Skip to content
TECH CEO Daily

Salesforce data breach lawsuit survives as judge keeps negligence and CCPA claims

Judge Jacqueline Scott Corley ruled that consumers can pursue negligence and privacy claims alleging Salesforce's OAuth token design enabled 2025 data thefts.

By · Editor

· Archive story, added · 4 min read · ✓ Fact-checked

The 60-second brief

  • 1On September 14, 2026, a federal judge largely denied Salesforce's motion to dismiss a consolidated consumer data-theft lawsuit.
  • 2Negligence and California Consumer Privacy Act claims survive; only fraud-based Illinois claims and one Washington injury theory were dismissed.
  • 3The ruling accepts allegations as true at this stage and is not a finding that Salesforce was negligent.

The news

A Salesforce data breach lawsuit by customers and employees of Allianz, Farmers and TransUnion can go forward after a federal judge on September 14, 2026, largely denied a Salesforce (CRM) motion to dismiss, testing how far cloud vendors answer for data their clients store.

U.S. District Judge Jacqueline Scott Corley of the Northern District of California ruled in In re Salesforce Customers Security Incident Litigation, a consolidated case with 18 named plaintiffs seeking to represent classes: eight tied to Allianz Life Insurance Company of North America, two to Farmers Group and eight to TransUnion. She heard oral argument on September 10.

The complaint alleges that a hacking group it calls SLH exploited OAuth tokens, the credentials Salesforce issues when a company connects a third-party app to its account. According to the complaint, as summarized in the order, attackers phoned client employees posing as IT help desk staff, persuaded them to enter a code on a Salesforce verification page and received a token carrying that employee's permissions. That allegedly bypassed multi-factor authentication and enabled bulk data exports from about March 2025 through at least August 2025.

The plaintiffs say Salesforce should have made tokens expire automatically, rotate automatically or work only on specific devices, measures they call standard on comparable cloud platforms. Allianz's notice to consumers said affected data may have included names, addresses, dates of birth and Social Security numbers, according to the order, and TransUnion plaintiffs say their letters listed dates of birth and Social Security numbers.

Judge Corley found the plaintiffs had standing and plausibly alleged negligence. Salesforce argued that criminals, its clients and tricked employees stood between it and any harm, but the judge said the allegations support an inference that its alleged lax OAuth security was "the enabling, underlying cause of the data breach." She held the plaintiffs did not need a special relationship with Salesforce to plead a duty of care, because they allege Salesforce's own platform design created an undue risk.

She also let a California Consumer Privacy Act (CCPA) claim proceed, rejecting Salesforce's argument that it is not a covered business because it does not directly collect consumer data or decide how it is processed. The court dismissed only fraud-based claims under the Illinois Consumer Fraud Act and a Washington consumer-protection theory based on invasion of privacy. A negligence per se claim and the other Illinois and Washington claims survive, and the judge deferred whether California negligence law covers non-California plaintiffs.

The numbers

Named plaintiffs
18 (8 Allianz, 2 Farmers, 8 TransUnion)
Alleged data-export period
About March 2025 through at least August 2025 (per complaint)
Case number
3:25-cv-07232-JSC (N.D. Cal.)
Records claimed by hackers (Oct. 2025, per TechCrunch)
About 1 billion (unverified claim)

Why CEOs should care

For CISOs, the attack path described in the complaint runs through a gap many teams assume sits on the customer's side of the shared-responsibility model: connected apps and OAuth grants that the customer's own staff authorize. Whatever the court finally decides, inventory every connected app and OAuth grant in your CRM and other SaaS tenants, restrict which users can authorize new apps, shorten token lifetimes where the platform allows, alert on bulk data exports, and train help desk and other staff to refuse phone requests to enter codes.

For general counsel and procurement, the CCPA holding reaches beyond Salesforce. At least at the pleading stage, a SaaS provider that stores and processes client data was treated as a possible covered business with its own security duty, not only a service provider. Reread your shared-responsibility terms, the vendor's contractual security obligations, breach-notification duties, indemnities and liability caps, and ask the vendor which token and app-authorization controls are on by default.

For boards and CFOs, the notable point is that consumers are suing the platform vendor directly over data its clients collected. Ask management whether cyber insurance and vendor contracts cover a breach that plaintiffs attribute to a vendor's platform design, and who would pay notification, credit-monitoring and legal costs.

The bigger picture

The decision comes at the pleading stage, when a court treats the complaint's allegations as true; it is not a finding that Salesforce was negligent or broke the law. In October 2025, Salesforce said there was no indication its platform had been compromised or that the activity was tied to any known vulnerability, as reported by TechCrunch. TechCrunch also reported that a group calling itself Scattered LAPSUS$ Hunters claimed to have stolen about 1 billion records from Salesforce customer databases, and that companies including Allianz Life, Google, Qantas and TransUnion had confirmed data theft.

The CCPA reasoning may travel. Judge Corley declined to follow In re Accellion, a January 2024 ruling in the same district that took a narrower view of when a software vendor counts as a covered business. If other courts agree, SaaS vendors could face more consumer suits after breaches at their clients.

What happened next

On September 15, 2026, Bloomberg Law and Law360 reported the ruling; Bloomberg Law said Salesforce must face most of the claims. With the dismissal bid largely denied, the next steps to watch are Salesforce's answer to the complaint, discovery and, later, any class certification fight; the order did not set those dates. The judge also left open whether California negligence law applies to plaintiffs outside California, which she said needed fuller briefing.

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

How this story was made. Researched from primary sources such as company announcements and filings, with the help of technology tools, fact-checked twice, and approved for publication by Hussein Mukhtar.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards · Report an error

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Weekdays, 6 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.

More in Cybersecurity