#UNC6040
UNC6040 might regret this... it's like DDOSing the FBI and saying "catch me if you can"
NEW, by me: Google has confirmed that some of its customers' data was stolen in a recent breach of one of its Salesforce databases.

Google attributed the hack to ShinyHunters, a group known for hacking into Salesforce instances using voice phishing attacks.

More:
Google says hackers stole its customers' data in a breach of its Salesforce database | TechCrunch
Google confirmed that one of its cloud-stored Salesforce databases was breached, exposing its customer data. Google attributed the breach to a hacking group, ShinyHunters, known for breaking into Sale...
techcrunch.com
August 6, 2025 at 2:43 PM
The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations' Salesforce environments to steal data and extort victims.
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data
The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations' Salesforce environments to steal data and extort victims.
www.bleepingcomputer.com
September 14, 2025 at 9:56 PM
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data
The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations' Salesforce environments to steal data and extort victims.
www.bleepingcomputer.com
September 14, 2025 at 10:12 PM
UNC6040 used voice-phishing to steal data from companies' Salesforce systems

cloud.google.com/blog/topics/...
June 4, 2025 at 5:51 PM
FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups
FBI Warns of Salesforce attacks by UNC6040 and UNC6395
The U.S. FBI issued a flash alert to warn of malicious activities carried out by two cybercriminal groups tracked as UNC6040 and UNC6395.
securityaffairs.com
September 13, 2025 at 8:02 PM
🚨 UPDATE ShinyHunters

With 3 allegedly active breaches (UNC6040, #Salesforce Aura, #AWS accounts), and a total over 3M Salesforce records, threat actor #ShinyHunters sets a final warning before the data release, on April 3rd.

#ransomNews #databreach
April 1, 2026 at 7:50 AM
Security breach with Google by a hacker group called "shinyhunters" (also tracked as UNC6040)

For anyone who hasn't heard of this and has a Gmail account

#Google #SecurityBreach #ChangeYourPassword #Gmail

www.fastcompany.com/91431686/goo...
Why Google is really warning 2.5 billion Gmail users to stop using their passwords
Your email account is the key to everything. Google is warning users to up their security.
www.fastcompany.com
November 9, 2025 at 7:17 PM
-California has an AI safety law
-Afghanistan shuts down its internet to block "immoral activities"
-CISA and others release OT guidance
-Germany issues passkey server guide
-The Netherlands won't support Chat Control
-Infoblox reports WebNIC to ICANN over malware op
-UNC6040, Lunar Spider profiles
October 1, 2025 at 8:20 AM
Google confirms ShinyHunters (UNC6040) breached its internal Salesforce database via a vishing scam, affecting SMB customer data.

Read: hackread.com/google-sales...

#CyberSecurity #ShinyHunters #UNC6040 #Salesforce #DataBreach #Google
Google Confirms Salesforce Data Breach by ShinyHunters via Vishing Scam
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
August 7, 2025 at 2:42 PM
FBI Warns Of UNC6040 And UNC6395 Targeting Salesforce Platforms In Data Theft Attacks - https://mwyr.es/4BRHWCB #thn #infosec
FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks
FBI warns UNC6040, UNC6395 breached Salesforce via OAuth tokens and vishing, sparking theft and extortion.
mwyr.es
September 15, 2025 at 1:11 AM
UNC3944 vishes help desks; UNC6395 steals CRM via hijacked OAuth; UNC6040 rides SaaS add-ons. Tap “Allow All” again, I dare you. 🕷️🔐

Skim it, then lock your scopes—subscribe if you want fewer surprises.

blog.alphahunt.io/saas-data-th...

