Cyber Criminal Groups Compromising Salesforce Instances for Data Theft and Extortion
Sept. 15, 2025, 9:15 p.m.
Description
Two cyber criminal groups, UNC6040 and UNC6395, are targeting organizations' Salesforce platforms for data theft and extortion. UNC6040 uses social engineering, particularly voice phishing, to gain access to Salesforce accounts. They trick employees into granting access or sharing credentials, then use API queries or malicious connected apps to exfiltrate data. UNC6395 exploits compromised OAuth tokens for the Salesloft Drift application to access Salesforce instances. Both groups have been observed exfiltrating large volumes of customer data. Victims of UNC6040 have received extortion emails demanding cryptocurrency payments to prevent data publication. The FBI has provided numerous IP addresses and other indicators of compromise associated with these groups, along with recommended mitigations to enhance security and prevent such attacks.
Tags
Date
- Created: Sept. 15, 2025, 2:01 p.m.
- Published: Sept. 15, 2025, 2:01 p.m.
- Modified: Sept. 15, 2025, 9:15 p.m.
Indicators
- 96.44.191.157
- 96.44.191.141
- 96.44.189.109
- 94.156.167.237
- 91.199.42.164
- 87.120.112.134
- 83.147.52.41
- 8.131.130.53
- 72.5.42.72
- 69.246.124.204
- 68.63.167.122
- 68.235.43.202
- 66.63.167.122
- 67.217.228.216
- 64.95.84.159
- 64.95.11.225
- 64.95.11.112
- 64.94.84.78
- 51.89.240.10
- 38.22.104.226
- 31.58.169.96
- 31.58.169.92
- 31.58.169.85
- 23.162.8.66
- 23.94.126.63
- 23.145.40.99
- 23.145.40.165
- 23.145.40.167
- 206.217.206.84
- 206.217.206.26
- 206.217.206.64
- 206.217.206.25
- 206.217.206.14
- 206.217.206.124
- 206.217.206.104
- 205.234.181.14
- 198.54.133.123
- 198.54.130.108
- 198.44.129.88
- 198.54.130.100
- 198.44.129.56
- 198.244.224.200
- 192.198.82.235
- 195.54.130.100
- 163.5.149.152
- 191.96.207.201
- 185.209.199.56
- 151.242.41.182
- 151.242.58.76
- 147.161.173.90
- 146.70.198.112
- 146.70.189.111
- 146.70.189.47
- 146.70.185.47
- 146.70.173.60
- 146.70.165.47
- 104.223.118.62
- 104.193.135.221
- 196.251.83.162