LAPSUS$ Publishes Portal Claiming Responsibility for Salesforce Breach, Threatens to Expose Global Brands
Cyber Insider
|
Contributed by: Drex DeFord
Summary
The hacking collective LAPSUS$ has established a new online portal to claim responsibility for a substantial data breach affecting Salesforce products, impacting over 50 prominent companies, including Toyota and FedEx. They allege to have extracted several terabytes of sensitive data, including personal identifiers and corporate information, by exploiting vulnerabilities such as weak OAuth protections and improper two-factor authentication. This incident raises serious concerns about the security of cloud-based services and highlights the need for healthcare organizations, which often use similar systems, to enhance their data protection measures. Failure to address these vulnerabilities could result in significant data exposure and regulatory repercussions as hackers threaten full disclosure of the data by October 2025.