The cybersecurity landscape has been shaken by the emergence of Trinity of Chaos, a sophisticated ransomware collective that has created a data leak website containing sensitive information from 39 major companies.
See also: 13-year-old RCE vulnerability in Redis allows full host access

This powerful alliance, which likely includes members from the notorious Lapsus$, Scattered Spider , and ShinyHunters, represents a significant evolution in the organization and operational capability of cybercriminals.
The group has strategically positioned itself as a hybrid threat actor, combining traditional ransomware tactics with data extortion methodologies to maximize their impact and financial returns. Trinity of Chaos has demonstrated remarkable operational sophistication by creating a dedicated Data Leak Site (DLS) on the TOR network, following the established pattern of modern ransomware groups.
Rather than announcing new attacks, the group has chosen to reveal previously unpublished successful breaches, sharing samples of stolen data to validate their claims and pressure victims to comply. This approach suggests a calculated strategy designed to maintain operational security while maximizing their influence over their targets through the threat of public data exposure.
Following the previous exploitation of the Salesforce cases, they have issued ultimatums to the affected companies, threatening massive data leaks if negotiation demands are not met.
Resecurity analysts noted the group's well-crafted marketing approach, with the collective describing itself as experts in " high-value corporate data acquisition and strategic breach operations " spanning multiple industries, including automotive, finance, insurance, technology, and telecommunications sectors globally.
See also: Use-after-free vulnerability in Redis Server allows RCE

Threat actors have indicated that their operations began as early as 2019, suggesting extensive experience and a well-established operational infrastructure. The scope of the Trinity of Chaos breach is unprecedented, with victims spanning Fortune 100 companies across multiple industries.
Major tech giants like Google and Cisco feature prominently among the compromised entities, along with household names like Toyota Motor Corporation, FedEx, Disney/Hulu, Home Depot, Marriott, McDonald’s , and many other high-profile organizations.
The group has set an October 10th deadline for most victims to negotiate, using psychological pressure tactics similar to traditional ransomware operations while threatening regulatory reports that could lead to criminal negligence charges against non-compliant organizations.
The Trinity of Chaos collective has demonstrated sophisticated attack methodologies focused on exploiting Salesforce instances through the breach of Salesloft Drift's AI chat integration.
The majority of data leaks do not contain passwords, but do contain significant amounts of personally identifiable information (PII), strongly suggesting that the stolen files came from targeted Salesforce environments.
See also: 40-year-old arrested for cyberattack that caused chaos at European airports
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The group's ability to maintain persistent access within victims' networks for extended periods, as demonstrated in the Vietnam Airlines where the attackers remained undetected for nearly three years, highlights the sophistication of their operational capabilities.
