Chanel has confirmed a data breach caused by unauthorized access to its Salesforce customer service database. The attack, which occurred in July 2025, exposed contact details of customers who had interacted with Chanel’s U.S. client care center.
The breach compromised names, email addresses, phone numbers, and mailing addresses. Chanel stated that no financial or payment information was affected. The company launched an internal investigation, activated its incident response plan, and notified impacted individuals.
ShinyHunters Behind the Breach
The ShinyHunters extortion group carried out the attack by targeting a third-party vendor. The group used voice phishing tactics to impersonate IT support staff and convinced employees to install a malicious OAuth app. Once granted access, the attackers extracted data from the connected Salesforce environment.
This method allowed them to bypass traditional login safeguards, including multi-factor authentication, and gain access to customer records through legitimate API functionality.
Part of a Larger Campaign
Attackers also targeted other luxury and travel companies in this wave of breaches. They compromised Salesforce integrations across multiple brands as part of a broader campaign that hijacks trusted cloud platforms using deceptive app installations and credential harvesting.
The attackers often used realistic app names and interfaces to lower suspicion. In some cases, OAuth tokens granted long-term access, making detection difficult until large volumes of data had already been extracted.
What Was Exposed
While Chanel confirmed that no financial data was leaked, the compromised information still includes:
- Full names
- Email addresses
- Physical addresses
- Phone numbers
- Case IDs or reference numbers from past support interactions
This data could be used in targeted phishing attacks, impersonation scams, or further social engineering attempts.
Security Lessons and Industry Risks
This attack highlights the increasing risk associated with third-party service providers and cloud CRM platforms. Even without a vulnerability in Salesforce itself, the attackers used social engineering to exploit authorized access points. Luxury brands and global businesses are particularly attractive targets due to the high value of customer data.
To prevent similar incidents, organizations should:
- Restrict third-party OAuth access
- Conduct routine audits of connected applications
- Train staff to recognize phishing and vishing attempts
- Use anomaly detection tools to identify unusual API activity
- Enforce strict access controls and app approval policies
Conclusion
The Chanel Salesforce attack reflects a rising trend of cybercriminals targeting cloud service integrations through social engineering. The breach created serious reputational and security risks by exposing customer contact information, even though it did not involve payment data. Companies using CRM platforms must remain vigilant and ensure both human and technical defenses are in place.


0 responses to “Chanel Salesforce Attack Exposes U.S. Customer Data in ShinyHunters Hack”