<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

FBI Warns of Threat Actors Hitting Salesforce Customers

FBI warns of threat groups targeting Salesforce users via social engineering. Protect your data with multi-factor authentication and vigilance.
Content Team

The FBI is warning about two threat groups targeting Salesforce customers through sophisticated social engineering attacks. UNC6040 (also known as ShinyHunters) has been calling company help desks since October 2024, posing as IT support to trick employees into sharing login credentials or installing malicious apps that steal customer data.

UNC6395 previously exploited stolen OAuth tokens from Salesloft's Drift application to access hundreds of Salesforce environments earlier this year. Salesforce and Salesloft revoked all Drift tokens in August, but the threat remains active through other integrations.

Some victims have received extortion emails demanding cryptocurrency payments to prevent data publication. The FBI recommends training call center staff, implementing phishing-resistant multi-factor authentication, and monitoring network activity to defend against these ongoing campaigns.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo