Tython

SalesforceSecurity

One Year Since the Billion-Record October

Scott Covert · 

One year ago this week, the Salesforce ecosystem had its worst stretch on record. On October 6, 2025, the Scattered Lapsus$ Hunters collective claimed to hold nearly a billion records stolen from Salesforce customers and stood up a dedicated leak site naming 39 companies–FedEx, Disney, Google, Cisco, Toyota, Marriott, Home Depot, Adidas among them. On October 8, Salesforce publicly refused to pay. On October 10, the FBI seized a BreachForums domain being used for the extortion. None of it involved a Salesforce vulnerability: the records came through vishing calls, stolen OAuth tokens from the Salesloft Drift compromise, and malicious connected apps that employees were talked into authorizing. A year on–and with this summer’s enforcement wave and this spring’s guest user exploitation in the rearview–it’s worth an honest audit: what actually changed, and what didn’t?

What Changed: The Platform Got Harder to Misuse

Credit where due–Salesforce spent the year systematically closing the doors that campaign walked through:

  • Connected app governance got teeth. The enforcement wave restricted how uninstalled connected apps acquire tokens and pushed admins toward explicit allowlisting via API Access Control. The “employee approves a malicious app in one click” path is meaningfully narrower than it was.
  • Credential lifetimes got finite. The 180-day client secret rotation policy for Marketing Cloud–whose first expiry deadline hit September 30–ended the era of integration secrets that outlive the employees who created them.
  • Agent-era controls arrived under disclosure pressure. Trusted URLs hardening, safer Agentforce action defaults, and the rapid SalesBleed patch cycle show a vendor that has internalized the lesson of treating AI agents as attack surface.

What Didn’t Change: The Doors in Your Configuration

The uncomfortable half of the audit is that the attacks kept working wherever the fix required customer action. In January, Salesforce warned that the same crews had pivoted to impersonating IT support against third-party identity providers. In March, FINRA issued an alert about active exploitation of misconfigured Experience Cloud guest user profiles–a configuration failure we were writing about before and after. The Aura breach, roughly 900,000 records, began the way the 2025 wave did: a targeted vishing call to one employee. The platform hardened. The playbook didn’t have to.

Deeper Dive

The Anniversary Scorecard

A year is enough time to judge each link in the 2025 kill chain. Here’s the honest state of each:

  1. Vishing: still the front door. No Salesforce control can prevent an employee from being talked into something on a phone call. The mitigations that work are procedural–callback verification for anything touching credentials or app authorizations, and treating “IT support is calling” as a phishing indicator by default. If your awareness training was updated after October 2025 and still doesn’t include a vishing simulation, it isn’t updated.
  2. OAuth token theft: partially closed. The Drift-style supply chain path–compromise a vendor, harvest the tokens its integration holds–remains structurally possible for any connected app with broad scopes and long-lived refresh tokens. API Access Control and connected app allowlisting bound it, but only in orgs that turned them on. The enforcement wave made the defaults better; it didn’t make your existing app inventory smaller.
  3. Malicious connected apps: meaningfully harder. This is the platform’s clearest win. But audit your historical grants anyway: apps authorized before the enforcement changes retain their access, and token revocation is still a manual decision.
  4. Guest user misconfiguration: unchanged, and still being exploited. The March FINRA alert could have been written in 2021. Secure Guest User Record Access has been default for years, yet sites configured before the defaults–or deliberately opened up–persist. This is pure configuration debt, and it’s the item on this list most likely to be your problem right now.
  5. Extortion infrastructure: disrupted, not destroyed. The FBI seizure took a domain, not an operation. The same actors resurfaced within months under the same umbrella. Assume the data stolen in 2025 is permanently in circulation and plan identity-verification processes accordingly.

The Metric That Matters

If you want a single number to track between this anniversary and the next, make it this: the count of credentials in your org that can access customer data without a human completing MFA. That includes integration users, connected app tokens, API-only accounts, and now agent identities. Every incident in the 2025 wave and its 2026 aftershocks ultimately cashed out as one of those credentials being created, stolen, or abused. The number won’t reach zero–but whether it’s trending down is the truest measure of whether your org learned the year’s lesson.

Our Week 2 CISO Pulse poll is live on LinkedIn now–who explicitly owns your AI agents’ identity and permissions?–and next week we widen the lens to the agent-security reckoning happening across the whole industry.

Book a 15-Minute Security Strategy Call

Reference(s):

https://www.salesforceben.com/salesforce-data-theft-roundup-everything-you-need-to-know/

https://www.upguard.com/blog/salesforce-leak-extortion-scatterered-lapsus-hunters

https://www.finra.org/rules-guidance/guidance/cybersecurity-alert-salesforce-experience-cloud-security-incident

https://en.wikipedia.org/wiki/Scattered_Lapsus$_Hunters

https://www.techtarget.com/searchcio/feature/Salesforce-breach-What-IT-leaders-must-know