logo

ShinyHunters and UNC6395: Inside the Salesforce and Salesloft Breaches

ID: d947c923-0cd4-5514-b1bb-a42953dcfba9

STIX ID: report--d947c923-0cd4-5514-b1bb-a42953dcfba9

Feed Name: Mitiga

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-29

...
...

Mitiga Labs outlines two active campaigns against Salesforce and related supply-chain services: ShinyHunters (UNC6040) uses OAuth Device Flow plus vishing to obtain access and demand ransom, while UNC6395 exploited Salesloft/Drift to steal OAuth tokens and exfiltrate customer Salesforce data; the report provides attack flow details, behavioral detection logic, GitHub/AWS/Salesforce hunting guidance, and IOCs (IP addresses and user-agent strings).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.