A coordinated cyber campaign has compromised major corporations including Qantas, Allianz Life, LVMH luxury brands, and Adidas, with all attacks traced back to the notorious ShinyHunters extortion group. The hackers exploited Salesforce CRM systems through sophisticated voice phishing techniques, marking one of the most significant corporate data breach waves of recent months.
## The Attack Method: Voice Phishing Meets Cloud Exploitation
Google’s Threat Intelligence Group first identified the threat in June, tracking the attackers as UNC6040. The cybercriminals employed a clever social engineering strategy:
– **Impersonation tactics**: Hackers posed as IT support staff during phone calls to employees
– **Malicious app deployment**: Victims were tricked into installing a compromised version of Salesforce’s Data Loader OAuth app
– **Credential theft**: Additional attacks used fake Okta login pages to steal passwords and multi-factor authentication tokens
The attackers often renamed their malicious tools to “My Ticket Portal” to appear more legitimate during the deception process.
## High-Profile Victims Across Industries
The breach campaign affected numerous major companies:
**Luxury Brands**: LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co. all reported unauthorized database access, with Tiffany Korea specifically noting a “vendor platform” compromise.
**Airlines and Insurance**: Qantas confirmed 5.7 million customers were affected, while Allianz Life disclosed that attackers accessed their third-party CRM system on July 16, 2025, impacting the majority of their 1.4 million customers.
**Retail**: Adidas also reported breaches involving third-party systems during the same timeframe.
## The ShinyHunters Connection
While companies haven’t publicly named Salesforce as the compromised platform, cybersecurity experts have confirmed all incidents stem from the same campaign. The attacks are linked to ShinyHunters, a group that operates differently from typical ransomware gangs by focusing on data theft and private extortion rather than public leaks.
### Complex Criminal Network
The cybersecurity community initially struggled to attribute these attacks, with some pointing to Scattered Spider (UNC3944). However, research reveals:
– **Overlapping operations**: Both groups may share members and communicate within the same criminal networks
– **Different tactics**: ShinyHunters focuses on cloud platform exploitation, while Scattered Spider conducts full network breaches
– **Possible connections**: Links exist to the defunct Lapsus$ hacking group and “The Com” cybercriminal network
Some experts theorize ShinyHunters operates as an “extortion-as-a-service” model, conducting attacks on behalf of other criminals for revenue sharing.
## Salesforce Response and Security Recommendations
Salesforce emphasized that their platform wasn’t directly compromised, stating the breaches resulted from social engineering attacks against customer accounts. The company recommends several critical security measures:
**Essential Protections**:
– Enable multi-factor authentication (MFA) across all accounts
– Implement trusted IP ranges for login access
– Follow least-privilege principles for app permissions
– Carefully manage and restrict connected applications
– Deploy Salesforce Shield for advanced threat detection
– Designate security contacts for incident communication
## Looking Forward
As private extortion attempts continue, security experts warn that failed negotiations may trigger a wave of public data leaks, similar to ShinyHunters’ previous Snowflake attacks. Organizations using cloud-based CRM systems should immediately review their security postures and implement comprehensive protection strategies against these evolving social engineering threats.
The coordinated nature of these attacks demonstrates the sophistication of modern cybercriminal operations and highlights the critical importance of employee security awareness training alongside technical safeguards.
