Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Hackers breach Salesforce data at 20 companies in US, Europe

A hacking group linked to a collective known as Com has breached Salesforce tools of at least 20 companies in the US and Europe, according to a report by Google’s Threat Analysis Group.

The attackers impersonated IT support personnel, convincing employees to share sensitive credentials or connect malicious applications to their Salesforce accounts.

This allowed them to steal data, which in some cases led to extortion demands months later.

Google noted that these attacks relied on social engineering tactics rather than vulnerabilities in Salesforce’s systems.

In response to the report, Salesforce said that the issues were not due to flaws in its services but rather targeted scams that exploited gaps in user cybersecurity awareness.

The company stressed the importance of strong cybersecurity practices among users.

🔗 Source: Bloomberg


🧠 Food for thought

1️⃣ Social engineering remains hackers’ most effective weapon despite decades of awareness

Social engineering attacks continue to dominate the cybersecurity landscape, with approximately 98% of cyberattacks relying on these psychological manipulation tactics rather than exploiting technical vulnerabilities 1.

The persistence of this attack vector is striking. While the specific technologies have evolved, the core psychological principles exploited by attackers remain unchanged from tactics documented decades ago when Kevin Mitnick popularized the term in the 1990s 2.

Despite organizations investing heavily in technical defenses, the human element remains the weakest link, with studies showing that 68% of successful cyberattacks involve manipulating employees through various forms of deception 3.

The Salesforce attacks demonstrate the continued effectiveness of basic impersonation techniques, such as pretending to be IT support staff, despite years of security awareness training across industries.

This pattern suggests organizations must fundamentally rethink their approach to security awareness, as traditional compliance-based training clearly isn’t effectively addressing the psychological vulnerabilities exploited by attackers.

2️⃣ Retail sector faces disproportionate targeting due to specific vulnerabilities

The retail industry has become a prime target for cybercriminals, with 24% of all global cyberattacks in 2020 targeting retailers and 57% of retail businesses reporting an increase in cyber incidents 4.

Recent Salesforce developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.