North America
Salesforce ecosystem
In one of the most significant cyberthreats of 2025, the Salesforce ecosystem was targeted in a sweeping third-party data breach, sending shockwaves across industries worldwide. The breach exposed more than 1 billion records across dozens of global enterprises. The campaign unfolded in multiple stages, deliberately targeting the weakest links in the ecosystem: human users and third-party integrations.
Crucially, this was not a direct breach of Salesforce’s core infrastructure. Instead, cybercriminals exploited human error and trusted third-party access to compromise individual customer Salesforce instances. The attack followed a clear, repeatable pattern:
- First, attackers used social engineering and voice phishing (vishing) to impersonate IT staff and trick employees into granting access.
- Next, victims were misled into authorizing malicious Connected Apps — such as fake versions of Salesforce Data Loader — or exposing OAuth tokens tied to legitimate tools like Salesloft, Drift and Gainsight. These tokens gave attackers persistent application programming interface (API) access and often bypassed multifactor authentication (MFA).
- Finally, attackers used Salesforce APIs to export large volumes of data, hunting for credentials, account records and sensitive personal information.
The attack’s impact was extensive. Affected organizations included aviation companies such as Air France–KLM, Qantas and Vietnam Airlines, retail brands like IKEA, Adidas and Chanel, and other major corporations, including Google, TransUnion, Toyota and Disney.
The breach was claimed by a hacker group known as Scattered LAPSUS$ Hunters, which launched a dark website to publish samples of stolen data. The group threatened Salesforce and its customers with further data releases unless ransom payments were made. Salesforce publicly refused to comply with any ransom demands, drawing a clear line against extortion.
How it could affect your business
This incident made it clear that even robust security platforms can be compromised when attackers exploit weak links, such as user error and trusted third-party integrations. Rather than attacking Salesforce directly, cybercriminals targeted individuals and permissions already within the ecosystem.
It also highlighted how AI-driven social engineering is raising the bar for cybercrime. By using AI to craft more convincing messages and impersonations, cybercriminals can easily trick users into granting access or approving malicious actions. This makes it critical for organizations to strengthen user awareness and closely monitor third-party access, connected apps and data permissions.