Data leak
Stellantis Salesforce ShinyHunters Vishing Breach
Primary Source βIncident Details
Stellantis, the multinational automotive manufacturer (maker of Jeep, Chrysler, Fiat, Peugeot, and other brands), disclosed in September 2025 that a breach via its Salesforce platform had exposed customer contact information. The breach was attributed to the ShinyHunters/Scattered Spider social engineering campaign that compromised Salesforce environments at multiple large enterprises in 2025. Exposed data included customer names, email addresses, and other contact information. Part of the broader 2025 Salesforce campaign that also affected TransUnion (44M+), Air France-KLM, Cisco, Pandora, Chanel, and Farmers Insurance.
Technical Details
- Initial Attack Vector
- ShinyHunters compromised Stellantis's Salesforce environment through vishing/social engineering of a Salesforce-privileged user, part of the broader 2025 ShinyHunters Salesforce campaign
- Vendor / Product
- Salesforce
Timeline
- 2025-07-01 Breach occurred
- 2025-09-20 Publicly disclosed
- 2025-09-20 Customers notified