See the Complete Picture.
Published loading...Updated

Hackers Are Using a Modified Salesforce App to Trick Employees and Extort Companies, Google Says

  • Google reported on June 4, 2025, that a financially motivated group called UNC6040 has tricked employees in companies across Europe and the Americas using a modified Salesforce Data Loader app to steal data.
  • UNC6040 uses voice phishing, impersonating IT support to convince employees to approve a malicious app version that grants attackers extensive access within Salesforce environments.
  • After initial intrusion, UNC6040 steals data from Salesforce plus connected services like Okta, Microsoft 365, and Workplace, sometimes delaying extortion demands while possibly partnering with another criminal actor.
  • Google reported that the UNC6040 campaign has targeted roughly 20 organizations, while Salesforce confirmed that these social engineering attacks do not stem from any flaws within its platform.
  • This campaign highlights risks of identity-based attacks exploiting employee trust to gain multi-cloud access and underscores the need for restrictive permission practices and user awareness.
Insights by Ground AI
Does this summary seem wrong?

27 Articles

All
Left
3
Center
3
Right
2
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 38% of the sources lean Left, 38% of the sources are Center
38% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

CSO Online broke the news in on Wednesday, June 4, 2025.
Sources are mostly out of (0)