Car giant Stellantis confirms data breach after third-party hit by cyberattack
- Stellantis confirms data breach via third-party platform supporting North American customer services
- Attack linked to ShinyHunters, part of broader Salesforce-related data theft campaign
- Customers warned to avoid suspicious emails and remain alert for phishing attempts
Stellantis, one of the world’s largest automakers, confirmed suffering a cyberattack and losing sensitive customer data.
In a short announcement, Stellantis said the breach did not occur within its infrastructure, but rather in a third party service provider’s platform that supports its North American customer service operations.
“Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation,” the company said in the report. “We are also notifying the appropriate authorities and directly informing affected customers.”
ShinyHunters strike again
The report offered little details, as Stellantis noted the personal information involved was “limited to contact information” and that financial, or “sensitive personal information” was not accessed, since it wasn’t stored on company servers in the first place.
It did not detail who the threat actors were, or what they sought out to achieve, but BleepingComputer claims the attack was carried out by ShinyHunters, and that it was part of a recent wave of Salesloft data breaches.
The threat actors reprotedly claimed responsibility for the attack, telling the publication it stole more than 18 million Salesforce records, including names, and contact details.
Stellantis is yet to confirm or deny these claims, but if they turn out to be true, the automotive giant will be added to a long list of major companies that had their data compromised in the Salesloft issues.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Other companies that suffered the same fate include Google, Cloudflare, Zscaler, Palo Alto Networks, Proofpoints, Cato Networks, and many others.
In the meantime, Stellantis urged its customers to remain vigilant against potential phishing attempts, and to be particularly wary of incoming communication claiming to come from the automaker.
Furthermore, it warned the customers not to click on any links in emails, or other forms of communication, especially in those demanding urgent activity or response.
You might also like
Stellantis confirms data breach via third-party platform supporting North American customer services Attack linked to ShinyHunters, part of broader Salesforce-related data theft campaign Customers warned to avoid suspicious emails and remain alert for phishing attempts Stellantis, one of the world’s largest automakers, confirmed suffering a cyberattack and losing sensitive customer…
Recent Posts
- Apple begins requiring age verification for App Store use in Texas
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
- WiiM expands its whole-home ecosystem with a new soundbar
- You can make the hyper-violence in Marvel’s Wolverine more PG-13, if you want to
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023