Data Breach Alert: ๐Ÿšจ 1 Billion Records Stolen from Salesforce Buyer Databases! ๐Ÿ•ต๏ธโ€โ™€๏ธ

A notorious predominantly English-speaking hacking group has launched a website to extort its victims, threatening to release about a billion records stolen from companies who store their customersโ€™ data in cloud databases hosted by Salesforce.

The loosely organized group, which has been known as Lapsus$, Scattered Spider and ShinyHunters, have published a dedicated data leak site on the dark web, called Scattered LAPSUS$ Hunters.ย 

The website, first spotted by threat intelligence researchers on Friday and seen by TechCrunch, aims to pressure victims into paying the hackers to avoid having their stolen data published online.ย 

โ€œContact us to regain control on data governance and prevent public disclosure of your data,โ€ reads the site. โ€œDo not be the next headline. All communications demand strict verification and will be handled with discretion.โ€

Over the last few weeks, the ShinyHunters gang allegedly hacked dozens of high-profile companies by breaking into their cloud-based databases hosted by Salesforce.ย 

a screenshot from the ShinyHunters' hacking group's leak site, which claims 1 billion records stolen from Salesforce databases
Image Credits:TechCrunch (screenshot)

Insurance giant Allianz Life, Google, fashion conglomerate Kering, the airline Qantas, carmaking giant Stellantis, credit bureau TransUnion, and the employee management platform Workday, among several others, have confirmed their data was stolen in these mass hacks.

The hackersโ€™ leak site lists several alleged victims, including FedEx, Hulu (owned by Disney), and Toyota Motors, none of which responded to a request for comment on Friday.

Itโ€™s not clear if the companies known to have been hacked but not listed on the hacking groupโ€™s leak site have paid a ransom to the hackers to prevent their data from being published. When reached by TechCrunch, a representative from ShinyHunters said, โ€œthere are numerous other companies that have not been listed,โ€ but declined to say why.

At the top of the site, the hackers mention Salesforce and demand that the company negotiate a ransom, threatening that otherwise โ€œall your customers [sic] data will be leaked.โ€ The tone of the message suggests that Salesforce has not yet engaged with the hackers.

A spokesperson for Salesforce did not respond to TechCrunchโ€™s outreach or questions about the breach.

For weeks, security researchers have speculated that the group, which has historically eschewed a public presence online, was planning to publish a data leak website to extort its victims.ย 

Historically, such websites have been associated with foreign, often Russian-speaking, ransomware gangs. In the last few years, these organized cybercrime groups have evolved from stealing, encrypting their victimโ€™s data and then privately asking for a ransom, to simply threatening to publish the stolen data online unless they get paid.ย 

Updated with comment from ShinyHunters.

Source link

Show Comments (0) Hide Comments (0)
0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Stay Updated!

Subscribe to get the latest blog posts, news, and updates delivered straight to your inbox.

By pressing the Sign up button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use