Pirates claim to have stolen more than a billion dies of dollars – and demand nearly $ 1 billion so as not to flee them


  • Dispatched lapsus hunters launch the data leak site to put pressure on the victims of the ransom of negotiations
  • The attackers used the Drift of Salesloft application to access data from Salesforce customers, not in Salesforce himself
  • The victims include Cloudflare, Zscaler, Tenable; Salesforce denies compromises of the platform or active vulnerabilities

Dispmed Lapsus $ Hunters, a team of sadly famous hacking groups scattered Spider, Lapsus $ and shiny hunters, apparently created a data leak and autonomous extortion page in order to put their victims to pay their ransom requests.

Earlier in 2025, the news announced that the attackers managed to violate a third -party application – the integration of the drift of Salesloft – and to steal oauth and refreshment tokens. Then they used the tokens to call the dirty APIs of the APP customers and the exfiltrate data such as customer contact records, case and similar objects. Salesforce himself was not raped, but the data hosted by customers were nevertheless entered.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top