Data breach
UPS (Partial)
- Records
- 29,618,000
- Breach date
- 10 October 2025Estimated
- Added
- 3 October 2025
What was exposed
4 types of data
- Email addresses1
- Names1
- Home addresses1
- Phone numbers1
About this breach
UPS is one of dozens of companies whose Salesforce customer data was swept up in a wide-ranging extortion campaign in 2025. A group calling itself Scattered LAPSUS$ Hunters claimed it had stolen data from Salesforce instances belonging to roughly 39 organizations, including UPS, Toyota, FedEx, Disney, and Google, and threatened to publish the data unless the companies or Salesforce paid. According to our investigation team, this listing covers a partial dataset attributed to UPS containing about 29.6 million rows, added to our index on October 3, 2025, with an estimated attack date around October 10, 2025. The attackers, who reported the data came from a voice phishing campaign against company employees rather than a hack of Salesforce itself, released samples of stolen records in early October and set an October 10, 2025 deadline for ransom negotiations. Salesforce said it would not negotiate with or pay any extortion demand.
Breach Timeline
Early October 2025: Scattered LAPSUS$ Hunters launched a leak site listing 39 companies, including UPS, whose Salesforce data it claimed to hold, as reported by Help Net Security and SecurityWeek.
October 3, 2025: The group published samples of data from several targeted companies, and our investigation team indexed the UPS-related records, per KrebsOnSecurity.
October 8, 2025: A Salesforce spokesperson confirmed the company "will not engage, negotiate with, or pay any extortion demand," according to Help Net Security.
October 10, 2025: The hackers' stated deadline for victims to begin ransom negotiations, after which they threatened to release the full datasets.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names
Email addresses
Phone numbers
Home addresses
The catalog for this listing does not include counts for each data type, and it does not indicate that Social Security numbers, passwords, or payment card details were part of the indexed records. Because the listing is partial, the full contents of the stolen UPS data may differ from what has been indexed so far.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Names, email addresses, phone numbers, and home addresses are the raw material for targeted scams. Criminals can use them for phishing emails, smishing texts, and phone calls that appear more convincing because the caller knows your name and location. Package delivery themes are a common lure, so a message referencing a UPS shipment may seem credible. Exposed addresses can also support mail fraud attempts or attempts to verify your identity elsewhere. Financial account takeover is less likely with this data alone, but combined with details gathered from other breaches or public sources, it can strengthen social engineering attacks.
What Should You Do If You Were Affected?
Be skeptical of unexpected emails, texts, or calls about shipments, invoices, or account problems, even when they cite accurate personal details. Do not click links or share codes from unsolicited messages.
Verify any delivery or account notice by going directly to the company's official website or app rather than following links in a message.
Use unique passwords and multi-factor authentication on your email and important accounts, since contact data from one breach is often combined with credentials from others.
Watch for suspicious account activity and report attempted scams to the Federal Trade Commission at reportfraud.ftc.gov.
In the news
- KrebsOnSecurity: ShinyHunters Wage Broad Corporate Extortion Spreekrebsonsecurity.com (opens in a new tab)
- SecurityWeek: Hackers Extorting Salesforce After Stealing Data From Dozens of Customerssecurityweek.com (opens in a new tab)
- Help Net Security: Hackers launch data leak site to extort 39 victimshelpnetsecurity.com (opens in a new tab)
- Hackread: ShinyHunters leak data from Qantas, Vietnam Airlines and othershackread.com (opens in a new tab)
