Google Salesforce Hack: Is Your CRM Customer Data Still Safe?
In June 2025, an internal Salesforce CRM system at Google was hacked. What makes it particularly critical: This system is used specifically to manage customer and contact data of small and medium-sized businesses, meaning it contains information that is especially sensitive for many companies. The attackers, known as ShinyHunters (UNC6040), gained access to contact information and sales notes.
Although the stolen information is considered basic and largely publicly available, it still carries high potential for misuse. This attack is part of a larger, ongoing campaign against Salesforce databases. In addition to Google, companies such as Adidas, Qantas, Cisco, Allianz Life, Pandora, and several LVMH brands were also affected. The clear focus is on exploiting human weaknesses rather than technical vulnerabilities in the Salesforce platform.
Google reacted quickly and was able to stop the unauthorized access within a short time. Nevertheless, the company warns of possible follow-on risks, especially with regard to extortion tactics.
Attack Method — How Google's Data Was Stolen
Social Engineering via Vishing
The hackers used voice phishing, calling employees and posing as internal IT support teams. The goal was to get employees to authorize a manipulated version of the Salesforce Data Loader, often disguised as a seemingly legitimate app with names like "My Ticket Portal."
Technical Execution
The attacks ran through so-called connected apps with OAuth integration. In some cases, custom-built Python scripts were used to automate uploads and downloads and bypass security controls.
The operation was distributed across multiple clusters: UNC6040 handled the initial compromise, while UNC6240 may be responsible for potential extortion and publication activities.
Extortion Risk via Data Leak Sites
Google assumes that ShinyHunters is preparing to publish the data on a data leak site. These platforms are used to make stolen data public and pressure companies into paying ransom. Even seemingly harmless basic data can thus become leverage for targeted follow-up attacks.
Who Is ShinyHunters and What Other Targets Were Hit?
ShinyHunters has been active in the cybercrime scene for years and is known for attacks on major brands and their cloud databases. Affected companies range from Ticketmaster and Santander to luxury brands like Dior and Louis Vuitton.
Their strength lies in combining social engineering, sophisticated deception tactics, and the targeted exploitation of the cloud connectivity of tools like Salesforce. Technical vulnerabilities in the platform are usually bypassed — the focus is on people as the point of entry.
Risks for Companies — What Does This Mean for You?
- Phishing wave: Stolen basic data is often enough to craft deceptively genuine phishing emails or calls
- Reputational damage: Published or misrepresented data can lastingly damage the trust of customers and partners
- Compliance risks: Gaps in access control can lead to fines even when no sensitive data is involved, for example in the case of GDPR violations
- Financial losses: Attacks of this kind can cause follow-up costs in the millions, from incident response to customer communication
Immediate Measures — What Can You Do Now?
| Measure | Description |
|---|---|
| Employee Awareness | Regular training on social engineering, vishing, and cloud security |
| MFA & Least Privilege | Multi-factor authentication on all accounts, granting only the permissions that are strictly necessary |
| Control connected apps | Only allow vetted applications and conduct regular app audits |
| Monitoring & Logging | Suspicious activity, especially in cloud services, monitored automatically |
| Incident Response Plan | Simulate breach scenarios and define clear escalation paths and communication plans |
Practical Example — Pandora
Pandora, a global jewelry retailer, was also affected by this wave of attacks. Customers' names and email addresses were stolen; passwords and payment information remained untouched. Pandora nevertheless warned of possible phishing attempts and urged caution with unexpected messages.
Investigations and Law Enforcement
The attacks did not go unanswered: As early as June 2025, four suspected members of ShinyHunters were arrested in France. Law enforcement agencies from several countries are working together to dismantle the groups' infrastructure.
Despite these successes, the groups have proven highly adaptable — individual cells continue to operate independently and constantly adjust their methods.
Conclusion — and Where heyData Comes In
The Salesforce hack at Google makes one thing clear: Even corporations with huge IT budgets can fall victim to social engineering. Technical safeguards are only half the battle — people remain the weakest link.
This is exactly where heyData can help:
- Instant check of your compliance landscape with a digital audit
- GDPR-compliant processes and documentation in an all-in-one platform
- Trainings on compliance and data protection
- External data protection officers and compliance consulting
With heyData, you get not just tools but also expert knowledge that makes your organization resilient against attacks like this one.
FAQ
Was sensitive data such as passwords stolen from Google?
Was sensitive data such as passwords stolen from Google?
No. Only basic information such as company names, phone numbers, email addresses, and notes was stolen.
Why Salesforce?
Why Salesforce?
Salesforce is a central platform for customer data and accessible globally. That's why attackers rely on social engineering to exploit the human factor.
What is a data leak site?
What is a data leak site?
A website where stolen data is published, usually to put pressure on companies and extort ransom payments.
How quickly do I need to respond?
How quickly do I need to respond?
Immediately. Even a few hours of delay can massively increase the risk, from further data exfiltration to public disclosure.







