Mass Salesforce Hacks: How Criminals Are Targeting the Cloud Supply Chain episode artwork

EPISODE · Aug 19, 2025 · 14 MIN

Mass Salesforce Hacks: How Criminals Are Targeting the Cloud Supply Chain

from Cyberside Chats: Cybersecurity Insights from the Experts · host Chatcyberside

A wave of coordinated cyberattacks has hit Salesforce customers across industries and continents, compromising millions of records from some of the world’s most recognized brands — including Google, Allianz Life, Qantas, LVMH, and even government agencies.  In this episode of Cyberside Chats, Sherri Davidoff and Matt Durrin break down how the attackers pulled off one of the most sweeping cloud compromise campaigns in recent memory — using no zero-day exploits, just convincing phone calls, malicious connected apps, and gaps in cloud supply chain security.  We’ll explore the attack timeline, parallels to the Snowflake breaches, ties to the Scattered Spider crew, and the lessons security leaders need to act on right now.    Key Takeaways  Use phishing-resistant MFA — FIDO2 keys, passkeys.  Train for vishing resistance — simulate phone-based social engineering.  Monitor for abnormal data exports from SaaS platforms.  Lockdown your Salesforce platform — vet and limit connected apps.  Rehearse rapid containment — revoke OAuth tokens, disable accounts fast.    References  Google - The Cost of a Call: From Voice Phishing to Data Extortion   Salesforce – Protect Your Salesforce Environment from Social Engineering Threats  BleepingComputer – ShinyHunters behind Salesforce data theft at Qantas, Allianz Life, LVMH  TechRadar – Google says hackers stole some of its data following Salesforce breach  LMG Security Blog – Our Q3 2024 Top Control is Third Party Risk Management: Lessons from the CrowdStrike Outage 

A wave of coordinated cyberattacks has hit Salesforce customers across industries and continents, compromising millions of records from some of the world’s most recognized brands — including Google, Allianz Life, Qantas, LVMH, and even government agencies.  In this episode of Cyberside Chats, Sherri Davidoff and Matt Durrin break down how the attackers pulled off one of the most sweeping cloud compromise campaigns in recent memory — using no zero-day exploits, just convincing phone calls, malicious connected apps, and gaps in cloud supply chain security.  We’ll explore the attack timeline, parallels to the Snowflake breaches, ties to the Scattered Spider crew, and the lessons security leaders need to act on right now.    Key Takeaways  Use phishing-resistant MFA — FIDO2 keys, passkeys.  Train for vishing resistance — simulate phone-based social engineering.  Monitor for abnormal data exports from SaaS platforms.  Lockdown your Salesforce platform — vet and limit connected apps.  Rehearse rapid containment — revoke OAuth tokens, disable accounts fast.    References  Google - The Cost of a Call: From Voice Phishing to Data Extortion   Salesforce – Protect Your Salesforce Environment from Social Engineering Threats  BleepingComputer – ShinyHunters behind Salesforce data theft at Qantas, Allianz Life, LVMH  TechRadar – Google says hackers stole some of its data following Salesforce breach  LMG Security Blog – Our Q3 2024 Top Control is Third Party Risk Management: Lessons from the CrowdStrike Outage

NOW PLAYING

Mass Salesforce Hacks: How Criminals Are Targeting the Cloud Supply Chain

0:00 14:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Cyberside Chats: Cybersecurity Insights from the Experts?

This episode is 14 minutes long.

When was this Cyberside Chats: Cybersecurity Insights from the Experts episode published?

This episode was published on August 19, 2025.

What is this episode about?

A wave of coordinated cyberattacks has hit Salesforce customers across industries and continents, compromising millions of records from some of the world’s most recognized brands — including Google, Allianz Life, Qantas, LVMH, and even government...

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Cyberside Chats: Cybersecurity Insights from the Experts episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!