Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

FBI Shares IoCs for Recent Salesforce Intrusion Campaigns

Posted on September 15, 2025September 15, 2025 By CWS

The FBI has shared indicators of compromise (IoCs) related to two malicious campaigns concentrating on Salesforce clients for knowledge theft and extortion.

The primary marketing campaign, attributed to a risk actor tracked as UNC6040 and ongoing for a number of months, depends on voice phishing (vishing) to persuade staff on the sufferer organizations to grant them entry to the Salesforce occasion or to share credentials for the portal.

In some circumstances, the attackers information the worker to approve a modified Salesforce Knowledge Loader software variant that grants them entry to the information saved within the Salesforce occasion.

“UNC6040 risk actors have utilized phishing panels, directing victims to go to from their cellphones or work computer systems in the course of the social engineering calls. After acquiring entry, UNC6040 risk actors have then used API queries to exfiltrate massive volumes of information in bulk,” the FBI notes in its alert (PDF).

After stealing the information, the cybercriminals ship extortion calls for to the sufferer organizations, threatening to launch the knowledge publicly except a ransom is paid in cryptocurrency.

Salesforce warned of such a assaults in March, roughly three months earlier than Google mentioned that, in some situations, UNC6040 was seen transferring laterally to different platforms, akin to Microsoft 365, Okta, and Office.

UNC6040 has claimed affiliation with the notorious ShinyHunters extortion group, which seems linked to the Scattered Spider hackers.

The second malicious operation the FBI warns about is the latest widespread Salesforce-Salesloft knowledge theft marketing campaign that hit over 700 organizations by way of the combination with the Drift AI chatbot, and which has been attributed to a risk actor tracked as UNC6395.Commercial. Scroll to proceed studying.

As a part of the assault, hackers used compromised OAuth tokens for Drift to entry the Salesforce situations and steal massive quantities of information. The hackers exfiltrated the tokens from Drift’s AWS occasion, after gaining access to Salesloft’s GitHub account between March and June 2025.

Over a dozen cybersecurity companies have disclosed knowledge breaches linked to the assault, with HackerOne and Qualys being the newest to verify the influence.

Along with publishing IoCs related to these campaigns, the FBI is recommending that organizations implement phishing-resistant multi-factor authentication (MFA), prepare their name middle on phishing, implement authentication, authorization, and accounting (AAA) techniques, implement IP-based entry restrictions, monitor logs, and evaluate third-party integrations.

“The FBI recommends organizations examine and vet indicators previous to taking motion, akin to blocking,” the company notes.

Associated: US Authorities Is Investigating Messages Impersonating Trump’s Chief of Employees, Susie Wiles

Associated: West Virginia Credit score Union Notifying 187,000 Folks Impacted by 2023 Knowledge Breach

Associated: New ‘SmartAttack’ Steals Air-Gapped Knowledge Utilizing Smartwatches

Associated: Russian Hacker Will get 12 Years in Huge Knowledge Theft Scheme

Security Week News Tags:Campaigns, FBI, Intrusion, IoCs, Salesforce, Shares

Post navigation

Previous Post: LangChainGo Vulnerability Let Attackers Access Sensitive Files
Next Post: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More

Related Posts

Cisco Patches Another Critical ISE Vulnerability Security Week News
Honeywell Experion PKS Flaws Allow Manipulation of Industrial Processes Security Week News
Academics Build AI-Powered Android Vulnerability Discovery and Validation Tool Security Week News
Microsoft Paid Out $17 Million in Bug Bounties in Past Year Security Week News
Fable Security Raises $31 Million for Human Risk Management Platform Security Week News
Major Enterprise AI Assistants Can Be Abused for Data Theft, Manipulation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Terra Security Raises $30 Million for AI Penetration Testing Platform
  • BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies
  • Mustang Panda With SnakeDisk USB Worm and Toneshell Backdoor Seeking to Penetrate Air-Gap Systems
  • 6 Browser-Based Attacks Security Teams Need to Prepare For Right Now
  • Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Terra Security Raises $30 Million for AI Penetration Testing Platform
  • BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies
  • Mustang Panda With SnakeDisk USB Worm and Toneshell Backdoor Seeking to Penetrate Air-Gap Systems
  • 6 Browser-Based Attacks Security Teams Need to Prepare For Right Now
  • Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News