Hackers Are Using a Modified Salesforce App to Trick Employees and Extort Companies, Google Says
- Google reported on June 4, 2025, that a financially motivated group called UNC6040 has tricked employees in companies across Europe and the Americas using a modified Salesforce Data Loader app to steal data.
- UNC6040 uses voice phishing, impersonating IT support to convince employees to approve a malicious app version that grants attackers extensive access within Salesforce environments.
- After initial intrusion, UNC6040 steals data from Salesforce plus connected services like Okta, Microsoft 365, and Workplace, sometimes delaying extortion demands while possibly partnering with another criminal actor.
- Google reported that the UNC6040 campaign has targeted roughly 20 organizations, while Salesforce confirmed that these social engineering attacks do not stem from any flaws within its platform.
- This campaign highlights risks of identity-based attacks exploiting employee trust to gain multi-cloud access and underscores the need for restrictive permission practices and user awareness.
27 Articles
27 Articles
Salesforce customers duped by series of social-engineering attacks
A financially motivated threat group posing as IT support has intruded the systems of about 20 organizations by duping employees into installing a malicious, illegitimate version of Salesforce’s Data Loader and granting broader access to cloud-based environments, Google Threat Intelligence Group said in a threat report released Wednesday. The attacks, which Google attributes to UNC6040, have hit organizations in hospitality, retail and education…
Hackers are using a modified Salesforce app to trick employees and extort companies, Google says
Hackers are tricking employees at companies in Europe and the Americas into installing a modified version of a Salesforce-related app, allowing the hackers to steal reams of data, gain access to other corporate cloud services and extort those companies, Google said on Wednesday.

Hackers abuse modified Salesforce app to steal data, extort companies, Google says
(Reuters) -Hackers are tricking employees at companies in Europe and the Americas into installing a modified version of a Salesforce-related app, allowing the hackers to steal reams of data, gain access to other corporate cloud services and extort those companies, Google said on Wednesday.
Coverage Details
Bias Distribution
- 38% of the sources lean Left, 38% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage