Data leak
Air France-KLM Salesforce ShinyHunters Breach
Primary Source βIncident Details
Air France-KLM, the Franco-Dutch multinational airline group, disclosed in August 2025 that their Salesforce CRM environment had been compromised as part of the ShinyHunters/Scattered Spider Salesforce social engineering campaign. Exposed data included customer names, email addresses, phone numbers, Flying Blue frequent flyer rewards details, and transaction history. Air France-KLM notified affected customers and filed notifications with French (CNIL) and Dutch (AP) data protection authorities. Part of the broader 2025 Salesforce campaign also affecting TransUnion (44M+), Cisco, Pandora, Chanel, Stellantis, and Farmers Insurance.
Technical Details
- Initial Attack Vector
- ShinyHunters compromised Air France-KLM's Salesforce CRM environment through social engineering / vishing of a Salesforce-privileged employee, part of the broader 2025 ShinyHunters Salesforce campaign
- Vendor / Product
- Salesforce
Timeline
- 2025-07-01 Breach occurred
- 2025-08-20 Publicly disclosed
- 2025-08-20 Customers notified