~Mandiant~
UNC6040 uses vishing to trick users into authorizing malicious apps, enabling large-scale data theft from Salesforce instances.
-
IOCs: (None identified)
-
#Salesforce #ThreatIntel #UNC6040 #Vishing
Burst. Burst. Burst. Small amounts of data exfiltrated from a rotating cast of IP addresses. This is how #UNC6040 makes off with #Salesforce data without raising flags.
Watch more from this on-demand webcast: https://loom.ly/0awUw38
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data reconbee.com/fbi-warns-of...
#FBI #federalbureauofinvestigation #UNC6040 #UNC6395 #hackers #Hacked #salesforcedata #DataSecurity
FBI e CISA: exploit attivi su Salesforce e DELMIA Apriso (CVE-2025-5086). Urgente remediation, MFA robusta e segmentazione tra SaaS e OT.
#cisa #DELMIAApriso #FBI #OAuth #Salesforce #UNC6040 #UNC6395 #vishing
www.matricedigitale.it/2025/09/13/f...
#Cibreseguridad: | #Google Confirma Brecha de Seguridad en su Instancia de #Salesforce Asociada a #UNC6040 | 2.500 millones de cuentas de #Gmail afectadas www.newstecnicas.info.ve/2025/08/brec...
Google confirms ShinyHunters (UNC6040) breached its internal Salesforce database via a vishing scam, affecting SMB customer data.
Read: hackread.com/google-sales...
#CyberSecurity #ShinyHunters #UNC6040 #Salesforce #DataBreach #Google
Google and Cisco, have disclosed separate data breaches stemming from voice phishing (vishing) attacks that compromised customer information stored in cloud-based CRM systems.
www.computing.co.uk/news/2025/security/googl...
#salesforce […]
Google said one of its Salesforce database systems, used to store contact information and related notes for small and medium-sized businesses, was breached by a hacking group
#Google #salesforce #shinyhunters #UNC6040 #databreach #security #cybersecurity #hackers #hacking #hacked
#Google says the group behind last year's #Snowflake attack slurped data from one of its #Salesforce instances
www.theregister.com/2025/08/06/g...
#ShinyHunters suspected in rash of intrusions
#CyberSecurity #InfoSec #CyberCrime #DataBreach #UNC6040
~Varonis~
Financially motivated actor UNC6040 uses vishing to trick users into installing a malicious Salesforce app for data theft and extortion.
-
IOCs: (None identified)
-
#Salesforce #ThreatIntel #UNC6040 #Vishing
Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App reconbee.com/google-expos...
#google #vishinggroup #UNC6040 #salesforce #dataloaderapp #cyberattack
~Mandiant~
UNC6040 uses voice phishing to install malicious Data Loader apps on Salesforce for data theft & extortion.
-
IOCs: UNC6040, My Ticket Portal
-
#Salesforce #ThreatIntel #UNC6040 #Vishing
Google Warns of Vishing, Extortion Campaign Targeting Salesforce Customers A financially motivate...
www.securityweek.com/google-warns-of-vishing-...
#Cybercrime #data #extortion #UNC6040 #vishing
Result Details