
Mass Salesforce Hacks: How Criminals Are Targeting the Cloud Supply Chain
About this episode
A wave of coordinated cyberattacks has hit Salesforce customers across industries and continents, compromising millions of records from some of the world’s most recognized brands — including Google, Allianz Life, Qantas, LVMH, and even government agencies.
In this episode of Cyberside Chats, Sherri Davidoff and Matt Durrin break down how the attackers pulled off one of the most sweeping cloud compromise campaigns in recent memory — using no zero-day exploits, just convincing phone calls, malicious connected apps, and gaps in cloud supply chain security.
We’ll explore the attack timeline, parallels to the Snowflake breaches, ties to the Scattered Spider crew, and the lessons security leaders need to act on right now.
Key Takeaways
- Use phishing-resistant MFA — FIDO2 keys, passkeys.
- Train for vishing resistance — simulate phone-based social engineering.
- Monitor for abnormal data exports from SaaS platforms.
- Lockdown your Salesforce platform — vet and limit connected apps.
- Rehearse rapid containment — revoke OAuth tokens, disable accounts fast.
References
- BleepingComputer – ShinyHunters behind Salesforce data theft at Qantas, Allianz Life, LVMH
Get every episode summarized
Each time Cyberside Chats: Cybersecurity Insights from the Experts publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Cyberside Chats: Cybersecurity Insights from the Experts

AI Collusion? Inside the OpenAI–Hugging Face Attack
Cyberside Chats: Cybersecurity Insights from the Experts

Your Security Tools Can Be Used Against You
Cyberside Chats: Cybersecurity Insights from the Experts

Zoomsday: Anyone in Your Meeting Can Own You
Cyberside Chats: Cybersecurity Insights from the Experts

AI vs. AI: Hacking the Agent, Not the Human
Cyberside Chats: Cybersecurity Insights from the Experts