ZeroHour

scattered lapsus$ hunters

Ransomware / extortion group tracked from leak-site posts

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
0
All-time (tracked)
51since 2025-10-03
Last post
10-11 06:57UTC
Estimated earnings
public reporting
Profile not written yet: the pipeline profiles the most active groups first, a few per run.

Leak-site victims

VictimDiscoveredDetails
Salesforce, Inc. · Oct 3, 2025This message serves as formal notification that Salesforce, Inc. has been hacked by us and faced a major information security breach. Near 1 billion records containing sensitive Personally Identifiable Information (PII) have been exfiltrated from your systems. The processed data we took includes information subject to a lot of privacy regulations. As we have it in our possession, you are directly facing cross-border legal exposure. Other records hold strategic value, which could compromise Salesforce, Inc.’s market position if released. We also dumped over 100+ other unnamed instances because you do not enforce 2FA or any other type of OAuth Apps security. Failure to meet these demands will ultimately have us release all of the compromised data and you will be dealing with the escalation of all consequences described above. Because you had no preventive measures in place you will be dealing with them a lot. A lot more information about full lists of companies and each of their data samples can be provided to you, if requested. Unless you comply with our demand, as of 10/10/25 (deadline), we will be openly complying with the many law firms that are pursuing civil and commercial litigation against you. Specifically, we will be cooperating with the Berger Montague Law Firm if you do not comply with our request. Not only will we provide them with full lists of affected companies along with the information on the breach and data samples of each affected companies, we will also be contacting said companies and affected individuals from each companies with instructions to aid law firms with their lawsuits against your company. We will also be documenting publicly how your company made little to no attempt to prevent unauthorised access to PII, which contained, including but not limited to, Driver Licenses, Date of Births, Social Security Numbers, and more. For example, we e-mail taunted you from shinygroup[at]tuta[.]com in July 2025 and you never took any further…

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .