Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Robot Dogs on Patrol: How AI Can Make Law Enforcement Safer, Smarter, and More Effective

      August 30, 2026

      Trump Launches Plan for U.S. Space Academy to Build America’s Next Space Workforce

      August 30, 2026

      Federal Appeals Court Backs State Authority Over Kalshi Sports Contracts

      August 30, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

        August 30, 2026

        Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

        August 29, 2026

        Chinese Bot Network Targets U.S. Data-Center And Energy Debate

        August 29, 2026

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        American-Made Space Armor Heads to Orbit on SpaceX Mission

        August 29, 2026
      • AI

        ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

        August 30, 2026

        Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

        August 29, 2026

        Altman Concedes AI Industry Has Failed to Make Its Case to the Public

        August 29, 2026

        Chinese Bot Network Targets U.S. Data-Center And Energy Debate

        August 29, 2026

        Free AI Boot Camp Expands Technology Training for Chicago High School Students

        August 29, 2026
      • Security

        Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

        August 29, 2026

        Chinese Bot Network Targets U.S. Data-Center And Energy Debate

        August 29, 2026

        Password-Free Flock Cameras Raise New Questions About America’s Expanding Surveillance Network

        August 29, 2026

        Dallas Police Extend Flock Camera Data Retention to One Year

        August 29, 2026

        Uber Adds Live Video Monitoring for Teen Rides

        August 28, 2026
      • Health

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        Silicon Valley Parents Push Back Against Classroom Technology and AI

        August 27, 2026

        Moderna’s Cancer Vaccine Breakthrough Revives Hope for Personalized Oncology

        August 25, 2026

        AI Chatbots Expand Access While Raising New Mental Health Concerns

        August 23, 2026

        TikTok Agrees to $400 Million Settlement Over Children’s Privacy Violations

        August 23, 2026
      • Science

        Trump Launches Plan for U.S. Space Academy to Build America’s Next Space Workforce

        August 30, 2026

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        American-Made Space Armor Heads to Orbit on SpaceX Mission

        August 29, 2026

        Washington Deepens Strategic Rare Earth Investment to Counter China

        August 26, 2026

        SpaceX Confirms $100 Billion Louisiana Starbase Expansion

        August 26, 2026
      • Tech

        Gen Z’s Fading Handwriting Skills Raise New Concerns About Communication

        August 28, 2026

        OpenAI Infrastructure Shake-Up Continues as Data Center Chief Departs Ahead of IPO

        August 27, 2026

        New York Overtakes San Francisco as Largest U.S. Tech Talent Market

        August 25, 2026

        Google AI Bias Controversy Raises Fresh Questions About Reliability

        August 25, 2026

        San Francisco’s High-Tech Public Toilet Rollout Stalls After Repeated Breakdowns

        August 25, 2026
      TallwireTallwire
      Home»Tech»FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing
      Tech

      FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing

      Updated:December 25, 20254 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing
      FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing
      Share
      Facebook Twitter LinkedIn Pinterest Email

      The FBI has issued a flash alert warning that two cybercriminal threat clusters—UNC6040 and UNC6395—are actively targeting organizations using Salesforce platforms, carrying out data theft and extortion attacks. UNC6395’s attacks in August 2025 stemmed from a breach of Salesloft’s GitHub account between March and June; this breach allowed attackers to steal OAuth tokens associated with the Salesloft Drift AI chatbot app, which were then used to access numerous Salesforce instances to exfiltrate sensitive data such as AWS keys, passwords, and Snowflake tokens. 

      Sources: Hacker News, Internet Crime Complaint Center

      Key Takeaways

      – OAuth & Third-Party App Risk: Integrations like Salesloft Drift that link to Salesforce via OAuth are being exploited; stolen tokens allow attackers to bypass many protections and gain access to customer data across multiple customers.

      – Social Engineering & Vishing Over Technical Exploits: These campaigns (especially by UNC6040) lean heavily on voice phishing, deceptive connected app authorizations, and impersonation rather than zero-day vulnerabilities, underlining that human-factor risks are still major.

      – Supply Chain & Credential Management Must Be Prioritized: Compromise of platforms like GitHub (in the case of Salesloft) or misconfigured connected apps magnify risk; organizations need tighter controls over credentials, external integrations, MFA, and least-privilege practices.

      In-Depth

      In recent months, the security landscape has seen alarming developments involving two threat clusters—UNC6040 and UNC6395—targeting Salesforce platforms via sophisticated, yet fundamentally social engineering-driven methods. The FBI’s flash alert makes clear that while technical vulnerabilities are part of the picture, attacks are being largely enabled by human trust and misconfigurations, especially in how connected apps and OAuth tokens are managed.

      UNC6395 first entered the stage in August 2025 with a breach rooted in a compromised GitHub account owned by Salesloft. Between March and June, attackers accessed multiple repositories, added guest users, and established workflows—activities that remained under the radar for months. With those footholds, they were able to grab OAuth tokens tied to the Salesloft Drift AI chatbot app. These tokens enabled access to Salesforce instances; attackers ran SOQL queries, exfiltrated data including sensitive credentials (AWS keys, passwords, Snowflake tokens), and deleted query jobs to avoid detection. 

       In response, Salesloft and Salesforce revoked the active tokens, removed the Drift app from the AppExchange, and urged customers to treat all integrations and credentials tied to Drift as potentially compromised. 

      UNC6040, active since approximately October 2024, is using voice phishing (vishing) and deceptive practices to trick employees—often in customer support or admin roles—into authorizing connected apps. One common approach involves guiding them during a vishing call to Salesforce’s connected apps setup pages, where they approve a malicious app (often a modified version of the Data Loader). That approval grants API-level access, allowing bulk data exfiltration via API queries. 

       Because the connected app is “trusted” (by the system once approved), traditional security barriers—MFA, password resets, login monitoring—are often evaded. After data theft, some victims are extorted—attackers may threaten to leak or expose data, sometimes leveraging association with known groups like ShinyHunters to increase pressure. 

      What both campaigns underscore is that even well-designed platforms like Salesforce, which may be secure from a technical standpoint, can still be compromised via poor integration management, lax credential protection, or weak monitoring. The attack vectors involve no inherent vulnerability in Salesforce, but rather exploitation of how external apps are connected and how human trust is leveraged. For defenders, the imperative is clear: audit all third-party integrations (especially those using OAuth), ensure strict least privilege and role separation, rotate and revoke credentials and tokens proactively, enable strong MFA for both platform and source repositories (e.g. GitHub), monitor for unexpected workflow changes or new external users, and train staff and call-handling personnel to recognize vishing or unusual authorization requests.

      As these threat actors evolve, organizations must operate under the assumption that silence from a group or a pause in activity doesn’t mean the threat is gone—only that it may be changing tactics.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleFandom-First Search Startup Lore Raises $1.1M to Fuel Deep Internet Discovery
      Next Article FCC Moves to Revoke Recognition of Seven Chinese Labs Over Security Concerns

      Related Posts

      ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

      August 30, 2026

      Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

      August 29, 2026

      Chinese Bot Network Targets U.S. Data-Center And Energy Debate

      August 29, 2026

      Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

      August 29, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

      August 30, 2026

      Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

      August 29, 2026

      Chinese Bot Network Targets U.S. Data-Center And Energy Debate

      August 29, 2026

      Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

      August 29, 2026
      Popular Topics
      Tesla Cybertruck Satellite Satya Nadella spotlight Series B Viral Space Taiwan Tech Stocks starlink Sundar Pichai Tesla trending Series A SpaceX Software Tim Cook Samsung UAE Tech Startup
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.