The FBI has issued an urgent security alert about two sophisticated cybercriminal groups, UNC6040 and UNC6395, who are systematically targeting Salesforce environments to steal sensitive data and extort victims. These attacks have already impacted numerous high-profile companies and represent a significant threat to organizations using Salesforce platforms.
## How the Attacks Work
**UNC6040 Campaign (Social Engineering Focus)**
The first wave of attacks, identified by Google’s Threat Intelligence team in June 2024, relies on social engineering tactics. Cybercriminals impersonate IT support staff and trick employees into connecting malicious OAuth applications to their company’s Salesforce accounts. These fake apps, sometimes disguised as legitimate tools like “My Ticket Portal,” give attackers direct access to corporate Salesforce data.
Once connected, the criminals mass-extract customer information from critical database tables, particularly “Accounts” and “Contacts” data. This stolen information is then used by the ShinyHunters extortion group to blackmail companies.
**UNC6395 Campaign (Supply Chain Attack)**
The second campaign represents a more sophisticated supply chain attack. Between August 8-18, 2024, threat actors exploited stolen Salesloft Drift OAuth tokens to breach Salesforce instances. The attack originated from a March 2024 compromise of Salesloft’s GitHub repositories, which eventually led to the theft of authentication tokens.
These stolen tokens allowed attackers to access support case information stored in Salesforce, extracting valuable credentials including AWS keys, passwords, and authentication tokens. This data enables further attacks on other cloud environments.
## Major Companies Affected
The attacks have impacted a wide range of prominent organizations:
**UNC6040 Victims:** Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, and Tiffany & Co.
**UNC6395 Victims:** Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, and Palo Alto Networks.
## The Criminal Groups Behind the Attacks
According to sources, the ShinyHunters extortion group and associated threat actors calling themselves “Scattered Lapsus$ Hunters” are responsible for both attack campaigns. These groups claim connections to notorious cybercriminal organizations including Lapsus$, Scattered Spider, and ShinyHunters.
In a concerning development, the attackers recently claimed to have breached the FBI’s E-Check background system and Google’s Law Enforcement Request system, potentially allowing them to impersonate law enforcement officials. However, these claims remain unverified.
## FBI Response and Recommendations
The FBI has released indicators of compromise (IOCs) including suspicious IP addresses, user agent strings, and URLs to help organizations defend against these attacks. The bureau emphasizes the need for heightened awareness and proactive security measures.
## Protective Measures
Organizations using Salesforce should immediately:
– Review and audit all OAuth applications connected to their Salesforce environments
– Implement stronger employee training on social engineering tactics
– Monitor for suspicious authentication activities
– Regularly review and rotate access tokens
– Establish strict verification procedures for IT support requests
This ongoing threat demonstrates the evolving sophistication of cybercriminal operations and the critical importance of robust cloud security practices in protecting sensitive corporate data.
