logo

Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations

ID: 83d78978-3059-5d42-9c60-e099c0423239

STIX ID: report--83d78978-3059-5d42-9c60-e099c0423239

Feed Name: Threat Intelligence

Threat Score
70/100

Date Published: 2025-09-30

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report provides prioritized proactive hardening recommendations to defend against UNC6040 activity targeting SaaS applications via social engineering and vendor-impersonation. It outlines robust identity verification (live video proofing, out-of-band checks), identity provider controls (SSO, phishing-resistant MFA, device trust), automated risk-based response actions, and special handling procedures for help desk and third-party vendor requests to prevent credential theft and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.