FBI Releases IOCs on Cyber Threats Exploiting Salesforce for Data Theft
ID: c20c3eda-4582-50bb-843e-b353f7d719ad
STIX ID: report--c20c3eda-4582-50bb-843e-b353f7d719ad
Feed Name: GBHackers
**FBI Advisory — OAuth-based Exfiltration Against Salesforce:** The FBI and CISA detail campaigns by UNC6040 (vishing to trick call-center staff into authorizing malicious connected apps) and UNC6395 (use of compromised Salesloft/Drift OAuth tokens) to gain persistent API access and exfiltrate customer data from Salesforce; the bulletin lists extensive IOCs (IP ranges, URLs, user‑agents) and recommends mitigations such as phishing‑resistant MFA, restricting third‑party integrations, IP restrictions, token revocation, and enhanced monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
