Google Salesforce Hack: Is Your CRM Customer Data Still Safe?

In June 2025, an internal Salesforce CRM system at Google was hacked. What makes it particularly critical: This system is used specifically to manage customer and contact data of small and medium-sized businesses, meaning it contains information that is especially sensitive for many companies. The attackers, known as ShinyHunters (UNC6040), gained access to contact information and sales notes.

Although the stolen information is considered basic and largely publicly available, it still carries high potential for misuse. This attack is part of a larger, ongoing campaign against Salesforce databases. In addition to Google, companies such as Adidas, Qantas, Cisco, Allianz Life, Pandora, and several LVMH brands were also affected. The clear focus is on exploiting human weaknesses rather than technical vulnerabilities in the Salesforce platform.

Google reacted quickly and was able to stop the unauthorized access within a short time. Nevertheless, the company warns of possible follow-on risks, especially with regard to extortion tactics.

Attack Method — How Google's Data Was Stolen

Social Engineering via Vishing

The hackers used voice phishing, calling employees and posing as internal IT support teams. The goal was to get employees to authorize a manipulated version of the Salesforce Data Loader, often disguised as a seemingly legitimate app with names like "My Ticket Portal."

Technical Execution

The attacks ran through so-called connected apps with OAuth integration. In some cases, custom-built Python scripts were used to automate uploads and downloads and bypass security controls.

The operation was distributed across multiple clusters: UNC6040 handled the initial compromise, while UNC6240 may be responsible for potential extortion and publication activities.

Extortion Risk via Data Leak Sites

Google assumes that ShinyHunters is preparing to publish the data on a data leak site. These platforms are used to make stolen data public and pressure companies into paying ransom. Even seemingly harmless basic data can thus become leverage for targeted follow-up attacks.

Who Is ShinyHunters and What Other Targets Were Hit?

ShinyHunters has been active in the cybercrime scene for years and is known for attacks on major brands and their cloud databases. Affected companies range from Ticketmaster and Santander to luxury brands like Dior and Louis Vuitton.

Their strength lies in combining social engineering, sophisticated deception tactics, and the targeted exploitation of the cloud connectivity of tools like Salesforce. Technical vulnerabilities in the platform are usually bypassed — the focus is on people as the point of entry.

Risks for Companies — What Does This Mean for You?

  • Phishing wave: Stolen basic data is often enough to craft deceptively genuine phishing emails or calls
  • Reputational damage: Published or misrepresented data can lastingly damage the trust of customers and partners
  • Compliance risks: Gaps in access control can lead to fines even when no sensitive data is involved, for example in the case of GDPR violations
  • Financial losses: Attacks of this kind can cause follow-up costs in the millions, from incident response to customer communication

Immediate Measures — What Can You Do Now?

Measure Description
Employee Awareness Regular training on social engineering, vishing, and cloud security
MFA & Least Privilege Multi-factor authentication on all accounts, granting only the permissions that are strictly necessary
Control connected apps Only allow vetted applications and conduct regular app audits
Monitoring & Logging Suspicious activity, especially in cloud services, monitored automatically
Incident Response Plan Simulate breach scenarios and define clear escalation paths and communication plans

Practical Example — Pandora

Pandora, a global jewelry retailer, was also affected by this wave of attacks. Customers' names and email addresses were stolen; passwords and payment information remained untouched. Pandora nevertheless warned of possible phishing attempts and urged caution with unexpected messages.

Investigations and Law Enforcement

The attacks did not go unanswered: As early as June 2025, four suspected members of ShinyHunters were arrested in France. Law enforcement agencies from several countries are working together to dismantle the groups' infrastructure.

Despite these successes, the groups have proven highly adaptable — individual cells continue to operate independently and constantly adjust their methods.

Conclusion — and Where heyData Comes In

The Salesforce hack at Google makes one thing clear: Even corporations with huge IT budgets can fall victim to social engineering. Technical safeguards are only half the battle — people remain the weakest link.

This is exactly where heyData can help:

With heyData, you get not just tools but also expert knowledge that makes your organization resilient against attacks like this one.