Salesforce Data Loader Exfiltration Attack Explained
ID: 86a24ee8-f10b-5e95-8b5f-a69d46c69e89
STIX ID: report--86a24ee8-f10b-5e95-8b5f-a69d46c69e89
Feed Name: Mitiga
This report documents incidents in which threat actors abused a trojanized Salesforce Data Loader application authorized via vishing to gain OAuth API access, then performed automated, burst-style REST API queries (rotating Tor/VPN IPs and anonymization services) to exfiltrate nearly 3.9 GB—about 4 million records—of customer PII from Salesforce; detection relied on Salesforce Event Monitoring (REST API logs, anomalous connected app IDs, unusual user agents) and recommended mitigations include restricting connected-app privileges, app allowlisting, employee vishing training, and proactive threat hunting and anomaly detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