#AlphaHunt #CyberSecurity #OAuth #SaaS
SaaS Data Theft: How UNC3944, UNC6040, and UNC6395 Quietly Redefined Cloud Risk
Three financially motivated clusters—UNC3944 (“Scattered Spider”), UNC6040, and UNC6395—are driving a surge in SaaS and cloud data theft via social engineering, OAuth abuse, and supply-chain attacks.…
blog.alphahunt.io
September 21, 2025 at 7:46 PM
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations' Salesforce environments to steal data and extort victims. [...]
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data
The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations' Salesforce environments to steal data and extort victims. [...]
www.bleepingcomputer.com
September 14, 2025 at 10:03 PM
ForceHound is an open-source Python tool that creates a BloodHound CE identity graph for auditing Salesforce orgs, mapping profiles, permission sets, roles, connected apps, and sharing at multiple levels. #ForceHound #SalesforceAudit #UNC6040
Auditing Salesforce Permission Hierarchies with ForceHound 
ForceHound is an open-source Python collector that builds a BloodHound CE identity graph to help audit Salesforce orgs by visualizing profiles, permission sets, roles, connected apps, field- and record-level sharing, and system capabilities. The post details collection modes (API, Aura, both), empirical CRUD probing, BloodHound CE integration, audit logging, scope-control flags, and frames urgency after the UNC6040 campaign that abused malicious Connected Apps. #ForceHound #UNC6040
www.hendryadrian.com
April 18, 2026 at 9:30 PM
Google Confirma Brecha de Seguridad en su Instancia de Salesforce Asociada a UNC6040 | 2.500 millones de cuentas de Gmail afectadas www.newstecnicas.info.ve/2025/08/brec...
Google Confirma Brecha de Seguridad en su Instancia de Salesforce Asociada a UNC6040 | 2.500 millones de cuentas de Gmail afectadas
Google confirma una brecha de seguridad en su base de datos de Salesforce, con exfiltración de datos empresariales básicos. Se presume un ataque de UN
www.newstecnicas.info.ve
September 5, 2025 at 4:15 PM
UNC6040 is a new financially-driven threat gang "specifically designed to compromise organization’s Salesforce instances for large-scale data theft and subsequent extortion."

Expect a wave of extortion attempts at big companies; sounds similar in tactics to the Snowflake data thefts last year.
Unclear on overlap with UNC3944/Scattered Spider / Octo Tempest etc, but clearly a popular tactic. Why reinvent the wheel if things work. Can’t express how important it is for Intel to reach directly to not only cyber teams but IT, Helpdesk, etc. One team mentality can do wonders.
June 4, 2025 at 3:18 PM
UNC3944 vishes your help desk, UNC6395 loots your CRM tokens, and UNC6040 strolls through SaaS supply chains. But sure, keep trusting “Allow All” OAuth prompts. 🕷️☠️

Read the breakdown & maybe lock down your scopes: blog.alphahunt.io/saas-data-th...

#AlphaHunt #CyberSecurity #SaaS #OAuth
SaaS Data Theft: How UNC3944, UNC6040, and UNC6395 Quietly Redefined Cloud Risk
Three financially motivated clusters—UNC3944 (“Scattered Spider”), UNC6040, and UNC6395—are driving a surge in SaaS and cloud data theft via social engineering, OAuth abuse, and supply-chain attacks.…
blog.alphahunt.io
September 15, 2025 at 9:45 PM
Detecting UNC6040 Vishing Attacks in SaaS

Spot UNC6040 vishing attacks, secure OAuth apps, boost SaaS security with AppOmni’s Threat Detection.

#hackernews #news
Detecting UNC6040 Vishing Attacks in SaaS
Spot UNC6040 vishing attacks, secure OAuth apps, boost SaaS security with AppOmni’s Threat Detection.
securityboulevard.com
August 17, 2025 at 2:46 PM
Salesforce customers duped by series of social-engineering attacks. Google Threat Intelligence Group said about 20 organizations have been hit by a cybercrime group it tracks as UNC6040. via @mattkapko.com cyberscoop.com/google-unc60...
Salesforce customers duped by series of social-engineering attacks
Google Threat Intelligence Group said about 20 organizations have been hit by a cybercrime group it tracks as UNC6040.
cyberscoop.com
June 4, 2025 at 9:03 PM
Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening
Recommendations
cloud.google.com/blog/topics/...
Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations | Google Cloud Blog
Proactive hardening, detection, and logging recommendations to protect against UNC6040 and broader SaaS application compromises.
cloud.google.com
October 1, 2025 at 1:11 PM
Spammers really made answering voice calls absolutely obnoxious.

search.app/qLLUe
Do Not Answer These Calls — Google Issues New Smartphone Warning
Don’t pick up the phone — Google warns of UNC6040 calls danger.
search.app
June 11, 2025 at 5:19 AM