Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedReported

Stellantis confirms customer data stolen from Salesforce platform

Stellantis · Manufacturing · Netherlands · September 2025

What happened

Stellantis, the automaker behind Jeep, Chrysler, Dodge and Peugeot, confirmed in September 2025 that a third-party service provider supporting its North American customer service operations was breached and customer contact information was taken. Reporting tied the incident to the Salesforce data-theft campaign; the ShinyHunters-linked group claimed to hold around 18 million records, a figure Stellantis did not confirm.

How the deception worked

The campaign this incident is attributed to relied on telephone social engineering rather than exploitation. Callers rang employees at the target or its outsourced customer-service provider, presented themselves as internal IT or the SaaS vendor's support team, and asked the employee to complete an app-authorisation flow in the Salesforce tenant, reading out a connection code that linked an attacker-controlled OAuth application. The abuse of trust was twofold: an authoritative internal-sounding voice and a legitimate-looking vendor consent screen. Employees believed they were resolving a support ticket. The authorised app then allowed bulk extraction of CRM contact records, followed by a private extortion email.

The control that would have caught it· our reading, not a claim from the sources

Third-party contact-centre staff need the same OAuth-consent restrictions and caller-verification rules as internal employees; consent screens should not be reachable by ordinary support accounts.

Sources (2)

  1. Automaker giant Stellantis confirms data breach after Salesforce hack
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. Stellantis confirms data breach involving customers' contact information
    Engadget·engadget.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.