Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Salesforce platforms are being cracked open for data theft – FBI warns of UNC6040 and UNC6395 IOCs

Tech Wavo by Tech Wavo
September 16, 2025
in Computers
0




  • Two threat groups, UNC6040 and UNC6395, are actively targeting Salesforce accounts to steal sensitive data
  • UNC6395 exploits integrations like the Salesloft Drift chatbot, while UNC6040 uses phone-based social engineering to impersonate IT staff and gain access
  • The FBI warns that follow-up extortion attacks are often carried out by ShinyHunters, linked to Scattered Spider

Two separate threat actors are currently targeting organizations’ Salesforce accounts to steal sensitive data found within. This is according to the US Federal Bureau of Investigation (FBI), which recently issued a FLASH advisory to warn businesses about the ongoing threat.

“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions,” the agency said in its advisory.

“Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms. The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.”


You may like

Scattered Spider and ShinyHunters

In recent times there were numerous reports of cybercriminals who compromised company Salesforce accounts through the Salesloft Drift application, an AI chatbot that can be integrated with Salesforce.

The FBI labeled this group as UNC6395 and apparently, it struck some of the biggest tech and security organizations, including Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, Palo Alto Networks, and others.

The other group, UNC6040, gained access by tricking their victims into sharing the access. They would call them on the phone, posing as IT support employees addressing enterprise-wide connectivity issues.

“Under the guise of closing an auto-generated ticket, UNC6040 actors trick customer support employees into taking actions that grant the attackers access or lead to the sharing of employee credentials, allowing them access to targeted companies’ Salesforce instances to exfiltrate customer data,” the FBI explained.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

A threat actor known to have perfected this technique is Scattered Spider. While the FBI did not name that group in its advisory, it did say that the follow-up extortion attacks were usually mounted by ShinyHunters, a group known to have been working together with Scattered Spider. At one point, the groups even merged into an entity they dubbed ScatteredLapsus$Hunters.

Via BleepingComputer

You might also like

Previous Post

Hollow Knight Silksong review: a daring, experimental, and breathtakingly beautiful sequel

Next Post

Best Buy’s OLED TV sale is like a Black Friday preview – shop clearance prices from $699.99

Next Post
Best Buy’s OLED TV sale is like a Black Friday preview – shop clearance prices from $699.99

Best Buy's OLED TV sale is like a Black Friday preview – shop clearance prices from $699.99

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SpaceX’s lunar lander could be ‘years late’ for a planned 2027 mission to the moon

by Tech Wavo
September 22, 2025
0
SpaceX’s lunar lander could be ‘years late’ for a planned 2027 mission to the moon
Computers

SpaceX's lunar lander has run into a snag and may not be ready for a mission to the moon that...

Read more

Nvidia plans to invest up to $100B in OpenAI

by Tech Wavo
September 22, 2025
0
Computers

Nvidia announced Monday it plans to invest up to $100 billion in OpenAI as part of a deal to build...

Read more

Huawei outlines Kunpeng roadmap with 256-core CPU planned for 2028, though benchmarks suggest a potentially earlier arrival

by Tech Wavo
September 22, 2025
0
US warns Chinese tech firms may have ties to notorious cyber espionage group which hit hundreds of firms
Computers

Huawei outlines Kunpeng roadmap with CPUs scaling to 256 cores by 2028Benchmarks show processor referred to as Kunpeng 960 delivering...

Read more

This M’sian startup provides handymen as a subscription service

by Tech Wavo
September 22, 2025
0
This M’sian startup provides handymen as a subscription service
Computers

Handibee provides handyman services at a subscription model Ever tried hunting down a reliable handyman in Malaysia? If you have,...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock