institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Hackers Are Using a Modified Salesforce App to Trick Employees and Extort Companies, Google Says

  • Hackers tracked as UNC6040 by Google have used modified Salesforce Data Loader apps in voice phishing attacks since early 2025 to steal data from companies in Europe and the Americas.
  • These attackers impersonate IT support, tricking English-speaking employees into approving malicious OAuth-connected apps via fake Salesforce setup pages to access corporate Salesforce environments.
  • After gaining access, UNC6040 exfiltrates data from Salesforce and other cloud platforms such as Okta, Microsoft 365, and Workplace, sometimes moving laterally within victim networks.
  • Approximately 20 organizations across retail, hospitality, and education sectors have been affected, with extortion attempts claiming ShinyHunters affiliation occurring months after initial intrusions, according to Google.
  • Google and Salesforce recommend restricting API permissions, limiting app installation, and improving security awareness to mitigate risks, noting no inherent platform vulnerabilities caused these incidents.
Insights by Ground AI
Does this summary seem wrong?

28 Articles

All
Left
3
Center
3
Right
2
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 38% of the sources lean Left, 38% of the sources are Center
38% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

CSO Online broke the news in on Wednesday, June 4, 2025.
Sources are mostly out of (0)