Data leak

Air France-KLM Salesforce ShinyHunters Breach

πŸ“… 2025-07-01 🏒 Salesforce
Primary Source β†—

Incident Details

Air France-KLM, the Franco-Dutch multinational airline group, disclosed in August 2025 that their Salesforce CRM environment had been compromised as part of the ShinyHunters/Scattered Spider Salesforce social engineering campaign. Exposed data included customer names, email addresses, phone numbers, Flying Blue frequent flyer rewards details, and transaction history. Air France-KLM notified affected customers and filed notifications with French (CNIL) and Dutch (AP) data protection authorities. Part of the broader 2025 Salesforce campaign also affecting TransUnion (44M+), Cisco, Pandora, Chanel, Stellantis, and Farmers Insurance.

Technical Details

Initial Attack Vector
ShinyHunters compromised Air France-KLM's Salesforce CRM environment through social engineering / vishing of a Salesforce-privileged employee, part of the broader 2025 ShinyHunters Salesforce campaign
Vendor / Product
Salesforce

Timeline

  1. 2025-07-01 Breach occurred
  2. 2025-08-20 Publicly disclosed
  3. 2025-08-20 Customers notified