ShinyHunters Steals 1.5B Salesforce Records in Drift Hacks
- Okay, here's a summary of the details provided, focusing on the key takeaways:
- A significant data breach is impacting numerous major companies, stemming from a compromise of the Salesloft and Drift applications - both integrated with Salesforce.
- * Google * Cloudflare * Zscaler * Tenable * Cyberark * Elastic * beyondtrust * Proofpoint * JFrog * Nutanix * Qualys * Rubrik *...
Okay, here’s a summary of the details provided, focusing on the key takeaways:
Major Supply Chain Attack Targeting Salesforce Customers
A significant data breach is impacting numerous major companies, stemming from a compromise of the Salesloft and Drift applications – both integrated with Salesforce. Affected companies include:
* Google
* Cloudflare
* Zscaler
* Tenable
* Cyberark
* Elastic
* beyondtrust
* Proofpoint
* JFrog
* Nutanix
* Qualys
* Rubrik
* Cato Networks
* Palo Alto Networks
* And many more (as indicated by the “many more” link).
Attribution & FBI Involvement
* The attacks are attributed to threat actors identified as UNC6040 and UNC6395.
* The FBI has issued an advisory regarding these groups, including Indicators of Compromise (IOCs) to help organizations detect and respond to the threat.
* These groups are believed to be associated with the larger hacking group Scattered Spider.
Scattered Spider’s “Going Dark” Announcement
* The threat actors claiming affiliation with Scattered Spider announced they are ceasing communication about their operations on Telegram.
* Before doing so, they claimed to have breached Google’s law Enforcement Request System (LERS).
In essence, this is a widespread and serious supply chain attack with significant implications for data security across a large number of organizations. The FBI’s involvement highlights the severity of the situation. The attackers’ decision to go silent suggests they may be preparing for new operations or attempting to evade detection.
