Skip to main content
See every side of every news story
Published loading...Updated

Salesforce Refuses to Pay Ransomware Crims' Extortion Demand

Threat actors stole nearly 1 billion records via SalesLoft's Drift app in two campaigns and extorted 39 companies, but Salesforce refuses to pay ransom or negotiate.

  • Salesforce said it will not negotiate or pay any extortion demand and emailed customers on Tuesday warning of credible threats to leak stolen data.
  • Earlier this year, the breach traced back to SalesLoft's Drift app when attackers used social engineering to steal OAuth tokens, accessing customers' Salesforce environments.
  • A newly launched leak site listed 39 companies and demanded payment to prevent publication of 989.45 million stolen records, while ShinyHunters claimed to have stolen 1.5 billion records from over 760 companies.
  • The data leak site has been shut down and uses nameservers historically deployed by the FBI, while Salesforce is contacting affected customers and keeping the Drift app disabled.
  • Criminals set an October 10 deadline, saying they hold nearly 1 billion records and ShinyHunters plans to share data on forums if unpaid.
Insights by Ground AI

11 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 50% of the sources are Center
50% Center

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

Bloomberg broke the news in United States on Tuesday, October 7, 2025.
Sources are mostly out of (0)
News
For You
Search
BlindspotLocal