A significant automaker simply skilled a knowledge breach that might have an effect on tens of thousands and thousands of shoppers.
Stellantis, the carmaker behind Jeep, Fiat, Chrysler, and Dodge, acknowledged on Sunday in a press launch that it “not too long ago” uncovered “unauthorized entry” to a third-party service platform a part of its customer support operations in North America.
“We’re additionally notifying the suitable authorities and straight informing affected clients,” Stellantis wrote within the press launch. The discharge notes that whereas contact data was uncovered, monetary data was not. The assertion didn’t specify the sorts of contact data affected.
Associated: Jaguar Land Rover Shuts Down Manufacturing After Cyberattack, Costing the Firm Greater than a Billion So Far
Stellantis, which was created in 2021 following the merger of Fiat Chrysler Vehicles and PSA Group, is the world’s fifth-largest automaker by gross sales quantity.
The automobile firm didn’t reveal the variety of folks impacted by the breach. Nonetheless, the ShinyHunters cybercriminal group claimed accountability for the assault and informed tech web site BleepingComputer on Monday that it had stolen greater than 18 million Salesforce information from Stellantis, together with names and speak to data.
A 2025 Stellantis Jeep Wrangler, a 2025 Stellantis Ram 1500, and a 2025 Stellantis Jeep Grand Wagoneer. Photographer: Kent Nishimura/Bloomberg through Getty Photos
ShinyHunters has been going after high-profile Salesforce clients because the starting of the 12 months through the use of voice phishing assaults to steal information. Google confirmed in June that ShinyHunters was liable for a knowledge breach affecting one among its personal Salesforce databases that contained details about small and medium-sized companies.
Louis Vuitton and insurance coverage firm Allianz Life additionally skilled information breaches in July that had been linked to the ShinyHunters group.
In accordance with the Nationwide CIO Assessment, ShinyHunters employs a constant assault technique: Somebody calls an organization worker pretending to be IT assist and has them obtain an app, which grants the attacker entry to buyer information. The attacker then steals data like names, emails, and telephone numbers, and calls for ransom funds from the corporate to cease the publication of the info.
ShinyHunters informed BleepingComputer that it had stolen over 1.5 billion Salesforce information from 760 corporations in whole thus far.
A significant automaker simply skilled a knowledge breach that might have an effect on tens of thousands and thousands of shoppers.
Stellantis, the carmaker behind Jeep, Fiat, Chrysler, and Dodge, acknowledged on Sunday in a press launch that it “not too long ago” uncovered “unauthorized entry” to a third-party service platform a part of its customer support operations in North America.
“We’re additionally notifying the suitable authorities and straight informing affected clients,” Stellantis wrote within the press launch. The discharge notes that whereas contact data was uncovered, monetary data was not. The assertion didn’t specify the sorts of contact data affected.
The remainder of this text is locked.
Be a part of Entrepreneur+ in the present day for entry.
