A Look Back at the Top Ransomware Attack Targeting the Salesforce Supply Chain

Several high-impact ransomware operations in 2025 leveraged SaaS supply chain access to infiltrate enterprise environments. Among them, the Salesforce SaaS supply chain attack stood out for its scale and cross-sector impact. Threat actors reportedly exploited trusted integrations and harvested OAuth tokens to pivot into downstream customer environments. The consequences included large-scale data exposure, CRM compromise, and multisector operational disruption.

Security researchers published1,2 multiple IoCs tied to the campaign. After consolidating and validating the original lists, we analyzed 39 IoCs in total.

Our investigation led to these discoveries:

  • One domain tagged as an IoC was deemed likely to turn malicious 76 days before being dubbed as such
  • 1,722 potential victim IP addresses communicated with 24 IP addresses identified as IoCs
  • 405 email-connected domains, four of which turned out to be malicious
  • Two additional IP addresses, both of which turned out to be malicious
  • 11 IP-connected domains
  • 7,900 string-connected domains, six of which turned out to be malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://otx.alienvault.com/pulse/68b92a8539a07aca04fef136
  • [2] https://www.seqrite.com/blog/google-salesforce-breach-unc6040-threat-research/
Try our WhoisXML API for free
Get started