CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Compromise of Nordstrom's Salesforce-OKTA integration leveraged for cryptocurrency scam distribution

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

An attacker compromised a Nordstrom marketing infrastructure path via an Okta SSO to Salesforce integration, then sent fraudulent St. Patrick’s Day cryptocurrency scam emails to Nordstrom customers from the legitimate [email protected] address. The emails urged recipients to rapidly deposit crypto to double the amount within two hours, using grammatical errors and urgency to deceive. Nordstrom confirmed the unauthorized campaign and warned customers that no legitimate Nordstrom communication requests crypto transfers. Some customers reportedly sent funds to attacker-controlled wallet addresses before the company issued a takedown notice.

Timeline

  1. 18.03.2026 15:55 1 articles · 3h ago

    Nordstrom cryptocurrency scam campaign distributed via compromised Salesforce-OKTA pipeline

    A threat actor leveraged a compromised Okta SSO to Salesforce integration to send fraudulent cryptocurrency promotion emails to Nordstrom customers via Salesforce Experience Cloud. The emails impersonated a legitimate St. Patrick’s Day campaign, urged rapid crypto deposits to double the amount within two hours, and originated from the official [email protected] address. Nordstrom responded by issuing a customer alert confirming the unauthorized campaign and reiterating that it never requests crypto transfers.

    Show sources

Information Snippets