A hacker group known as Scattered LAPSUS$ Hunters has reportedly leaked the personal data of more than 7.3 million Vietnam Airlines customers after gaining access to Salesforce accounts, marking one of the most significant data breaches to hit the national carrier in recent years.

A hacker group known as Scattered LAPSUS$ Hunters has reportedly leaked the personal data of more than 7.3 million Vietnam Airlines customers after gaining access to Salesforce accounts, marking one of the most significant data breaches to hit the national carrier in recent years.
The breach surfaced on October 13, when the Vietnam Computer Emergency Response Team (VNCERT), part of the A05 unit under the Ministry of Public Security, confirmed that Vietnam Airlines’ customer data was being offered for sale on hacker forums. The exposed information includes customer names, dates of birth, phone numbers, email addresses, and residential addresses, with records spanning from November 23, 2020, to June 20, 2025.
According to cybersecurity sources, the group behind the leak is Scattered LAPSUS$ Hunters, a newly rebranded collective formed after the merger of the notorious ShinyHunters group with another cybercrime syndicate. ShinyHunters was previously linked to the breach of Vietnam’s National Credit Information Center (CIC).
The attackers allegedly infiltrated Salesforce accounts belonging to 39 companies, including major corporations such as Google, Cisco, Disney, FedEx, Qantas, and GAP Inc. Salesforce, a U.S.-based cloud software provider, offers customer relationship management (CRM) services to Vietnam Airlines. Investigators believe the hackers did not compromise Vietnam Airlines’ internal systems directly but instead accessed its Salesforce-hosted data.
After reportedly failing to extort Salesforce, the hackers began releasing and selling stolen customer data from several affected companies. Forum posts show that data from Vietnam Airlines, Qantas, and GAP Inc. is being traded, with 7.3 million Vietnam Airlines customer profiles listed for sale.
Vietnam Airlines has not yet issued a public statement regarding the breach. VietNamNet, a local media outlet, reported that it contacted the airline on October 12 for comment but received no response.
Cybersecurity experts warn that the leaked information could be exploited in phishing attacks and scam campaigns impersonating Vietnam Airlines. Authorities have advised citizens to remain cautious of unsolicited communications or fraudulent offers claiming to be from the airline.
This latest breach adds to Vietnam Airlines’ troubled history with cybersecurity. In 2016, hackers disrupted the airline’s information systems, replacing flight information screens with inflammatory messages and crippling operations at domestic and international terminals. The incident delayed nearly 100 flights and exposed data from more than 410,000 frequent flyer members.
VNCERT has launched an investigation into the latest breach, aiming to determine how attackers accessed the Salesforce environment and to assess the full scope of the compromised data.
As of now, there is no indication that flight operations or booking systems have been affected. However, experts say the incident underscores growing risks to companies that rely on third-party platforms to manage customer data.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543