INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Salesforce Deploys Anti-Ransomware Measures After Ransom Demand
| 2025-10-08 17:20 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On October 8, 2025, a ransomware extortion attempt was made against Salesforce by the threat actor LAPSUS$, resulting in nearly 989.45 million stolen records being threatened to be leaked online if a payment wasn't made within an unspecified timeframe. The attack is believed to have been related to past incidents and not a new breach of the Salesforce platform, according to the company's official statements on October 2. Salesforce has stated that it will not engage in negotiations or pay any ransom demands, with spokesperson Allen Tsai saying "Salesforce will not engage, negotiate with, or pay any extortion demand." The attack is part of an ongoing series of attempts by LAPSUS$ to extort payments from companies using the stolen data, which was previously accessed through a breach of SalesLoft's Drift application. As of October 8, Salesforce has reportedly notified affected customers and Google is investigating the intrusions.
Technical Mitigations AI-generated
• Patch Salesforce to address the ShinyHunters (UNC6240) vulnerability, which was exploited in a previous breach of SalesLoft's Drift application.
• Implement OAuth token validation and monitoring to detect potential unauthorized access to Salesforce instances.
• Block or hunt for indicators related to Scattered LAPSUS$ Hunters' tactics, such as the use of specific Bitcoin addresses.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
2025/10/08
Threat actors, claiming to have stolen nearly 1 billion customer records, demanded a ransom payment from Salesforce in exchange for not leaking the data.
Click on any entity below to view its context and source!
threat_actor
LAPSUS$
"
The following day, October 3, a crew now calling itself Scattered LAPSUS$ Hunters listed 39 companies' Salesforce environments on its new data-leak site and
demanded a ransom payment
to prevent what it claims is 989.45 million stolen records…
"
The Register
has learned that the stolen files Scattered LAPSUS$ Hunters are threatening to make public are primarily Salesforce customer data accessed from previous intrusions - not new breaches.
data_breach
989.45 stolen records
"
The following day, October 3, a crew now calling itself Scattered LAPSUS$ Hunters listed 39 companies' Salesforce environments on its new data-leak site and
demanded a ransom payment
to prevent what it claims is 989.45 million stolen records f…
data_breach
1 customer records
Salesforce won't pay a ransom demand to criminals who claim to have stolen nearly 1 billion customer records and are threatening to leak the data if the CRM giant doesn't pony up some cash.
financial
$10 gang
The gang also
offered $10 in Bitcoin
to anyone willing to "endlessly harass these executives" in an attempt to pressure the purported victims into paying ransoms.
Tactical Metrics
Metrics
data_breach
989,450,000
Stolen Records
Click for context!
"
The following day, October 3, a crew now calling itself Scattered LAPSUS$ Hunters listed 39 companies' Salesforce environments on its new data-leak site and
demanded a ransom payment
to prevent what it claims is 989.45 million stolen records f…
Metrics
data_breach
1,000,000,000
Customer Records
Salesforce won't pay a ransom demand to criminals who claim to have stolen nearly 1 billion customer records and are threatening to leak the data if the CRM giant doesn't pony up some cash.
Metrics
financial
10
Gang
The gang also
offered $10 in Bitcoin
to anyone willing to "endlessly harass these executives" in an attempt to pressure the purported victims into paying ransoms.
Intelligence Sources
The Register - CSO
2025-10-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
organisation
Identified Entity
Google
entity
3x
timeline
Temporal Reference
October 2
date
2x
tactic
Cyber Operation Type
Ransomware
tactic
Contextual Telemetry
Context Block
7 METRICS
source region
Origin Country
United States
country
industry
Targeted Sector
Technology
sector
threat actor
APT Group
LAPSUS$
actor
general metric
Companies
39
companies
data breach
Stolen Records
989,450,000
stolen records
data breach
Customer Records
1,000,000,000
customer records
financial
Gang
10
gang
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.