Stellantis Customer Data Stolen in Major Salesforce Security Breach

# Stellantis Confirms Customer Data Breach Through Third-Party Service Provider

**Major automotive manufacturer Stellantis has disclosed a cybersecurity incident affecting North American customers after hackers gained unauthorized access to a third-party platform.**

## About Stellantis

Stellantis, formed in 2021 through the merger of PSA Group and Fiat Chrysler Automobiles, ranks as the world’s fifth-largest automaker by volume. The multinational corporation operates 14 major brands including Jeep, Ram, Dodge, Chrysler, Peugeot, Citroën, and Alfa Romeo across over 130 countries.

## The Security Incident

The company detected unauthorized access to a third-party service provider’s platform supporting North American customer service operations. According to Stellantis, attackers only accessed customer contact information, as the compromised platform did not store financial data or other sensitive personal details.

“Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation,” the company stated.

## Connection to Broader Salesforce Attacks

Security researchers have linked this breach to a larger campaign targeting Salesforce customers. The ShinyHunters extortion group claimed responsibility, stating they stole over 18 million Salesforce records containing names and contact information from Stellantis.

### Widespread Impact

Since early 2024, ShinyHunters has targeted numerous high-profile organizations through Salesforce breaches, including:
– **Tech giants**: Google, Cisco, Cloudflare, Palo Alto Networks
– **Major brands**: Adidas, LVMH (Louis Vuitton, Dior, Tiffany & Co.)
– **Airlines**: Qantas
– **Insurance companies**: Farmers Insurance, Allianz Life

## Attack Method

The cybercriminals reportedly used voice phishing (vishing) attacks and exploited stolen OAuth tokens from Salesloft’s Drift AI chat integration with Salesforce. This method allowed them to access sensitive information including passwords, AWS access keys, and Snowflake tokens.

The group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised OAuth tokens.

## FBI Warning

The FBI recently issued a security alert sharing indicators of compromise and warning organizations about threat actors targeting Salesforce environments for data theft and extortion purposes.

## Customer Protection Advice

Stellantis has advised affected customers to:
– Remain vigilant against phishing attempts
– Avoid clicking suspicious links in unexpected communications
– Refrain from sharing personal information in unsolicited emails, texts, or calls
– Report any suspicious activity immediately

The company is directly notifying affected customers and cooperating with appropriate authorities in the ongoing investigation.

Share This Article