logo

FBI Releases IOCs on Cyber Threats Exploiting Salesforce for Data Theft

ID: c20c3eda-4582-50bb-843e-b353f7d719ad

STIX ID: report--c20c3eda-4582-50bb-843e-b353f7d719ad

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-09-15

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**FBI Advisory — OAuth-based Exfiltration Against Salesforce:** The FBI and CISA detail campaigns by UNC6040 (vishing to trick call-center staff into authorizing malicious connected apps) and UNC6395 (use of compromised Salesloft/Drift OAuth tokens) to gain persistent API access and exfiltrate customer data from Salesforce; the bulletin lists extensive IOCs (IP ranges, URLs, user‑agents) and recommends mitigations such as phishing‑resistant MFA, restricting third‑party integrations, IP restrictions, token revocation, and enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.