logo

Google reveals it became one of the Salesforce attack victims in June

ID: 752c5ac5-9ce6-5b33-a114-e1171035233f

STIX ID: report--752c5ac5-9ce6-5b33-a114-e1171035233f

Feed Name: DataBreaches.Net

Threat Score
68/100

Date Published: 2025-08-06

Date Updated: 2026-04-19

Author: Dissent

...
...

**Google** disclosed that in June a corporate Salesforce CRM instance was compromised via voice-phishing intrusions attributed to **UNC6040**, enabling brief exfiltration of basic SMB contact details before access was cut; Google’s GTIG tracks ensuing extortion as **UNC6240** (72-hour bitcoin demands). **ShinyHunters** claimed involvement and plans to extort, while GTIG suggested a potential data leak site escalation (which ShinyHunters denies). The report places Google’s breach within an ongoing campaign targeting Salesforce environments for data theft and extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.