Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
August 14, 2025
No Result
View All Result
Concur News

Home » Google Discloses Breach Exposing Potential Google Ads Customer Details

Google Discloses Breach Exposing Potential Google Ads Customer Details

August 12, 2025
in United States
Reading Time: 3 mins read
Google ads - news.concur.live
Share on LinkedinShare on Whatsapp

Google Confirms Data Breach Involving Potential Google Ads Customers

Google has confirmed that a recent data breach in one of its Salesforce CRM systems exposed the information of potential Google Ads customers.

“We’re writing to let you know about an event that affected a limited set of data in one of Google’s corporate Salesforce instances used to communicate with prospective Ads customers,” reads a data breach notification shared with BleepingComputer.

“Our records indicate basic business contact information and related notes were impacted by this event.”

Consent Foundation

Information Exposed in the Breach

Google stated that the exposed data includes business names, phone numbers, and “related notes” for a Google sales agent to follow up. The company clarified that no payment information was compromised.

It also confirmed that the breach did not affect data stored in Google Ads accounts, Merchant Center, Google Analytics, or other Ads-related products.

Who Was Behind the Attack?

The attack was carried out by threat actors known as ShinyHunters, a group linked to multiple Salesforce-related data theft incidents. They claimed the stolen database contains around 2.55 million records, though it is unclear if there are duplicates.

ShinyHunters told BleepingComputer they worked with members of another hacking group, Scattered Spider, to gain initial access to targeted systems.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

The group now calls themselves “Sp1d3rHunters” to reflect the overlap between the two groups.

How the Breach Happened

The hackers reportedly used social engineering tactics to trick employees into giving away credentials or authorizing a malicious version of Salesforce’s Data Loader OAuth app. Once inside, they downloaded the full Salesforce database and sent ransom emails threatening to release the stolen data.

Google’s Threat Intelligence Group (GTIG) first reported similar Salesforce breaches in June. The company itself fell victim a month later.

Extortion Attempt

Databreaches.net reported that the attackers demanded 20 Bitcoins (around $2.3 million) from Google to avoid leaking the stolen information.

“I don’t care about ransoming Google anyway, I just sent them a bogus email for the lulz of it,” said the threat actor.

ShinyHunters revealed they are now using a custom-built tool to steal data from Salesforce more efficiently. Google confirmed they have seen hackers using Python scripts in place of Salesforce’s Data Loader during recent attacks.



Also read: ABDM Introduces Strong Cybersecurity Steps to Safeguard Digital Health Records

Tags: Data breachData privacyData ProtectiongoogleTechnology

Related Posts

Quick Heal Signs MoU with BHASHINI to Bridge Cybersecurity and Privacy Language Gaps
India

Quick Heal Signs MoU with BHASHINI to Bridge Cybersecurity and Privacy Language Gaps

August 13, 2025
Why Facebook Is Flooded With the Same Privacy Post and the Real Story Behind It
India

Why Facebook Is Flooded With the Same Privacy Post and the Real Story Behind It

August 13, 2025
ABDM Introduces Strong Cybersecurity Steps to Safeguard Digital Health Records
India

ABDM Introduces Strong Cybersecurity Steps to Safeguard Digital Health Records

August 12, 2025
Aishwary
Interview

Interview with Aishwary Gupta on Building AI-Driven Privacy Compliance Across GDPR, CCPA, and India’s DPDPA

August 12, 2025

RECOMMENDED NEWS

Tea App Hit by Major Data Breach; Women-Only Platform Lets Users Review Men

Tea App Hit by Major Data Breach; Women-Only Platform Lets Users Review Men

2 weeks ago
NHS software provider fined £3m over data breach

NHS software provider fined £3m over data breach

5 months ago
India Hosts 53% of Global Capability Centres as Legal Challenges Grow

India Hosts 53% of Global Capability Centres as Legal Challenges Grow

3 weeks ago
Data breach

Man Claims FIITJEE Fraud and Data Breach, Seeks Rs 71,000

4 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Interview Investigation Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager