FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks
HighWhat happened
The FBI has issued a flash alert regarding two cybercriminal groups, UNC6040 and UNC6395, targeting organizations' Salesforce platforms through different initial access methods, leading to data theft and extortion.
Who is affected
Organizations utilizing Salesforce platforms, particularly those integrating third-party applications like Salesloft Drift, are at risk.
Why it matters
These attacks compromise sensitive organizational data, including customer information and proprietary business data, potentially leading to financial loss, reputational damage, and regulatory penalties.
How it could have been prevented
Implementing multi-factor authentication (MFA) for all Salesforce users, especially administrators, and conducting regular security audits to identify and mitigate vulnerabilities could have reduced the risk of unauthorized access.
Relevant professional terms
- OAuth Token
- A secure authorization method that allows third-party applications to access user data without exposing credentials.
- Vishing
- A form of social engineering where attackers use voice communication to deceive individuals into divulging confidential information.
Recommended reading: SecurityWeek
