• News/
  • https://www.theregister.com/2025/10/08/salesforce_refuses_to_pay_ransomware/

Take this rob and shove it! Salesforce issues stern retort to ransomware extort

The Register
·
Jessica Lyons
·
Published Oct 8, 2025
·
Updated

Salesforce won't pay a ransom demand to criminals who claim to have stolen nearly 1 billion customer records and are threatening to leak the data if the CRM giant doesn't pony up some cash. "Salesforce will not engage, negotiate with, or pay any extortion demand," Allen Tsai, a Salesforce spokesperson, told The Register. It has reportedly told customers the same thing. The SaaS giant declined to answer any additional questions and directed us to the company's official statements about the security incident. The most recent update, from October 2, says Salesforce is "aware of recent extortion attempts by threat actors, which we have investigated in partnership with external experts and authorities." These attempts to extort ransom payments "relate to past or unsubstantiated incidents, and we remain engaged with affected customers to provide support," it continues. "At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology." The following day, October 3, a crew now calling itself Scattered LAPSUS$ Hunters listed 39 companies' Salesforce environments on its new data-leak site and demanded a ransom payment to prevent what it claims is 989.45 million stolen records from being published online. The gang also offered $10 in Bitcoin to anyone willing to "endlessly harass these executives" in an attempt to pressure the purported victims into paying ransoms. Prior to the leak site go...

Read full article

Affected Software

1 affected component
Salesforce CRM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Salesforce's refusal to pay a ransom to cybercriminals threatening to leak stolen customer records.

2

What security implications are discussed?

The article highlights the risks associated with ransomware attacks and the potential exposure of sensitive customer data.

3

What products or software are affected?

The affected software mentioned in the article is Salesforce CRM.

4

How many customer records are claimed to be stolen?

The criminals claim to have stolen nearly 1 billion customer records from Salesforce.

5

What stance does Salesforce take regarding the ransom demand?

Salesforce firmly states that they will not engage with the criminals or pay the ransom.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203