Multiple masked hackers above laptop displaying binary code with large shield, locks, and data streams

Daily Dose of Cybersecurity News - September 14, 2025

FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks

High

What happened

The FBI has issued a flash alert regarding two cybercriminal groups, UNC6040 and UNC6395, targeting organizations' Salesforce platforms through different initial access methods, leading to data theft and extortion.

Who is affected

Organizations utilizing Salesforce platforms, particularly those integrating third-party applications like Salesloft Drift, are at risk.

Why it matters

These attacks compromise sensitive organizational data, including customer information and proprietary business data, potentially leading to financial loss, reputational damage, and regulatory penalties.

How it could have been prevented

Implementing multi-factor authentication (MFA) for all Salesforce users, especially administrators, and conducting regular security audits to identify and mitigate vulnerabilities could have reduced the risk of unauthorized access.

Relevant professional terms

OAuth Token
A secure authorization method that allows third-party applications to access user data without exposing credentials.
Vishing
A form of social engineering where attackers use voice communication to deceive individuals into divulging confidential information.

Recommended reading: SecurityWeek