An extortion group has launched a new data leak site to publicly extort dozens of companies impacted by a wave of Salesforce breaches, leaking samples of data stolen in the attacks. The threat actors responsible for these attacks claim to be part of the ShinyHunters, Scattered Spider, and Lapsus$ groups, collectively referring to themselves as "Scattered Lapsus$ Hunters." Today, they launched a new data leak site containing 39 companies impacted by the attacks. Each entry includes samples of data allegedly stolen from victims' Salesforce instances, and warns the victims to reach out to "prevent public disclosure" of their data before the October 10 deadline is reached. The companies being extorted on the data leak site include well-known brands and organizations, including FedEx, Disney/Hulu, Home Depot, Marriott, Google, Cisco, Toyota, Gap, McDonald's, Walgreens, Instacart, Cartier, Adidas, Sake Fifth Avenue, Air France & KLM, Transunion, HBO MAX, UPS, Chanel, and IKEA. "All of them have been contacted long ago, they saw the email because I saw them download the samples multiple times. Most of them chose to not disclose and ignore," ShinyHunters told BleepingComputer. "We highly advise you proceed into the right decision, your organisation can prevent the release of this data, regain control over the situation and all operations remain stable as always. We highly recommend a decision-maker to get involved as we are presenting a clear and mutually beneficial opportunity to r...
ShinyHunters launches Salesforce data leak site to extort 39 victims
BleepingComputer
·Sergiu Gatlan
·Published Oct 3, 2025
·Updated
Affected Software
1 affected component
Salesforce Salesforce
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how the hacking group ShinyHunters has started leaking data stolen from Salesforce attacks to extort victims.
2
What security implications are discussed in the article?
The article highlights the risks of data breaches and the potential for extortion when sensitive corporate data is leaked online.
3
What companies are affected by these Salesforce breaches?
The article mentions that 39 companies are victims of the extortion campaign related to the Salesforce data breaches.
4
What type of data is being leaked by the ShinyHunters group?
ShinyHunters is leaking samples of sensitive data stolen during the Salesforce attacks.
5
What measures can organizations take to protect themselves from such extortion threats?
Organizations can enhance their cybersecurity measures, conduct regular security assessments, and ensure proper data encryption to mitigate risks associated with breaches.