Data leak

Stellantis Salesforce ShinyHunters Vishing Breach

πŸ“… 2025-07-01 🏒 Salesforce
Primary Source β†—

Incident Details

Stellantis, the multinational automotive manufacturer (maker of Jeep, Chrysler, Fiat, Peugeot, and other brands), disclosed in September 2025 that a breach via its Salesforce platform had exposed customer contact information. The breach was attributed to the ShinyHunters/Scattered Spider social engineering campaign that compromised Salesforce environments at multiple large enterprises in 2025. Exposed data included customer names, email addresses, and other contact information. Part of the broader 2025 Salesforce campaign that also affected TransUnion (44M+), Air France-KLM, Cisco, Pandora, Chanel, and Farmers Insurance.

Technical Details

Initial Attack Vector
ShinyHunters compromised Stellantis's Salesforce environment through vishing/social engineering of a Salesforce-privileged user, part of the broader 2025 ShinyHunters Salesforce campaign
Vendor / Product
Salesforce

Timeline

  1. 2025-07-01 Breach occurred
  2. 2025-09-20 Publicly disclosed
  3. 2025-09-20 Customers notified