2025-06-01 (incident), Month only: Google says one of its corporate Salesforce instances was affected in June 2025. · US · Google
Google Salesforce instance hit by UNC6040 vishing campaign, 2025
Disclosed by the affected organisation.
Google Threat Intelligence tracks UNC6040, a group that phones employees while posing as IT support and talks them into authorising a modified Salesforce Data Loader as a connected app, then exports Salesforce data for later extortion. Google disclosed that in June 2025 one of its own corporate Salesforce instances, used for small and medium business contact data, was affected by similar activity. It said the data retrieved was basic, largely public business information such as names and contact details.
Timeline
- 2025-06-01 In June 2025 one of Google's corporate Salesforce instances is affected by activity similar to UNC6040's.
- 2025-06-04 Google Threat Intelligence publishes its analysis of the UNC6040 voice phishing campaign.
- 2025-08-08 Google completes email notifications to those affected.
- 2025-09-12 The FBI warns that UNC6040 callers pose as IT support and trick staff into authorising malicious connected apps.
Lessons
- Limit who can authorise connected apps, and require review before a new app can access CRM data.
- Tell staff that IT support will never ask them to enter a connection code or approve an app during a call.
- Monitor for large data exports and apps with unfamiliar names, such as a ticket portal that is really a data loader.
Scam types: Vishing into a malicious OAuth connected app, Data theft extortion · Techniques: Voice phishing (vishing), OAuth consent phishing
Sources
- Google Cloud: The cost of a call: from voice phishing to data extortion (Company disclosure, primary, accessed 2026-09-24)
- FBI FLASH-20250912-001: Cyber criminal groups UNC6040 and UNC6395 compromising Salesforce instances for data theft and extortion (Law enforcement, primary, accessed 2026-09-24)