Salesforce's North American and European customers endured a 15-hour outage after a cyber attack.
The incident came after the salesforce technology team blocked access to certain instances that contain customers affected by a database script deployment that inadvertently gave users broader data access than intended.
To protect the customers, the company blocked access to all instances that contain affected customers until they could block access to orgs with the inadvertent permissions.
As a result, customers who were not affected may also experienced service disruption.
Source: https://www.crn.com.au/news/salesforce-outage-hits-after-data-leak-525371
TPRM report: https://scoringcyber.rankiteo.com/company/salesforce
"id": "sal215719323",
"linkid": "salesforce",
"type": "Cyber Attack",
"date": "05/2019",
"severity": "60",
"impact": "",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology',
'location': ['North America', 'Europe'],
'name': 'Salesforce',
'type': 'Company'}],
'attack_vector': 'Database Script Deployment',
'description': "Salesforce's North American and European customers endured a "
'15-hour outage after a cyber attack. The incident came after '
'the salesforce technology team blocked access to certain '
'instances that contain customers affected by a database '
'script deployment that inadvertently gave users broader data '
'access than intended. To protect the customers, the company '
'blocked access to all instances that contain affected '
'customers until they could block access to orgs with the '
'inadvertent permissions. As a result, customers who were not '
'affected may also experienced service disruption.',
'impact': {'downtime': '15 hours',
'operational_impact': 'Service Disruption',
'systems_affected': ['Customer Instances']},
'post_incident_analysis': {'corrective_actions': ['Blocked access to orgs '
'with inadvertent '
'permissions'],
'root_causes': ['Inadvertent Permissions']},
'response': {'containment_measures': ['Blocked access to affected instances'],
'remediation_measures': ['Blocked access to orgs with '
'inadvertent permissions']},
'title': 'Salesforce 15-Hour Outage Due to Cyber Attack',
'type': 'Cyber Attack',
'vulnerability_exploited': 'Inadvertent Permissions'}