Hacking Group Allegedly Breaches Salesforce Client Databases, Stealing 1 Billion Records
An infamous hacking collective, predominantly English-speaking, has launched a site designed to extort its targets by threatening to disclose approximately one billion records acquired from businesses that store customer data in Salesforce’s cloud databases.
The loosely organized group, previously recognized as Lapsus$, Scattered Spider, and ShinyHunters, has unveiled a dedicated data leak platform on the dark web, dubbed Scattered LAPSUS$ Hunters.
This site was first identified by threat intelligence analysts on Friday and has since been reported by TechCrunch. Its objective is to pressure victims into paying the hackers to prevent the publication of their stolen data.
“Contact us to restore data governance and prevent public exposure of your data,” the site claims. “Don’t be the next headline. All communications will undergo strict verification and remain confidential.”
Recently, the ShinyHunters group has reportedly breached numerous high-profile organizations by accessing their Salesforce-hosted cloud databases.

Organizations such as Allianz Life, Google, fashion powerhouse Kering, Qantas Airlines, Stellantis, credit agency TransUnion, and employee management platform Workday have all acknowledged that their data was compromised during these significant breaches.
The hackers’ leak site lists several purported targets, including FedEx, Hulu (a Disney subsidiary), and Toyota Motors, none of which have responded to requests for comments on Friday.
It remains unclear if the companies known to have been hacked but not listed on the leak site have paid ransoms to the hackers to prevent their data from being disclosed. A representative from ShinyHunters did not immediately return TechCrunch’s inquiries.
At the top of their website, the hackers mention Salesforce and demand ransom negotiations, warning that if not, “all your customers [sic] data will be leaked.” This suggests that Salesforce has not yet entered into discussions with the hackers.
A Salesforce spokesperson did not respond to TechCrunch’s inquiries regarding the breach.
For weeks, cybersecurity analysts have speculated that this group, which has generally avoided a public online presence, was gearing up to launch a data leak site for extortion purposes.
Historically, such websites have been associated with foreign, often Russian-speaking, ransomware syndicates. In recent years, these organized cybercrime groups have shifted focus from stealing and encrypting data to simply threatening to publish stolen data online unless a ransom is paid.


