• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Salesforce hack

erek

8=D
2FA
Joined
Dec 19, 2005
Messages
17,816
“Drift massive attack traced back to loose Salesloft GitHub account


Meanwhile the victim count grows​

icon
Jessica Lyons
Mon 8 Sep 2025 // 19:52 UTC
The Salesloft Drift breach that compromised "hundreds" of companies including Google, Palo Alto Networks, and Cloudflare, all started with miscreants gaining access to the Salesloft GitHub account in March.
This new information comes from a Saturday update into the Mandiant-led investigation”

Source: https://www.theregister.com/2025/09/08/drift_breach_entry_salesloft_github/
 

FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data​

"While the FBI did not name the groups behind these campaigns, BleepingComputer was told by the ShinyHunters extortion group that they and other threat actors calling themselves "Scattered Lapsus$ Hunters, were behind both clusters of activity.

This group of hackers claims to have originated from and overlap with the Lapsus$, Scattered Spider, and ShinyHunters extortion groups.

On Thursday, the threat actors announced via a domain associated with BreachForums that they planned to "go dark" and stop discussing operations on Telegram.

However, in a parting post, the hackers claimed to have gained access to the FBI's E-Check background check system and Google's Law Enforcement Request system, publishing screenshots as proof.

If legitimate, this access would allow them to impersonate law enforcement and pull sensitive records of individuals.

When contacted by BleepingComputer, the FBI declined to comment, and Google did not respond to our email."

https://www.bleepingcomputer.com/ne...040-unc6395-hackers-stealing-salesforce-data/
 
I’m already receiving reports of people being contacted and they are name dropping me and others here in an attempt to make themselves seem more credible as they submit fake invoices and such.

This is gonna be bad.
 
  • Like
Reactions: erek
like this
I’m already receiving reports of people being contacted and they are name dropping me and others here in an attempt to make themselves seem more credible as they submit fake invoices and such.

This is gonna be bad.
“ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

hand-sifting-data.jpg

The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.”

https://www.bleepingcomputer.com/ne...ion-salesforce-records-stolen-in-drift-hacks/
 
"Salesforce Says It Won't Pay Extortion Demand in 1 Billion Records Breach (arstechnica.com)11
Posted by msmash on Wednesday October 08, 2025 @04:44PM from the not-negotiating-with-criminals dept.
Salesforce says it's refusing to pay an extortion demand made by a crime syndicate that claims to have stolen roughly 1 billion records from dozens of Salesforce customers. From a report:The threat group making the demands began their campaign in May, when they made voice calls to organizations storing data on the Salesforce platform, Google-owned Mandiant said in June. The English-speaking callers would provide a pretense that necessitated the target connect an attacker-controlled app to their Salesforce portal. Amazingly -- but not surprisingly -- many of the people who received the calls complied."
 
Great, meanwhile all the customers impacted by their breach.....
Curious to see if any of their customers sue....
 
Back
Top