216.73.216.6

Cyber Criminal Groups Compromising Salesforce Instances for Data Theft and Extortion

· Published 15/09/2025 14:01 · Modified 15/09/2025 21:15

Export JSON

Essential information

Published
15/09/2025 14:01
Modified
15/09/2025 21:15
Tags
2025-09-15 api exfiltration data theft extortion oauth salesforce shinyhunters social engineering vishing
Related entities
59 observables, 1 intrusion sets (apt), 7 techniques (mitre)

Description

Two cyber criminal groups, UNC6040 and UNC6395, are targeting organizations' platforms for and . UNC6040 uses , particularly voice phishing, to gain access to accounts. They trick employees into granting access or sharing credentials, then use API queries or malicious connected apps to exfiltrate data. UNC6395 exploits compromised tokens for the Salesloft Drift application to access instances. Both groups have been observed exfiltrating large volumes of customer data. Victims of UNC6040 have received emails demanding cryptocurrency payments to prevent data publication. The FBI has provided numerous IP addresses and other indicators of compromise associated with these groups, along with recommended mitigations to enhance security and prevent such attacks.

External references