Salesforce said it would not negotiate with or pay an extortion demand tied to data that attackers claimed covered 989.45 million records. That figure came from the threat actors, not an independently verified count. Contemporary reporting described customer data accessed through earlier intrusions, including activity involving Salesloft’s Drift application—not a confirmed compromise of Salesforce’s core platform.
Did Salesforce refuse to pay a ransom?
Yes. Salesforce spokesperson Allen Tsai told The Register on October 8, 2025: “Salesforce will not engage, negotiate with, or pay any extortion demand.” Salesforce also said it was supporting affected customers.
Did Salesforce get hacked?
The available contemporaneous account does not establish that Salesforce’s core platform was breached. In an October 2, 2025 update quoted by The Register, Salesforce said there was “no indication that the Salesforce platform has been compromised” and that the activity was not related to a known vulnerability in its technology. It described the extortion attempts as related to “past or unsubstantiated incidents.”
That distinction matters: a customer’s Salesforce data can be exposed through stolen credentials or an integrated application without showing that Salesforce’s own platform was penetrated. The Register reported that some data theft was linked to an earlier compromise of Salesloft’s Drift application, which integrates with Salesforce. Attackers reportedly stole OAuth tokens and used them to access multiple Salesforce customer instances. This was a reported third-party integration and token-access route, not evidence of a Salesforce platform vulnerability.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- Hardware encrypted drive
- Simple to use pin access. RPM-5400
- Administrator password feature
- Bus powered
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
What did the attackers claim, and what is confirmed?
The group identified in The Register’s October 2025 coverage as Scattered LAPSUS$ Hunters claimed 989.45 million records. That is the attackers’ stated figure, not a verified exposure total; the reporting reviewed here did not establish an independent forensic count or final scope.
| Detail | What contemporaneous reporting said |
|---|---|
| Records | The threat group claimed 989.45 million; no independent verified total was established in the cited reporting. |
| Organizations | The Register said the group listed 39 companies’ Salesforce environments on October 3, 2025. |
| Deadline | The group reportedly set October 10, 2025, as its deadline for Salesforce to negotiate. |
SANS NewsBites, in its October 10, 2025 issue, also summarized Salesforce’s refusal and described the demand as concerning data from earlier intrusions, including the Salesloft Drift breach. SANS NewsBites and Information Security Media Group likewise reported the refusal and treated the group’s scope figures as claims.
Rank #2
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
- Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
- Software Free Design - With no admin rights needed
- Sealed from Physical Attacks by Tough Epoxy Coating
- Brute Force Self Destruct Feature
What happened after the October 10 deadline?
The contemporaneous reports cited here do not establish whether the threatened data was published after the deadline or what the final verified exposure scope was. The Register reported that Salesforce and Google had notified organizations believed to be affected before the group’s leak-site post appeared. Without verified later findings, neither publication of the data nor a final breach total should be presented as settled.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this means for Salesforce customers
The reports point to a risk involving particular customer environments and an integrated third-party application, rather than evidence that every Salesforce customer was affected. Organizations using connected applications can review which integrations have access to their Salesforce environment and follow Salesforce’s direct incident communications. The reporting does not provide a complete list of affected organizations or establish which individual customers’ data was exposed.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




