FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Data
HighWhat happened
The FBI has issued a FLASH alert regarding two cybercriminal groups, UNC6040 and UNC6395, who are compromising organizations' Salesforce environments to steal data and extort victims. UNC6040 employs social engineering and vishing attacks to trick employees into connecting malicious OAuth applications to their Salesforce accounts, while UNC6395 utilizes stolen OAuth and refresh tokens to access and exfiltrate data.
Who is affected
Organizations using Salesforce platforms are at risk, with notable companies such as Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, and Tiffany & Co. having been impacted.
Why it matters
These attacks highlight the vulnerabilities in cloud-based CRM platforms and the effectiveness of social engineering tactics. The exfiltrated data can be used for extortion, leading to financial losses and reputational damage.
How it could have been prevented
Implementing strict access controls and multi-factor authentication can mitigate unauthorized access. Regular employee training on recognizing and reporting social engineering attempts is crucial.
Relevant professional terms
- OAuth
- An open standard for access delegation, commonly used for token-based authentication and authorization.
- Vishing
- A form of phishing that uses voice communication to deceive individuals into divulging confidential information.
Recommended reading: Google: Hackers target Salesforce accounts in data extortion attacks
