Data leak
Vietnam Airlines Salesforce Breach via Scattered Lapsus$ Hunters - 23M Records
Primary Source βIncident Details
In October 2025, Scattered Lapsus$ Hunters published 63.62 GB of data (23+ million records) from Vietnam Airlines’ Salesforce CRM system. The initial intrusion occurred around June 2025 as part of the group’s broader campaign targeting 39+ organizations’ Salesforce environments via vishing. Data published October 10, 2025. Vietnam Airlines disclosed the breach on October 14, 2025. Exposed data included customer names, dates of birth, phone numbers, email addresses, and residential addresses. Payment information, passwords, travel itineraries, Lotusmiles loyalty balances, and passport details were not compromised. Have I Been Pwned indexed 7.3 million unique email addresses from the dataset.
Technical Details
- Initial Attack Vector
- Scattered Lapsus$ Hunters (ShinyHunters) breached Vietnam Airlines' Salesforce CRM instance as part of a campaign targeting 39+ companies via malicious OAuth app linked through vishing of employees
- Vendor / Product
- Salesforce CRM
Timeline
- 2025-06-01 Breach occurred
- 2025-10-10 Publicly disclosed
- 2025-10-14 Customers notified