Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      College Students Embrace AI Despite Public Backlash at Graduation Ceremonies

      August 9, 2026

      Teamsters Challenge California’s Driverless Truck Rules in Court

      August 9, 2026

      Chime Cuts Workforce as AI Reshapes Fintech Employment

      August 8, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Snap Doubles Down on Augmented Reality Glasses as AI Hardware Race Intensifies

        August 8, 2026

        China Expands Its Artificial Intelligence Footprint Across Africa

        August 7, 2026

        Chinese Robot Maker Unitree’s IPO Signals Intensifying Global AI Race

        August 7, 2026

        Google AI Leadership Shakeup Signals Intensifying Battle for Artificial Intelligence Dominance

        August 7, 2026

        Semiconductor Conference Departure Signals Shift From San Francisco to Phoenix

        August 7, 2026
      • AI

        Teamsters Challenge California’s Driverless Truck Rules in Court

        August 9, 2026

        College Students Embrace AI Despite Public Backlash at Graduation Ceremonies

        August 9, 2026

        Appeals Court Clears Path for AI Shopping on Amazon Without Company’s Permission

        August 8, 2026

        Chime Cuts Workforce as AI Reshapes Fintech Employment

        August 8, 2026

        Snap Doubles Down on Augmented Reality Glasses as AI Hardware Race Intensifies

        August 8, 2026
      • Security

        China Expands Its Artificial Intelligence Footprint Across Africa

        August 7, 2026

        OpenAI, Anthropic Models Exposed After AI Agents Used Deception in Cybersecurity Tests

        August 6, 2026

        Chinese Router Backdoor Discovery Renews Warnings Over Beijing-Linked Supply Chain Risks

        August 6, 2026

        Visa’s $2.4 Billion BioCatch Acquisition Signals Escalating Battle Against AI-Driven Financial Fraud

        August 6, 2026

        Meta Acknowledges AI Security Breach as Autonomous Agent Incidents Multiply

        August 6, 2026
      • Health

        WhatsApp Age Verification Test Intensifies Online Child Safety Debate

        August 8, 2026

        TikTok Settles Teen Addiction Lawsuits as Social Media Litigation Expands

        August 8, 2026

        Coordinated Cyberattack Targets More Than 30 Minnesota Water Systems

        August 4, 2026

        Social Media Giants Face Expanding Legal Reckoning Over Teen Deaths

        August 3, 2026

        Florida Pastor’s Lawsuit Raises New Questions About AI Medical Advice

        July 30, 2026
      • Science

        Digital Forensics Failure Leads to Shocking Wrongful Conviction in Canada

        August 4, 2026

        Google Retreats After AI Satellite Imagery Sparks Disinformation Fears

        August 4, 2026

        Open-Weight AI Emerges as the Next Major Battleground in America’s Technology Race

        August 1, 2026

        AI’s Advance Into Elite Mathematics Raises New Questions About the Future of Human Discovery

        July 30, 2026

        India Launches First Hydrogen-Powered Passenger Train as Rail Modernization Accelerates

        July 20, 2026
      • Tech

        Larry Ellison’s High-Stakes AI Gamble Raises Questions About Oracle’s Future

        August 4, 2026

        AI Pioneer Urges Governments to Ensure Future AI Agents Are Intrinsically Good

        August 3, 2026

        Zuckerberg Urges Faster AI Development While Rejecting Centralized Control

        August 1, 2026

        Elon Musk Becomes The World’s First Former Trillionaire

        July 31, 2026

        Senate Hearing Examines AI Deception and Growing Threats to America’s Seniors

        July 31, 2026
      TallwireTallwire
      Home»Tech»FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing
      Tech

      FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing

      Updated:December 25, 20254 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing
      FBI Sounds Alarm over UNC6040 & UNC6395 Exploits of Salesforce via OAuth Breaches and Vishing
      Share
      Facebook Twitter LinkedIn Pinterest Email

      The FBI has issued a flash alert warning that two cybercriminal threat clusters—UNC6040 and UNC6395—are actively targeting organizations using Salesforce platforms, carrying out data theft and extortion attacks. UNC6395’s attacks in August 2025 stemmed from a breach of Salesloft’s GitHub account between March and June; this breach allowed attackers to steal OAuth tokens associated with the Salesloft Drift AI chatbot app, which were then used to access numerous Salesforce instances to exfiltrate sensitive data such as AWS keys, passwords, and Snowflake tokens. 

