Salesforce platforms are open for data theft – the FBI warns IOC UNC6040 and UNC6395


  • Two threat groups, UNC6040 and UNC6395, actively target the Salesforce accounts to steal sensitive data
  • UNC6395 uses integrations such as the Salesloft Drift chatbot, while UNC6040 uses telephone -based social engineering to usurp the identity of IT staff and access
  • The FBI warns that follow -up attacks are often carried out by shinyhuters, linked to a scattered spider

Two distinct threat actors are currently targeting the Salesforce accounts of organizations to steal sensitive data found inside. This is in accordance with the Federal Bureau of Investigation (FBI), which recently published a Flash opinion to warn companies in the current threat.

“The Federal Bureau of Investigation (FBI) publishes this Flash to disseminate compromise indicators (CIO) associated with recent malware by cyber-criminals UNC6040 and UNC6395 groups, responsible for an increasing number of data and extortion,” said the agency in its council.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top