Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Shinyhunters claim that 1.5 billion salesforce records stole in drifted hack
    Security

    Shinyhunters claim that 1.5 billion salesforce records stole in drifted hack

    PineapplesUpdateBy PineapplesUpdateSeptember 18, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Shinyhunters claim that 1.5 billion salesforce records stole in drifted hack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Shinyhunters claim that 1.5 billion salesforce records stole in drifted hack

    The Shinyhunters Effertertion Group has claimed that more than 1.5 billion salesfors records have been stolen from 760 companies, which use salesloft drifted ooutes tokens.

    For the previous year, danger actor salesforce are targeting salesforce customers in data theft attacks using social engineering and malicious Oauth applications to dissolve and download data. The stolen data is then used to extract companies in ransom to pay ransom to prevent data from publicly leaking.

    These attacks have been claimed by the danger actors, stating that they are part of bright, scattered spider and lapsus $ forcibly recovery groups, now calling themselves “scattered lapsus $ hunter”. Google tracks this activity as UnC6040 and UnC6395.

    In March, one of the danger actors broke the Githb Repository of the salesloft, including a private source code for the company.

    Shinyhunters told Bleepingcomputer that danger actors used Trpholhog Safety tools to scan the source code for secrets, resulting in the discovery of oauth tokens for salesloft drifts and drift email platforms.

    Slesloft Drift is a third-party platform that combines the Drift AI chat agent with a salesforce example, allowing organizations to sink conversations, lead and support cases into their CRM. Drift email is used to manage email answers and to organize the CRM and marketing automation database.

    Using these stolen drifts OATH tokens, Shinohetors told BlappingCopper that the danger actors stole nearly 1.5 billion data records for 760 companies “” “” “” “” “” “” “” “” “” “” “for 760 companies for 760 companies stole nearly 1.5 billion data records for 760 companies for 760 companies.Account,Contact,Case,opportunity“, And “User“Salesforce object tables.

    Of these records, about 250 million account, 579 million from contact, 171 million from opportunity, 60 million from user and about 459 million from case salesforce table.

    Case tables were used to collect information and text from the support tickets presented by the customers of these companies, which, for technical companies, can include sensitive data.

    As a proof of the fact that they were behind the attack, the danger actor shared a text file, which lists the source code folders in the breted salesloft githib repository.

    Bleepingcomputer contacted Salesloft with questions about these record counts and total number of total companies, but did not receive our email response. However, a source confirmed that the numbers are accurate.

    Google Threat Intelligence (Mandient) reported that the stolen case data was analyzed for hidden mysteries, such as credentials, authentication tokens and access keys, to make the attackers capable of pilling other environments for further attacks.

    “After finishing the data, the actor discovered through data to search for mysteries, which can be used to compromise the potentially suffering environment,” Explained to google,

    “GTIG saw UnC6395 targeting sensitive credentials such as Amazon Web Services (AWS) Access Keys (AKIA), password and snowflake-related access tokens.”

    Stolen drifts and flow email tokens were used in large -scale data theft campaign, which hits major companies including Google, Cloudflare, Zscler, Worthy, Cyberk, Elastic, Beyond, Proof point, Jfrog, Neutanix, Qualis, Rubric, Cato networkPalo Alto Network, and Too much,

    Due to the sheer volume of these attacks, the FBI recently issued an advisory warning about the UNC6040 and UNC6395 threat actors, shared the IOC discovered during the attacks.

    Last Thursday, the danger actors claiming to be a part of the scattered Spider, said they planned “dark” and stopped discussing operations on Telegram.

    In a farewell post, danger actors claim to violate Google’s law enforcement system (Lers), which is used by law enforcement to issue data requests, and FBI Echeck platform, which is used to check background.

    After contacting Google about these claims, the company confirmed that a fraud account was added to its Lers platform.

    Google told Bleepingcomputer, “We have identified that a fraud account was created in our system for law enforcement requests and disabled the account.”

    “No requests were made with this fraud account, and no data was accessed.”

    While the danger actors indicated that they are retiring, from researchers Reconsideration Report that the danger actors started targeting financial institutions in July 2025 and the attacks are likely to continue.

    To protect these data theft attacks, Salesforce recommends Customers follow the best practices, including enabling multi-factor authentication (MFA), implementing the principle of at least privileges and carefully managing connected applications.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    billion claim drifted hack Records SAlesforce Shinyhunters stole
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleLovable CEO, one of the fastest growing startups in history, disrupt 2025
    Next Article Meta unveils new smart glass with a display and restband controller
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Here’s how to claim your share of the $700 million Google settlement

    December 11, 2025
    Startups

    Tech CEO fixed his ‘bad’ management skills to build a $19 billion company

    December 11, 2025
    Startups

    Why This $1 Billion Startup CEO Rejected 996, Hustle Culture

    December 10, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    Best LC10 loadout in call of duty: Warzone

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.