ShinyHunters and UNC6395: Inside the Salesforce and Salesloft Breaches
ID: d947c923-0cd4-5514-b1bb-a42953dcfba9
STIX ID: report--d947c923-0cd4-5514-b1bb-a42953dcfba9
Feed Name: Mitiga
Threat Score
Mitiga Labs outlines two active campaigns against Salesforce and related supply-chain services: ShinyHunters (UNC6040) uses OAuth Device Flow plus vishing to obtain access and demand ransom, while UNC6395 exploited Salesloft/Drift to steal OAuth tokens and exfiltrate customer Salesforce data; the report provides attack flow details, behavioral detection logic, GitHub/AWS/Salesforce hunting guidance, and IOCs (IP addresses and user-agent strings).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
