分散的 LAPSUS$ Hunters 以第三方违规为由,要求支付 989.45 美元,以防止泄露 40 家公司的 10 亿条 Salesforce 记录。
Scattered LAPSUS$ Hunters demands $989.45 to prevent release of 1 billion Salesforce records from 40 firms, citing third-party breaches.
一个自称自己为 " 散落的LAPSUS猎人 " 的网络犯罪集团又卷土重来,威胁要释放大约40家公司的10亿份销售联盟记录,除非在10月10日前支付989.45美元的赎金。
A cybercriminal group calling itself Scattered LAPSUS$ Hunters has resurfaced, threatening to release 1 billion Salesforce records from about 40 companies unless a $989.45 ransom is paid by October 10.
该组织声称使用网络钓鱼和社会工程通过受损的第三方集成(特别是 Salesloft Drift)访问数据。
The group claims to have accessed data through compromised third-party integrations, particularly Salesloft Drift, using phishing and social engineering.
Salesforce 否认其平台遭到破坏,并表示攻击针对的是用户和第三方应用程序,而不是其基础设施。
Salesforce denies its platform was breached, stating attacks targeted users and third-party apps, not its infrastructure.
Google和联邦调查局证实了该运动的策略,包括将抽样数据张贴在黑暗网站。
Google and the FBI confirm the campaign’s tactics, which include posting sample data on a dark web site.
受影响的组织已接到通知,至少有14起对销售联盟提起诉讼。
Affected organizations were notified, and at least 14 lawsuits have been filed against Salesforce.
该团伙的名称提到过去网络犯罪团伙尽管被捕,但现在仍然与正在进行的活动有关联。
The group’s name references past cybercrime gangs now linked to ongoing activities despite arrests.