# Salesforce Attacks Expand as Icarus Leaks Data

> The Icarus group expanded Salesforce attack impact by leaking data from newly identified victims, indicating broader initial exploitation.

**URL:** https://www.ciptadusa.com/blog/salesforce-attacks-expand-icarus-leaks-20260624  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-06-24  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-06/daily-appsec-20260624-014630.jpg  

## Article

Attacks against the Salesforce platform are expanding. The threat actor group known as Icarus has leaked data from organizations not previously identified as victims — widening the scope of an incident originally thought to be contained.

## Summary

The Icarus group expanded the impact of Salesforce attacks by leaking data from newly identified victims, indicating the initial exploitation was far broader than early assessments suggested.

## Challenge

Salesforce as the dominant CRM platform stores sensitive data ranging from customer records and transaction histories to internal business communications. When a single Salesforce instance is compromised, the blast radius extends to partners, vendors, and customers of the affected organization.

**Dark Reading** reports that Icarus — a threat actor previously linked to Salesforce misconfiguration exploitation — is now leaking data from additional organizations. This signals that the initial access obtained was broader than what was reported during the first incident response cycle.

The attack pattern is consistent: exploitation of overly permissive sharing rules, guest user access left enabled by default, and over-provisioned API permissions. No zero-days involved — rather an accumulation of configuration mistakes that each appear minor but together provide full access.

## Implications

**For security teams** — Salesforce configuration audits are no longer optional. Three critical areas require immediate validation:
1. **Guest user profiles** — ensure they cannot access sensitive objects
2. **Sharing rules** — review every rule using "All Internal Users" or "Public Groups"
3. **Connected Apps and API users** — inventory and revoke inactive ones

**For the broader market** — Salesforce adoption in enterprise continues to grow across Southeast Asia. Many implementations are performed by integration partners using default configurations that never get hardened. A single Salesforce configuration audit today could prevent becoming the next name on the Icarus leak list.

Minimum action: run the built-in Salesforce Health Check (Setup > Health Check) and ensure a score above 80%. Below that threshold, configurations need immediate remediation.

## References

- [Scope of Salesforce Attacks Expands as Icarus Leaks Data](https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data) — Dark Reading
- [Salesforce Security Health Check](https://help.salesforce.com/s/articleView?id=sf.security_health_check.htm) — Salesforce Official Documentation

---

*Markdown version of https://www.ciptadusa.com/blog/salesforce-attacks-expand-icarus-leaks-20260624 — generated for AI agents and LLM crawlers.*
