{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"},"incident":{"slug":"2025-adidas-customer-data-stolen-through-third-party-customer-service-provide","title":"Adidas customer data stolen through third-party customer service provider","date":"2025-05","date_precision":"month","year":2025,"victim_org":"Adidas","sector":"Retail","country":"Germany","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040 (reported)","summary":"Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.","how_it_worked":"Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.","lessons":"Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.","confidence":"Reported","sources":[{"title":"April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider","url":"https://www.rescana.com/post/april-2025-adidas-data-breach-supply-chain-attack-via-third-party-customer-service-provider","publisher":"Rescana"},{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-adidas-customer-data-stolen-through-third-party-customer-service-provide"}}