How Vietnam Airlines Hack Could Have Been Prevented Using Deception Technology
Neha5 min read
SAAS SECURITY-CLOUD-BREACHES#vietnam-airlines#salesforce#saas-security

How Vietnam Airlines Hack Could Have Been Prevented Using Deception Technology

Hackers accessed Salesforce accounts of Vietnam Airlines and 38 companies, exposing 7.3M customer records. Learn how honeytokens and cyber deception could have detected this SaaS breach in minutes.

Share:

The hackers who hit Vietnam Airlines never touched the airline's internal systems. They walked into a trusted third-party CRM platform instead, and pulled personal data on more than 7.3 million customers. Names, dates of birth, phone numbers, emails, and addresses, some of it dating back to 2020, showed up on underground forums in October 2025. The crew behind the leak, Scattered LAPSUS$ Hunters, is a rebrand of the notorious ShinyHunters. They're now selling the data openly after failing to extort Salesforce.

Vietnam Airlines wasn't alone. The same campaign reached Salesforce accounts belonging to 38 other major companies.

Vietnam Airlines

I spend most of my days inside SaaS tenants, and this incident points straight at a blind spot I see constantly. Attackers keep targeting cloud platforms where perimeter defenses simply don't reach. For an organization like Vietnam Airlines, this breach wasn't about a weak firewall. It was credential abuse in a shared ecosystem that nobody was watching closely enough.

The Backdoor Was the Front Door

The attack path was simple and brutal. The hackers got into Salesforce instances used by Vietnam Airlines and others, including Qantas, GAP Inc., Google, Cisco, Disney, and FedEx. There's no evidence that Salesforce's core infrastructure was compromised. Far more likely: stolen or phished credentials, misconfigured API keys, or session tokens lifted from compromised employee accounts.

Once they were in, they browsed customer objects and exported records in bulk. The data wasn't encrypted at rest in any way that stopped authorized, if malicious, access. No behavioral alerts fired on the mass exports, even though they came from unusual IPs and accounts. Salesforce ships strong security controls, MFA, IP restrictions, and login monitoring, but those only protect you when they're actually enforced across every admin and integration account.

This isn't the airline's first run-in with attackers either. Back in 2016, display systems at the Hanoi and Ho Chi Minh City airports were hijacked to show propaganda, delaying nearly 100 flights. That was defacement. This time it's identity theft at scale, the kind that feeds phishing, SIM swapping, and loyalty account takeovers for years.

If you want a sense of how CRM platforms keep becoming the target, the Workday CRM phishing breach followed a strikingly similar script.

The Shared-Responsibility Gap Nobody Owns

Plenty of teams treat SaaS platforms as black boxes. "Salesforce is secure, so we're fine." But security here is split. Salesforce enforces strong defaults, and the customer owns identity hygiene, access governance, and anomaly detection inside their own tenant. That second half is where things fall apart.

MFA and conditional access help, sure. They don't save you when credential theft comes through infostealers like RedLine or Raccoon, or through a convincing phishing page. API keys buried in scripts and shared service accounts rarely get rotated. And without context-aware monitoring, a clean-looking login from a new device in Eastern Europe slides right past.

The outcome is predictable. Attackers operate with valid permissions and exfiltrate data in plain sight. Detection becomes a forensics exercise after the fact, which is too late to prevent anything. I've watched this same token-theft pattern play out in the Anodot and Snowflake SaaS integration breach, where a single stolen integration credential opened the whole environment.

Deception: Catching the Intruder Mid-Theft

This is where cyber deception changes the math. You embed honeytokens, fake but believable data, directly into high-value systems like Salesforce. They become invisible tripwires that only an attacker would ever trigger.

Picture it running in a live tenant:

  • Decoy customer records. Seed fake passenger profiles with fabricated names, emails (something like john.doe.internal@vietnamairlines-internal.vn), and phone numbers routed to a monitoring sinkhole. Any access, export, or query against those records fires an alert.

  • Canary API tokens. Drop bogus Salesforce API keys into internal documentation, CI/CD pipelines, and employee workstations. The first time one gets used, even once, your security team knows, and you've just caught reconnaissance or lateral movement in progress.

  • Traps wired into connected systems. Link honeytokens to downstream services like loyalty platforms and booking engines. When a token surfaces in a phishing email or a dark web paste, that's confirmation of exfiltration.

Platforms like Mine2 automate this at scale. They generate context-aware decoys that match your CRM schema, embed them without disrupting anything, and watch for interaction in real time. Unlike noisy EDR rules, deception produces effectively zero false positives. Only an attacker touches the bait.

In the Vietnam Airlines case, a single honeytoken exported alongside real passenger data would have:

  • alerted the SOC within minutes of the breach,
  • pinpointed the compromised Salesforce account, and
  • enabled session termination and a credential reset before mass exfiltration.

Even with MFA bypassed, the behavior of querying fake records would have given the intruder away. That's the same logic the Marriott breach analysis walks through: detection that fires on action, not signature.

Building a Deception-First Posture

Prevention starts by assuming breach. For any SaaS-dependent organization, here's where I'd begin:

  1. Plant honeytokens in CRM fields. Seed fake PII in realistic, non-production schemas.
  2. Watch API and integration access. Use canary tokens inside service accounts, which are the assets that never rotate.
  3. Wire triggers into your SOAR. Auto-isolate a compromised identity the moment deception fires.
  4. Measure the ROI. Early detection collapses dwell time from weeks to minutes.

OAuth and device-code abuse deserve the same treatment. The device-code phishing and OAuth token playbook shows how attackers turn a single approved token into persistent cloud access, and how cloud mines catch it.

Vietnam Airlines now faces years of fraud risk. With deception layered into its Salesforce environment, the next attempt would have ended at the first fake record someone touched.

The future of defense isn't a taller wall. It's a smarter trap. Want to see what that looks like in your own tenant? Book a Mine2 demo and we'll show you deception running where it counts.

M2

Neha

Cloud Security Architect, Mine2

Neha works on cloud and identity security at Mine2, covering SaaS, OAuth, and the credential-theft paths attackers favour in the cloud.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.