Gridware Logo

What the Google CRM Breach Means for Businesses Using Ads

By Ahmed Khanji Updated 14 August 2025 4 min read

in 𝕏
What the Google CRM Breach Means for Businesses Using Ads

Google Contact Database Breached by ShinyHunters

In August, Google confirmed that one of its corporate Salesforce databases was breached by ShinyHunters. This group has a long history of targeting major brands and leaking stolen data. They’ve been linked to incidents at companies like LVMH, Adidas, and others, and they’ve developed a reputation for sitting on stolen data before using it in slow, calculated campaigns.

Their target this time was business contact data. Stored CRM notes were also taken. The records came from companies using Google services to manage ads, outreach, or customer lists. No payment data or credentials were involved, but what was taken still matters.

This is the data that was accessed. CRM details shared into Google Ads, like many businesses set up.

Breach caused by human error

Google says the attackers got in through voice phishing. They pretended to be IT staff and convinced employees to approve a fake Salesforce app. There was no technical flaw in Salesforce. The weak spot was staff who hadn’t been trained to spot this kind of threat.

Once they were in, a tampered version of the Salesforce Data Loader tool helped extract data from the account. Because the attacker had ‘valid’ permissions, everything they did looked legitimate until it was too late.

Breaches like this are hard to stop with technical controls. It came down to the attackers’ timing, trust, and human error.

Why it matters even though no ‘sensitive’ data was stolen

It’s easy to move past this breach because of how “light” the impact sounds. The data was mostly business names, contact info, and notes. There were no passwords. No credit card records.

But that doesn’t mean it was harmless.

What was taken is exactly the kind of curated data that powers targeted scams. Google confirmed that affected businesses were contacted directly and says the breach window was short. But threat actors now hold well-maintained, filtered business contact lists—paired with context about who uses what.

That’s a real problem if your business uses Google Ads or similar services to manage campaigns.

Most of the data taken looks like standard business contact details. On paper, that doesn’t sound critical. The data was mostly business names, contact info, and notes. There were no passwords. No credit card records.

But this data is linked to real ad accounts and marketing actions. This means attackers can target your customers with ‘specialised’ fake advertisements (potentially pretending to be your business) and exploit sensitive information that way.

If your team received a breach notification, it means your business was part of that list. Those same details can now be used for following up scams or account takeovers, especially if the attacker knows what platform you advertise on and who they should impersonate.

Our take

At Gridware, we’ve seen how stolen contact data gets used. Even when the breach looks small, it can power months of highly targeted fraud. This one will likely be no different.

ShinyHunters has been linked to several high profile breaches this year. But more interestingly, they’ve also been tied to Scattered Spider activity. We’ve been following Scattered Spider closely, including in our latest webinar and in our July threat recap.

Both groups share similar techniques. They use public data to impersonate real employees, then break into systems by preying on trust.

That makes breaches like this one a real concern. If you haven’t seen it yet, our post on how Scattered Spider is still breaching networks in 2025 breaks down their techniques.

Gain immunity to these types of breaches

If your business received a notification from Google, don’t wait for signs of compromise. Run an internal session and make sure your team knows how to handle suspicious contact.

We offer Adversary Simulation Training built around recent techniques like voice phishing, impersonation, and CRM abuse. Training your staff with realistic attack scenarios is one of the most effective ways to prevent human error attacks.

Even though Google says no Ads data was exposed, if your team uses Google Ads or a connected CRM, it’s time to prepare your business and get your employees ready.

Gridware’s monitoring ShinyHunters closely and will update our blog if we uncover any related incidents.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.