{"id":7419,"date":"2025-10-04T10:03:28","date_gmt":"2025-10-04T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/04\/scattered-lapsus-hunters-announced-salesforce-breach-list-on-new-onion-site\/"},"modified":"2025-10-04T10:03:28","modified_gmt":"2025-10-04T10:03:28","slug":"scattered-lapsus-hunters-announced-salesforce-breach-list-on-new-onion-site","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/04\/scattered-lapsus-hunters-announced-salesforce-breach-list-on-new-onion-site\/","title":{"rendered":"Scattered LAPSUS$ Hunters Announced Salesforce Breach List On New Onion Site"},"content":{"rendered":"<p>    Scattered LAPSUS$ Hunters Announced Salesforce Breach List On New Onion Site<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A cybercrime collective known as <a href=\"https:\/\/cybersecuritynews.com\/scattered-lapsus-hunters-4-0\/\" target=\"_blank\" rel=\"noreferrer noopener\">Scattered LAPSUS$<\/a> Hunters has launched a new data leak site on the dark web, claiming it holds nearly one billion records from Salesforce customers.<\/p>\n<p>The group is orchestrating a widespread blackmail campaign, setting a ransom deadline of October 10, 2025. They have threatened to publish sensitive data and technical details if their demands are not met.<\/p>\n<p>The threat actors allege that significant security lapses at Salesforce, including inadequate two-factor authentication (2FA) and OAuth protections, enabled them to compromise over 100 Salesforce instances. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQ9KkoS73oEGF7aanu2_k2hNRwaq8C82UoweOIHDPZe8T0-G6V5eBBjZI_XUhlFMSbFsg4fhIrlObptqjU0Kl5TCzQTCtSBOKtN6bOzwBU3zCmO-Thz73g583dXJZj9-D3q8RyfxuJekHW7S2vAWPOIxIwM956US9oObNhlHMdpLqvnGCGvGcSQkon3AFG\/s16000\/Scattered%2520LAPSUS%2524%2520Hunters%2520Listing.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Their new onion site lists numerous high-profile companies as victims of the data theft, including Toyota Motor Corporation, FedEx, UPS, Adidas, Disney\/Hulu, and McDonald\u2019s. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgUII3dJnWbiIzXuWHzEfWSn8CCpmkhMO-YE4ocZcCznFYs_0HQuf7g2iWJNujXWr_fHfA6nyFZcUagDPObeXpVO3uAwT7o79tBsaXABT4T_3z1c8H5zUWfuHVbZW5VMpTx0rAbppX8mpGbGi9Ws0IXpe6Dtbo_IS4VXYBUS2BOL9I5hFPHaH7-NintY3Gg\/s16000\/Scattered%2520LAPSUS%2524%2520Hunters%2520Listing1.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Other prominent names listed are Qantas, Aerom\u00e9xico, Vietnam Airlines, Stellantis, IKEA, KFC, GAP, and the educational platform Canvas by Instructure.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-scattered-lapsus-hunte-r-s-listings\">\n<strong>Scattered LAPSUS$ Hunte<\/strong>r<strong>s Listings<\/strong><br \/>\n<\/h2>\n<p>Scattered LAPSUS$ Hunters is not a new entity but rather a coalition of members from some of the most infamous hacking groups, including ShinyHunters, <a href=\"https:\/\/cybersecuritynews.com\/scattered-spider-hackers-aviation\/\" target=\"_blank\" rel=\"noreferrer noopener\">Scattered Spider<\/a>, and Lapsus$.<\/p>\n<p>This alliance has been linked to a series of major cyberattacks throughout 2025, with a particular focus on Salesforce environments. The group\u2019s formation represents a \u201ctrinity of chaos,\u201d combining different skill sets to execute complex intrusion campaigns.<\/p>\n<p>A blend of sophisticated social engineering and technical exploitation characterizes their methods. Attackers have been observed using <a href=\"https:\/\/cybersecuritynews.com\/fakecall-malware-employs-vishing\/\" target=\"_blank\" rel=\"noreferrer noopener\">voice phishing (vishing)<\/a> campaigns, where they impersonate IT support staff in phone calls to trick employees.<\/p>\n<p>During these calls, victims are guided to authorize a malicious application, which captures <a href=\"https:\/\/cybersecuritynews.com\/tag\/oauth\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAuth tokens<\/a>. These tokens grant the attackers persistent access to the company\u2019s Salesforce environment, effectively bypassing multi-factor authentication controls and allowing for the mass exfiltration of CRM data.<\/p>\n<p>The Salesforce campaign highlights a strategic evolution in cybercrime tactics. Instead of relying on traditional ransomware that encrypts files, groups like Scattered LAPSUS$ Hunters are focusing on data theft and extortion.<\/p>\n<p>The leverage is not the disruption of systems but the public exposure of stolen data, which can lead to customer backlash, regulatory fines, and severe reputational damage.<a href=\"https:\/\/www.vectra.ai\/blog\/scattered-lapsus-hunters-announce-they-are-going-dark-but-the-threat-remains\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>In mid-2025, actors associated with this collective claimed to have stolen 1.5 billion Salesforce records from 760 companies by compromising OAuth tokens linked to third-party integrations like <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Salesloft and Drift<\/a>.<\/p>\n<p>The attackers often release fragments of the stolen data as proof, holding back the full dataset to maximize pressure during negotiations. <\/p>\n<p>This incident follows a pattern seen in earlier 2025 attacks on companies like Google, <a href=\"https:\/\/cybersecuritynews.com\/jlr-shutdown-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Jaguar Land Rover<\/a>, and LVMH, where the same collective claimed responsibility.<\/p>\n<p>Despite a recent \u201cfarewell letter\u201d announcing their distribution, security experts believe the group has simply rebranded, and the threat of large-scale data leaks remains significant.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p><a href=\"https:\/\/socradar.io\/dark-web-profile-scattered-lapsus-hunters\/\"><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/scattered-lapsus-hunters-salesforce\/\">Scattered LAPSUS$ Hunters Announced Salesforce Breach List On New Onion Site<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Cyber Advisory<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/scattered-lapsus-hunters-salesforce\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Scattered LAPSUS$ Hunters Announced Salesforce Breach List On New Onion Site A cybercrime collective known as Scattered LAPSUS$ Hunters has launched a new data leak site on the dark web, claiming it holds nearly one billion records from Salesforce customers. The group is orchestrating a widespread blackmail campaign, setting a ransom deadline of October 10, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-7419","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7419"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7419"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7419\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7419"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7419"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7419"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}