FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups
ID: 37a26a6b-4a4b-5389-8f96-0d439616894f
STIX ID: report--37a26a6b-4a4b-5389-8f96-0d439616894f
Feed Name: Security Affairs
Threat Score
The FBI issued a FLASH alert warning that cybercriminal groups UNC6040 and UNC6395 have been actively targeting Salesforce platforms since early 2025, using vishing/social engineering, malicious connected apps, and compromised OAuth tokens (including Salesloft Drift tokens) to exfiltrate customer data and carry out extortion; the alert includes IOCs and recommended mitigations such as MFA enforcement, least-privilege, monitoring API usage, and rotating credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
