Massive Salesforce Breach: 1.5 Billion Customer Records Stolen from 760 Companies in OAuth Token Attack

# Massive Salesforce Data Breach: 1.5 Billion Records Stolen from 760 Companies

The cybercriminal group ShinyHunters has executed one of the largest data breaches in recent history, stealing over 1.5 billion Salesforce records from 760 companies through a sophisticated attack involving compromised OAuth tokens.

## The Attack Method

For the past year, threat actors operating under various names—including ShinyHunters, Scattered Spider, and Lapsus$—have been systematically targeting Salesforce customers. Their method involves social engineering tactics and malicious OAuth applications to breach Salesforce instances and extract valuable data for extortion purposes.

The breakthrough came in March when attackers breached Salesloft’s GitHub repository, gaining access to the company’s private source code. Using the TruffleHog security tool, they discovered OAuth tokens for Salesloft Drift and Drift Email platforms—third-party services that integrate with Salesforce to manage customer conversations, leads, and support cases.

## Scale of the Breach

The stolen data encompasses critical business information across multiple Salesforce database tables:
– **250 million** Account records
– **579 million** Contact records
– **171 million** Opportunity records
– **60 million** User records
– **459 million** Case records (including sensitive support ticket data)

## High-Profile Victims

The attack impacted numerous major technology companies, including Google, Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, and Palo Alto Networks, among others.

## Secondary Attacks and Intelligence Gathering

Google Threat Intelligence revealed that attackers analyzed the stolen data to extract hidden credentials, authentication tokens, and access keys. This information enabled them to launch additional attacks on victim environments, specifically targeting AWS access keys, passwords, and Snowflake tokens.

## Law Enforcement Response

The FBI has issued an advisory warning about these threat actors, tracked by Google as UNC6040 and UNC6395. Before allegedly “going dark,” the group claimed to have breached Google’s Law Enforcement Request system, though Google confirmed no data was accessed through the fraudulent account.

## Ongoing Threat

Despite claims of retirement, security researchers report the threat actors began targeting financial institutions in July 2025 and are likely to continue their operations.

## Protection Recommendations

Salesforce advises customers to implement essential security measures:
– Enable multi-factor authentication (MFA)
– Enforce principle of least privilege access
– Carefully monitor and manage connected applications
– Regularly audit OAuth token permissions

This breach highlights the critical importance of securing third-party integrations and maintaining robust cybersecurity practices across all connected platforms.

Share This Article