The Salesforce Customer Data Breaches of 2025
Dozens of companies, one method — and, contrary to what a lot of pages say, no single combined lawsuit. Here is what the panel actually decided and where each case now lives.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Actually Happened
Through 2025, attackers worked their way into the customer databases that companies keep inside Salesforce. The method was social engineering — talking an employee into granting access — used against one company at a time. That distinction carries the whole story, because it means this was not one breach with many victims but many separate breaches that happened to share a technique. The federal panel that examined them put it plainly: each incident was an attack on a customer, “not an exploit of Salesforce itself”, and most of the complaints do not even mention Salesforce.
Case Details
Cases are pending in at least six federal districts. The panel identified where each company’s litigation has settled: the Northern District of Illinois for TransUnion, the District of Minnesota for Allianz Life, the Central District of California for Farmers Insurance, the Northern District of California for Salesforce itself, and the Southern District of New York for Louis Vuitton.
The Decision Most Pages Get Wrong
Which Case Is Yours
It depends on the company that wrote to you, not on Salesforce. Allianz Life — 1,497,036 people, breach 16 July 2025, District of Minnesota. Farmers Insurance — more than 1.1 million, intrusion 29 May 2025, Central District of California. TransUnion — more than 4.4 million, intrusion 28 July 2025, MDL 3170 in Chicago. Louis Vuitton North America — Southern District of New York. Other Salesforce customers were affected too, and plaintiffs have alleged that dozens more had data taken the same way.
What These Cases Pay
Timeline
- 1
Through 2025 — the attacks
Attackers use social engineering to reach the Salesforce databases of one company after another.
- 2
May to July 2025 — the largest disclosures
Farmers Insurance (29 May), Allianz Life (16 July) and TransUnion (28 July) are among the biggest, together covering roughly seven million people.
- 3
29 August 2025 — the combined motion
Plaintiffs in five actions move to centralize 41 cases as MDL No. 3164.
- 4
3 October 2025 — TransUnion asks separately
TransUnion moves for its own MDL in the Northern District of Illinois, docketed as MDL No. 3170.
- 5
16 December 2025 — the panel splits the difference
The Salesforce MDL is refused; the TransUnion MDL is created before Judge Gettleman with 54 cases.
- 6
2026 — separate tracks
Each company’s litigation continues in its own district. No settlement in any of them.
Three Things That Are Not the Lawsuit
None of these cases has settled, which makes every claim form you are shown for them a red flag.
A “claim form” for a case that has not settled
There is no settlement in the Salesforce customer matter, which means there is no claim form, no claims administrator and no deadline. Any site or letter inviting you to file a claim and asking for a fee, your Social Security number or your bank details is not connected to this litigation. Joining a class action never costs money up front.
Callers who already “have your file”
Because the notification letters went to a known list of people, that list is valuable to callers who pretend to be from the company, a law firm or a regulator. A real firm will not cold-call demanding a payment or an account number to “release” compensation. Hang up and call back on a number you looked up yourself.
Credit monitoring you are asked to pay for
Where a company offers monitoring after a breach, it pays for it. If someone bills you for monitoring “because of the breach”, that is not the company's offer. Separately, a security freeze at each of the three bureaus is free by federal law and does more than monitoring does, because it blocks new accounts instead of reporting them afterwards.
Frequently Asked Questions
Is there a Salesforce class action I can join?
There are cases against Salesforce itself in the Northern District of California, but there is no combined Salesforce proceeding covering all the affected companies — the panel refused to create one on 16 December 2025. If a company wrote to you about a breach, your case is against that company, in that company’s district.
Is Salesforce to blame, or the company that wrote to me?
The panel’s finding was that these were social engineering attacks on individual customers rather than an exploit of the Salesforce platform, and that most complaints do not allege a common platform flaw. That is a procedural finding about whether the cases belong together, not a final ruling on anyone’s liability — which remains to be decided in each case.
I got letters from two different companies. Do I have two cases?
Yes, potentially. Because these are separate proceedings in separate courts, being in two affected groups means being a class member twice over, with two different timetables and eventually two separate notices. Keep both letters.
Is there a settlement I can claim from?
No. As of August 2026 there is no settlement in the Salesforce customer litigation, no claims administrator and no deadline. Anything presenting itself as a claim form for this case is not what it says it is.
Does joining cost me anything?
No. Data breach class actions are handled on contingency: the firms are paid out of a settlement or judgment if there is one, and nothing if there is not. You are never asked for money up front, and anyone who does ask is not a class action lawyer.
What should I do right now, regardless of the lawsuit?
Freeze your credit at all three bureaus — it is free, takes about ten minutes each, and blocks new accounts rather than just reporting them after the fact. Keep the notification letter: it is the simplest proof that you are in the affected group. And write down any costs you incur, because documented losses are the part of a breach claim that pays the most.
How long do these cases take?
Longer than people expect. A data breach class action that settles typically takes two to four years from the first complaint to money reaching class members, and the steps in between — motions to dismiss, class certification, appeals — can each add a year. There is no shortcut, and a case moving slowly is not a sign that it is going badly.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.