Google says hackers loosely affiliated with the Com in the US, the UK, and Western Europe breached 20+ companies in the US and Europe to steal Salesforce data
- Hacker gang impersonate IT staff to gain access to Salesforce — Retailers warned to be vigilant after recent jump in attacks
Context & Ripple Effects
Google’s account identifies social engineering against Salesforce access as the entry point, with retailers specifically warned amid a rise in such attacks. Later coverage broadened the Salesforce exposure: a Gainsight-linked supply-chain incident affected more than 200 companies, while Cloudflare disclosed access to its Salesforce customer-support instance in a separate Salesloft Drift breach.
The story matters because customer-management systems concentrate sensitive business and support data behind workforce identities. It connects this campaign to a wider run of cloud-application intrusions rather than a single company-specific failure.
First-order effects
- The more than 20 affected companies must assess Salesforce access obtained through IT-staff impersonation, including what data may have been taken and which accounts or sessions require remediation.
- Retailers and other Salesforce users face an immediate need to strengthen verification around help-desk and identity-related requests, the technique identified in Google’s account.
Second-order effects
- Salesforce customers will put greater scrutiny on identity controls and third-party support workflows, since an attacker who persuades staff can bypass the value of the underlying SaaS platform’s security controls.
- The subsequent expansion to a much larger Gainsight-linked Salesforce data theft makes vendors connected to customer-data environments a higher-priority review area, not just direct Salesforce administrators.
Third-order effects
- If these campaigns continue, security accountability will increasingly center on identity proofing and the operational supply chain around SaaS data, rather than on the cloud application alone.
- Repeated breaches involving shared customer-data systems could push enterprises toward tighter access segmentation and more explicit contractual security requirements for support and integration providers.
The trend: Cloud-data attacks are increasingly targeting the human identity and vendor relationships that govern access to high-value SaaS systems.