest victim in a sophisticated cybercrime campaign targeting major corporations through their Salesforce customer relationship management systems. The company confirmed on July 25, 2025, that unauthorized threat actors had breached a database containing personal information of U.S. customers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-5887","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5887"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5887"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5887\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}