Skip to content

2025-06-01 (incident), Month only: Google says one of its corporate Salesforce instances was affected in June 2025. · US · Google

Google Salesforce instance hit by UNC6040 vishing campaign, 2025

Disclosed by the affected organisation.

Google Threat Intelligence tracks UNC6040, a group that phones employees while posing as IT support and talks them into authorising a modified Salesforce Data Loader as a connected app, then exports Salesforce data for later extortion. Google disclosed that in June 2025 one of its own corporate Salesforce instances, used for small and medium business contact data, was affected by similar activity. It said the data retrieved was basic, largely public business information such as names and contact details.

Timeline

  1. 2025-06-01 In June 2025 one of Google's corporate Salesforce instances is affected by activity similar to UNC6040's.
  2. 2025-06-04 Google Threat Intelligence publishes its analysis of the UNC6040 voice phishing campaign.
  3. 2025-08-08 Google completes email notifications to those affected.
  4. 2025-09-12 The FBI warns that UNC6040 callers pose as IT support and trick staff into authorising malicious connected apps.

Lessons

Scam types: Vishing into a malicious OAuth connected app, Data theft extortion · Techniques: Voice phishing (vishing), OAuth consent phishing

Sources

  1. Google Cloud: The cost of a call: from voice phishing to data extortion (Company disclosure, primary, accessed 2026-09-24)
  2. FBI FLASH-20250912-001: Cyber criminal groups UNC6040 and UNC6395 compromising Salesforce instances for data theft and extortion (Law enforcement, primary, accessed 2026-09-24)