Payback: 'ShinyHunters' Clocks Google via Salesforce
ID: b80888d8-4c41-5f8a-b1d2-3a3167bcb6da
STIX ID: report--b80888d8-4c41-5f8a-b1d2-3a3167bcb6da
Feed Name: Dark Reading
The report describes ShinyHunters/UNC6040 conducting an active campaign of Salesforce-focused intrusions using sophisticated vishing and social-engineering to convince employees to install Trojanized connectors or run custom scripts, enabling theft of customer contact and business data across numerous major organisations (including Google); it highlights evolving TTPs (VPN/TOR, modified Data Loader, custom Python tooling), the brand-like decentralization of the group, and recommended defensive measures such as phishing-resistant MFA, allow-listing connected apps, and stricter access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
