The cybercriminal group ShinyHunters has executed one of the largest data breaches in recent history, stealing over 1.5 billion Salesforce records from 760 companies through a sophisticated attack involving compromised OAuth tokens.
## The Attack Method
For the past year, threat actors operating under various names—including ShinyHunters, Scattered Spider, and Lapsus$—have been systematically targeting Salesforce customers. Their method involves social engineering tactics and malicious OAuth applications to breach Salesforce instances and extract valuable data for extortion purposes.
The breakthrough came in March when attackers breached Salesloft’s GitHub repository, gaining access to the company’s private source code. Using the TruffleHog security tool, they discovered OAuth tokens for Salesloft Drift and Drift Email platforms—third-party services that integrate with Salesforce to manage customer conversations, leads, and support cases.
## Scale of the Breach
The stolen data encompasses critical business information across multiple Salesforce database tables:
– **250 million** Account records
– **579 million** Contact records
– **171 million** Opportunity records
– **60 million** User records
– **459 million** Case records (including sensitive support ticket data)
## High-Profile Victims
The attack impacted numerous major technology companies, including Google, Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, and Palo Alto Networks, among others.
## Secondary Attacks and Intelligence Gathering
Google Threat Intelligence revealed that attackers analyzed the stolen data to extract hidden credentials, authentication tokens, and access keys. This information enabled them to launch additional attacks on victim environments, specifically targeting AWS access keys, passwords, and Snowflake tokens.
## Law Enforcement Response
The FBI has issued an advisory warning about these threat actors, tracked by Google as UNC6040 and UNC6395. Before allegedly “going dark,” the group claimed to have breached Google’s Law Enforcement Request system, though Google confirmed no data was accessed through the fraudulent account.
## Ongoing Threat
Despite claims of retirement, security researchers report the threat actors began targeting financial institutions in July 2025 and are likely to continue their operations.
## Protection Recommendations
Salesforce advises customers to implement essential security measures:
– Enable multi-factor authentication (MFA)
– Enforce principle of least privilege access
– Carefully monitor and manage connected applications
– Regularly audit OAuth token permissions
This breach highlights the critical importance of securing third-party integrations and maintaining robust cybersecurity practices across all connected platforms.
