FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data

Two threat clusters, identified as UNC6040 and UNC6395, are breaching Salesforce environments of enterprises in order to steal data and extort victims, according to a FLASH alert released by the FBI.

According to the FBI’s FLASH advisory, the agency is releasing this FLASH to share Indicators of Compromise (IOCs) linked to recent malevolent cyber activity by cybercriminal organizations UNC6040 and UNC6395, which are in charge of an increasing number of data theft and extortion intrusions.

Both groups have lately been seen using various initial access methods to target Salesforce platforms used by enterprises. In order to raise awareness and give recipients IOCs that they may use for network defense and study, the FBI is making this information public.

Google Threat Intelligence (Mandiant) originally revealed UNC6040 in June, stating that since late 2024, threat actors have been tricking employees into connecting malicious Salesforce Data Loader OAuth apps read more about FBI warns of UNC6040 UNC6395 hackers stealing Salesforce data.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *