2025 Stellantis — third-party Salesforce breach; North American customer contact data (ShinyHunters campaign)
Data compromised
Customer contact information for North American operations (names and contact details per company); Stellantis stated no financial or sensitive personal data on the affected platform; ShinyHunters claimed ~18M Salesforce records—unverified by automaker
Technical writeup
Verified automaker disclosure — September 2025. Stellantis N.V., parent of Jeep, Ram, Chrysler, Dodge, Fiat, and Peugeot brands, confirmed unauthorized access to a third-party service provider platform used for North American customer-service operations, with incident activity placed in May 2025 by industry reporting. Stellantis activated incident response, investigated, contained the situation, notified authorities, and began alerting affected customers. The company said only contact information was involved and that the platform does not store financial or other sensitive personal data. SecurityWeek and Fox News tied the incident to the broader 2025 ShinyHunters Salesforce OAuth/integration campaign affecting Google, LVMH brands, and other enterprises; Fox News cited BleepingComputer reporting that ShinyHunters claimed roughly 18 million Stellantis Salesforce records—Stellantis has not published an official victim count. BreachHistory indexes recordsAffected 0 until a regulator or company tally emerges; contact-data exposure still elevates phishing risk for Jeep/Chrysler/Ram owners.
Root cause
Unauthorized access to third-party Salesforce platform supporting North American customer service; disclosed September 2025 amid ShinyHunters Salesforce extortion wave—company confirmed contact data only