A hacking group calling itself Scattered Lapsus$ Hunters claims to have stolen over one billion records from customers’ Salesforce databases—not by attacking Salesforce itself, but by exploiting third-party integrations (notably Salesloft’s Drift) and leveraging OAuth/refresh token access.
The group is demanding nearly US $1 billion in ransom to avoid publicly releasing the stolen data. They have launched a dark-web extortion portal and given victims until Friday October 10, 2025, to begin negotiations.
While Salesforce insists its core platform was not directly compromised and says it won’t pay the ransom, the episode highlights increasing risks in software supply chains, token security, and third-party integrations—especially in cloud environments.
Source: Hackers Claim 1B Salesforce Records Stolen, Demand $1B Ransom


