Automaker giant Stellantis confirms data breach after Salesforce hack
Stellantis遭遇数据泄露事件,攻击者通过入侵第三方服务提供商平台获取了北美部分客户的联系信息。未涉及财务或敏感个人信息。公司已启动应急响应并通知相关部门及受影响客户。此次事件可能与ShinyHunters勒索团伙有关,该团伙近期针对多个公司的Salesforce平台进行了数据窃取攻击。 2025-9-22 18:15:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:15 收藏

Stellantis

Automotive manufacturing giant Stellantis has confirmed that attackers stole some of its North American customers' data after gaining access to a third-party service provider's platform.

Stellantis is a multinational corporation formed in 2021 after the merger of the PSA Group (Peugeot Société Anonyme) and Fiat Chrysler Automobiles (FCA). Stellantis is currently one of the largest automotive companies globally by revenue and the world's fifth-largest automaker by volume.

The company owns 14 major automotive brands, including Alfa Romeo, Chrysler, Citroën, Dodge, DS Automobiles, Fiat, Jeep, Lancia, Maserati, Opel, Peugeot, Ram, and Vauxhall, and it operates manufacturing facilities across Europe, North America, South America, and other regions, with operations in over 130 countries.

According to a statement published over the weekend, the attackers only stole customer contact information during the breach since the compromised platform was not used to store financial or other sensitive personal information.

"We recently detected unauthorized access to a third-party service provider's platform that supports our North American customer service operations," Stellantis said.

"Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation. We are also notifying the appropriate authorities and directly informing affected customers."

The auto giant also advised customers to be cautious of potential phishing attempts and to refrain from clicking suspicious links or sharing personal information when receiving unexpected emails, texts, or calls.

BleepingComputer reached out to Stellantis with questions about the incident, but a response was not immediately available.

Salesforce data breach claimed by ShinyHunters

Although Stellantis didn't share more information regarding this attack, BleepingComputer has learned that it is part of a recent wave of Salesforce data breaches linked with the ShinyHunters extortion group, which has affected numerous high-profile companies.

Earlier today, ShinyHunters claimed responsibility for the Stellantis data breach and told BleepingComputer that they had stolen over 18 million Salesforce records, including names and contact details, from the company's Salesforce instance.

Since the start of the year, the extortion group has been targeting Salesforce customers in data theft attacks using voice phishing attacks, impacting companies such as Google, Cisco, Qantas, Adidas, Allianz Life, Farmers Insurance, Workday, and LVMH subsidiaries, including Dior, Louis Vuitton, and Tiffany & Co.

ShinyHunters also claims they used stolen OAuth tokens for Salesloft's Drift AI chat integration with Salesforce to steal sensitive information, such as passwords, AWS access keys, and Snowflake tokens, after gaining access to customers' Salesforce instances.

Using this method, they claimed to have stolen customer information from Google, Cloudflare, Zscaler, Tenable, Palo Alto NetworksCyberArk, Nutanix, Qualys, Rubrik, Elastic, BeyondTrust, Proofpoint, JFrogCato Networks, and many more.

Last week, the FBI released a Flash alert sharing IOCs discovered during the attacks and warning about threat actors breaching organizations' Salesforce environments to steal data and extort victims. Meanwhile, the extortion group told BleepingComputer that they had stolen over 1.5 billion Salesforce records from 760 companies, using compromised Salesloft Drift OAuth tokens.


文章来源: https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/
如有侵权请联系:admin#unsafe.sh