Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Cybercriminals Steal 1,000,000,000 Sensitive Records From Salesforce Containing Personally Identiable Information: Report

Cybercriminals Steal 1,000,000,000 Sensitive Records From Salesforce Containing Personally Identiable Information: Report

Daily HodlDaily Hodl2025/10/06 16:00
By:by Alex Richardson

Cybercriminals claiming ties to the “LAPSUS$” hacking group say they have stolen nearly 1 billion records from companies that use Salesforce, exposing vast amounts of personally identifiable information.

In a message to Reuters , the group, calling itself “Scattered LAPSUS$ Hunters,” insists it did not breach Salesforce’s internal systems.

Rather than directly exploiting Salesforce, its members say they targeted clients using the platform by deploying “vishing” attacks – voice phishing techniques in which attackers impersonate employees or technical staff and trick helpdesk workers into granting access.

They also claim to have used modified versions of Salesforce’s Data Loader tool to siphon data from compromised environments.

Salesforce has stated that there is “no indication the Salesforce platform has been compromised” and that the claims “do not appear tied to any known vulnerability in our technology.”

The company says it is working with affected customers to provide support and is investigating the extortion attempts.

The hackers published a dark-web leak site listing around 40 companies they claimed to have breached, though it remains unclear whether all are actual Salesforce users.

Law enforcement in the U.K. previously arrested four individuals under age 21 in connection with earlier attacks on British retailers, and cybersecurity researchers believe this operation may be tied to a wider criminal ecosystem known as “The Com.”

John Hultquist, an analyst at Google’s cybersecurity arm, warned earlier this year that US retailers are now facing cyberattacks involving ransomware and extortion tactics, similar to what UK businesses have just been contending with.

Says Google in a recent blog post,

“After shifting to ransomware and data theft extortion in early 2023, they impacted organizations in a broader range of industries. Since then, we have regularly observed UNC3944 conduct waves of targeting against a specific sector, such as financial services organizations in late 2023 and food services in May 2024. Notably, UNC3944 has also previously targeted prominent brands, possibly in an attempt to gain prestige and increased attention by news media.”

Generated Image: Midjourney

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!