/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Lapsus$ publishes a data leak site on the dark web that threatens to release ~1B records allegedly stolen from dozens of companies' Salesforce-hosted databases

Lorenzo Franceschi-Bicchierai Zack Whittaker  —  A notorious predominantly English-speaking hacking group has launched a website …

TechCrunch

Context & Ripple Effects

Lapsus$ previously emerged as a data-extortion group that used employee-focused intrusion tactics, documented in an earlier profile of its extortion model. Its alleged publication plan extends that established playbook from individual-company incidents to a shared cloud-software target.

The claim follows a recent report that another group allegedly obtained Salesforce records through compromised Salesloft Drift OAuth tokens, putting third-party access to Salesforce data under heightened scrutiny. The overlap makes attribution and scope validation especially important for affected companies.

First-order effects

  • Companies whose Salesforce-hosted data is allegedly included face immediate extortion, incident-response and customer-notification decisions, even before the claimed records are independently verified.
  • Salesforce and the named customer organizations will face pressure to establish whether the alleged data came from their environments, connected applications or another source.

Second-order effects

  • Security teams are likely to accelerate reviews of privileged accounts, connected apps and OAuth access around Salesforce, as a public leak threat raises the cost of delayed scope assessment.
  • A multi-company claim can shift attention from one-off victim remediation to shared vendors and integration paths; customers may demand clearer evidence and guidance from their software providers.

Third-order effects

  • If repeated, large leak sites tied to shared enterprise platforms could make identity and third-party integration controls a central competitive and procurement issue for SaaS ecosystems.
  • The pattern reinforces data extortion as a public-pressure business model: the credibility of the claimed dataset, rather than merely the intrusion itself, becomes a key lever in negotiations.

The trend: Enterprise breaches are increasingly being framed around shared SaaS access and public extortion channels, concentrating security risk across many customers at once.

Discussion

  • @zackwhittaker.com Zack Whittaker on bluesky
    NEW: A prolific English-speaking hacking and extortion group has published a data leak site claiming the theft of 1 billion records from companies who store their customer data in Salesforce databases.  —  The hackers claim to have stolen data Qantas, Stellantis, FedEx, Hulu, and…
  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    Several hacked companies, including Workday, don't appear on the hackers' dark web leak site.  —  I asked the hackers why, such as if the companies paid them a ransom.  ShinyHunters acknowledged that “there are numerous other companies that have not been listed,” but declined to …