Google reveals it became one of the Salesforce attack victims in June
ID: 752c5ac5-9ce6-5b33-a114-e1171035233f
STIX ID: report--752c5ac5-9ce6-5b33-a114-e1171035233f
Feed Name: DataBreaches.Net
**Google** disclosed that in June a corporate Salesforce CRM instance was compromised via voice-phishing intrusions attributed to **UNC6040**, enabling brief exfiltration of basic SMB contact details before access was cut; Google’s GTIG tracks ensuing extortion as **UNC6240** (72-hour bitcoin demands). **ShinyHunters** claimed involvement and plans to extort, while GTIG suggested a potential data leak site escalation (which ShinyHunters denies). The report places Google’s breach within an ongoing campaign targeting Salesforce environments for data theft and extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
