Workforce and access social engineering · Also called connected app vishing, OAuth vishing, Salesforce Data Loader vishing, UNC6040, malicious app authorization call
Vishing into a malicious OAuth connected app
Vishing into a connected app is an attack in which a caller posing as IT support talks an employee into authorising a malicious app on a company cloud service, often by entering a connection code. The app then gets standing access to company data, which the attackers export and later use for extortion.
How it works
- An attacker calls an employee while posing as IT support.
- The caller guides the employee to the service's connected app setup page and asks them to enter a connection code, which authorises an attacker-controlled app, sometimes a modified data export tool with a harmless-sounding name.
- The app's OAuth access lets the attackers query and export large amounts of data, and any passwords or MFA codes given on the call help them reach other cloud services.
- Weeks or months later, the victim receives an extortion demand, for example for bitcoin within 72 hours, threatening to publish the data.
Red flags
- An unexpected caller from IT support asks you to open an app authorisation or connected app setup page.
- The caller reads you a code to enter so that a tool can be connected to your account.
- An app you do not recognise asks for access to company data, even with a helpful-sounding name such as a ticket portal.
- The caller also asks for your password or an MFA code.
If you are targeted
- Stop: hang up and do not enter any code or approve any app.
- If you already approved something, tell your security team at once so administrators can revoke the app's access and tokens and check what data was exported.
- Change your password and let security review sign-ins to your other cloud accounts.
- Report it to your security team, then to the national service; our Report a scam page lists where, such as ic3.gov in the US.
Prevention
For individuals
- Never enter a connection code or approve an app because a caller asked you to.
- If a caller says they are from IT, hang up and call the help desk back on the number you already know.
- Never share your password or MFA codes on a call.
For organisations
- Restrict who can authorise or install connected apps to a few trusted administrators, with a review and approval process or an allowlist of known apps.
- Limit powerful data export permissions, such as API access for bulk data tools, to the users who need them.
- Restrict logins and app authorisations to trusted IP ranges, and challenge or deny those from unexpected networks.
- Monitor for large data downloads and unusual API use, and require MFA for all direct logins.
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Phishing and spoofing losses reported to the FBI IC3 in 2025 | $215.8M | US, 2025, FBI IC3 |
Real cases
2025-06 · US · Disclosed
Google Salesforce instance hit by UNC6040 vishing campaign, 2025
Delivered through: Voice phishing (vishing), OAuth consent phishing
How official datasets classify it
- FBI IC3
- Phishing/Spoofing
- MITRE ATT&CK
- T1566.004, T1528
Questions
- How can a phone call give attackers access to our cloud data?
- The caller does not need your password. Google Threat Intelligence describes callers posing as IT support who guide employees to approve a malicious connected app, which then has OAuth access to query and export data.
- How do we stop malicious connected apps?
- Only let a few administrators authorise new apps, keep an allowlist, limit bulk export permissions, and watch for large downloads. Train staff never to approve an app or enter a code because a caller asked.
Related scams
- Help desk password and MFA reset impersonation
- Data theft extortion
- Callback phishing (fake subscription renewal)