Salesforce Refuses to Pay Ransomware Crims' Extortion Demand
Threat actors stole nearly 1 billion records via SalesLoft's Drift app in two campaigns and extorted 39 companies, but Salesforce refuses to pay ransom or negotiate.
- Salesforce said it will not negotiate or pay any extortion demand and emailed customers on Tuesday warning of credible threats to leak stolen data.
- Earlier this year, the breach traced back to SalesLoft's Drift app when attackers used social engineering to steal OAuth tokens, accessing customers' Salesforce environments.
- A newly launched leak site listed 39 companies and demanded payment to prevent publication of 989.45 million stolen records, while ShinyHunters claimed to have stolen 1.5 billion records from over 760 companies.
- The data leak site has been shut down and uses nameservers historically deployed by the FBI, while Salesforce is contacting affected customers and keeping the Drift app disabled.
- Criminals set an October 10 deadline, saying they hold nearly 1 billion records and ShinyHunters plans to share data on forums if unpaid.
11 Articles
11 Articles
Salesforce Tells Clients It Won’t Pay Hackers for Data Extortion
Salesforce Inc. told customers Tuesday that it won’t pay a ransom demand from a hacker who claimed to have stolen a large amount of client data and threatened to publish it, according to an email seen by Bloomberg News.
Salesforce Says It Won't Pay Extortion Demand in 1 Billion Records Breach
Salesforce says it's refusing to pay an extortion demand made by a crime syndicate that claims to have stolen roughly 1 billion records from dozens of Salesforce customers. From a report: The threat group making the demands began their campaign in May, when they made voice calls to organizations sto...
Salesforce refuses to submit to extortion demands linked to hacking campaigns
The company said it is aware of recent claims, but will not negotiate or pay a ransom. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: Salesforce refuses to submit to extortion demands linked to hacking campaigns The post Salesforce refuses to submit to extortion demands linked to hacking campaigns appeared first on IT Security News.
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium