Week in Breach Special Edition: What major 2025 cyber incidents taught us

This week: Welcome to this Week in Breach Special Edition. We’re stepping back to look at five defining cyber incidents of 2025 and the lessons they taught us, including the Salesforce ecosystem breach that impacted hundreds of organizations worldwide and the costliest cyberattack in U.K. history, among other notable attacks.

Week in Breach Special Edition: What major 2025 cyber incidents taught us

North America

Salesforce ecosystem

Industry: Technology Exploit: Third-Party Data Breach

In one of the most significant cyberthreats of 2025, the Salesforce ecosystem was targeted in a sweeping third-party data breach, sending shockwaves across industries worldwide. The breach exposed more than 1 billion records across dozens of global enterprises. The campaign unfolded in multiple stages, deliberately targeting the weakest links in the ecosystem: human users and third-party integrations.

Crucially, this was not a direct breach of Salesforce’s core infrastructure. Instead, cybercriminals exploited human error and trusted third-party access to compromise individual customer Salesforce instances. The attack followed a clear, repeatable pattern:

  • First, attackers used social engineering and voice phishing (vishing) to impersonate IT staff and trick employees into granting access.
  • Next, victims were misled into authorizing malicious Connected Apps — such as fake versions of Salesforce Data Loader — or exposing OAuth tokens tied to legitimate tools like Salesloft, Drift and Gainsight. These tokens gave attackers persistent application programming interface (API) access and often bypassed multifactor authentication (MFA).
  • Finally, attackers used Salesforce APIs to export large volumes of data, hunting for credentials, account records and sensitive personal information.

The attack’s impact was extensive. Affected organizations included aviation companies such as Air France–KLM, Qantas and Vietnam Airlines, retail brands like IKEA, Adidas and Chanel, and other major corporations, including Google, TransUnion, Toyota and Disney.

The breach was claimed by a hacker group known as Scattered LAPSUS$ Hunters, which launched a dark website to publish samples of stolen data. The group threatened Salesforce and its customers with further data releases unless ransom payments were made. Salesforce publicly refused to comply with any ransom demands, drawing a clear line against extortion.

Source

How it could affect your business

This incident made it clear that even robust security platforms can be compromised when attackers exploit weak links, such as user error and trusted third-party integrations. Rather than attacking Salesforce directly, cybercriminals targeted individuals and permissions already within the ecosystem.

It also highlighted how AI-driven social engineering is raising the bar for cybercrime. By using AI to craft more convincing messages and impersonations, cybercriminals can easily trick users into granting access or approving malicious actions. This makes it critical for organizations to strengthen user awareness and closely monitor third-party access, connected apps and data permissions.

United Kingdom

Jaguar Land Rover (JLR)

Industry: Manufacturing Exploit: Ransomware & Malware

In late August 2025, Jaguar Land Rover was hit by a cyberattack that became the most economically damaging cyber incident in U.K. history, forcing a shutdown of systems across its global manufacturing operations and leading to estimated losses of £1.9 billion.

The breach began on August 31 and quickly escalated into a major operational crisis. Production across JLR's plants halted for nearly five weeks, and more than 5,000 supply chain partners were affected, with some suppliers facing up to six months of credit strain.

The attack was linked to Scattered LAPSUS$ Hunters, the same group connected to the Salesforce ecosystem breach and other 2025 incidents.

Source

How it could affect your business

Cybercriminals are increasingly targeting business continuity, not just data. A strong business continuity and disaster recovery (BCDR) strategy helps limit downtime and reduce cascading impact across partners and customers.

United States

U.S. universities

Industry: Education Exploit: Hacking

Cyberattacks on U.S. educational institutions accelerated in 2025, affecting major universities including the University of Pennsylvania and Princeton University, and exposing millions of records tied to students, alumni, staff and community affiliates.

At Penn, the attack surfaced on October 31 through emails that appeared to come from the Graduate School of Education, with systems linked to development and alumni activities compromised, including some banking details. Princeton's separate breach, disclosed weeks later, was limited to names, contact information, addresses and donation histories.

Beyond broad network intrusions, attackers also ran targeted campaigns against university staff, including a "payroll pirate" campaign uncovered by Microsoft in which threat actors broke into HR platforms like Workday to hijack employee salaries.

Source

How it could affect your business

Social-engineering-driven attacks are increasingly used to breach educational institutions as a first step toward data theft or ransomware. Institutions need stronger security layers, including advanced threat detection and reliable backup and recovery processes.

Australia

Western Sydney University

Industry: Education Exploit: Hacking

Western Sydney University experienced a series of cyber incidents in 2025, among the most serious breaches reported in the education sector that year.

The university identified unusual activity on August 6 and August 11 involving a student management system hosted by a third-party cloud provider. Investigation revealed the attacker had exploited a chain of connected suppliers, gaining access through third- and fourth-party systems to exfiltrate data.

Stolen information included tax file numbers, passport details and private health and disability data. In December, a former Western Sydney University student was charged in connection with the attacks.

Source

How it could affect your business

Not all cyberthreats originate from large ransomware groups or nation-state actors; a thriving underground market for malware kits and ransomware-as-a-service (RaaS) lowers the barrier to entry. Organizations need layered defenses combining continuous monitoring, strong access controls and encrypted backups.

North America

Red Hat

Industry: Technology Exploit: Hacking

On October 2, Red Hat confirmed a cyberattack involving its consulting GitLab instance, allegedly affecting data tied to more than 800 organizations. A day earlier, a group calling itself Crimson Collective publicly disclosed the breach, claiming it exfiltrated 570 GB of compressed data from more than 28,000 repositories, including sensitive customer engagement reports.

Red Hat confirmed unauthorized access to a self-hosted GitLab instance used for internal Red Hat Consulting collaboration, containing project specifications, example code snippets, internal communications and limited business contact information. The company said the incident did not impact its core products or production systems, though reports suggest the stolen data included nearly 3.5 million files related to banking, telecom and government sector networks.

Source

How it could affect your business

Attackers increasingly target vendors, consultants and shared platforms with trusted access to multiple organizations. Organizations should treat third-party access as part of their own security perimeter, limiting vendor access and monitoring for unusual activity.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Autotask quarterly product innovation update

Autotask quarterly product innovation update

Read more
Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Read more
Compliance as a Service: The MSP revenue stream clients can't opt out of

Compliance as a Service: The MSP revenue stream clients can't opt out of

Read more