      Sources: Hacker News, Internet Crime Complaint Center

      Key Takeaways

      – OAuth & Third-Party App Risk: Integrations like Salesloft Drift that link to Salesforce via OAuth are being exploited; stolen tokens allow attackers to bypass many protections and gain access to customer data across multiple customers.

      – Social Engineering & Vishing Over Technical Exploits: These campaigns (especially by UNC6040) lean heavily on voice phishing, deceptive connected app authorizations, and impersonation rather than zero-day vulnerabilities, underlining that human-factor risks are still major.

      – Supply Chain & Credential Management Must Be Prioritized: Compromise of platforms like GitHub (in the case of Salesloft) or misconfigured connected apps magnify risk; organizations need tighter controls over credentials, external integrations, MFA, and least-privilege practices.

      In-Depth

      In recent months, the security landscape has seen alarming developments involving two threat clusters—UNC6040 and UNC6395—targeting Salesforce platforms via sophisticated, yet fundamentally social engineering-driven methods. The FBI’s flash alert makes clear that while technical vulnerabilities are part of the picture, attacks are being largely enabled by human trust and misconfigurations, especially in how connected apps and OAuth tokens are managed.

      UNC6395 first entered the stage in August 2025 with a breach rooted in a compromised GitHub account owned by Salesloft. Between March and June, attackers accessed multiple repositories, added guest users, and established workflows—activities that remained under the radar for months. With those footholds, they were able to grab OAuth tokens tied to the Salesloft Drift AI chatbot app. These tokens enabled access to Salesforce instances; attackers ran SOQL queries, exfiltrated data including sensitive credentials (AWS keys, passwords, Snowflake tokens), and deleted query jobs to avoid detection. 

       In response, Salesloft and Salesforce revoked the active tokens, removed the Drift app from the AppExchange, and urged customers to treat all integrations and credentials tied to Drift as potentially compromised. 

      UNC6040, active since approximately October 2024, is using voice phishing (vishing) and deceptive practices to trick employees—often in customer support or admin roles—into authorizing connected apps. One common approach involves guiding them during a vishing call to Salesforce’s connected apps setup pages, where they approve a malicious app (often a modified version of the Data Loader). That approval grants API-level access, allowing bulk data exfiltration via API queries. 

       Because the connected app is “trusted” (by the system once approved), traditional security barriers—MFA, password resets, login monitoring—are often evaded. After data theft, some victims are extorted—attackers may threaten to leak or expose data, sometimes leveraging association with known groups like ShinyHunters to increase pressure. 

      What both campaigns underscore is that even well-designed platforms like Salesforce, which may be secure from a technical standpoint, can still be compromised via poor integration management, lax credential protection, or weak monitoring. The attack vectors involve no inherent vulnerability in Salesforce, but rather exploitation of how external apps are connected and how human trust is leveraged. For defenders, the imperative is clear: audit all third-party integrations (especially those using OAuth), ensure strict least privilege and role separation, rotate and revoke credentials and tokens proactively, enable strong MFA for both platform and source repositories (e.g. GitHub), monitor for unexpected workflow changes or new external users, and train staff and call-handling personnel to recognize vishing or unusual authorization requests.

      As these threat actors evolve, organizations must operate under the assumption that silence from a group or a pause in activity doesn’t mean the threat is gone—only that it may be changing tactics.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleFandom-First Search Startup Lore Raises $1.1M to Fuel Deep Internet Discovery
      Next Article FCC Moves to Revoke Recognition of Seven Chinese Labs Over Security Concerns

      Related Posts

      Snap Doubles Down on Augmented Reality Glasses as AI Hardware Race Intensifies

      August 8, 2026

      China Expands Its Artificial Intelligence Footprint Across Africa

      August 7, 2026

      Chinese Robot Maker Unitree’s IPO Signals Intensifying Global AI Race

      August 7, 2026

      Google AI Leadership Shakeup Signals Intensifying Battle for Artificial Intelligence Dominance

      August 7, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Snap Doubles Down on Augmented Reality Glasses as AI Hardware Race Intensifies

      August 8, 2026

      China Expands Its Artificial Intelligence Footprint Across Africa

      August 7, 2026

      Chinese Robot Maker Unitree’s IPO Signals Intensifying Global AI Race

      August 7, 2026

      Google AI Leadership Shakeup Signals Intensifying Battle for Artificial Intelligence Dominance

      August 7, 2026
      Popular Topics
      Tesla Series A Tim Cook Samsung UAE Tech Satya Nadella spotlight Stocks Sundar Pichai Space trending Tesla Cybertruck SpaceX starlink Taiwan Tech Series B Satellite Software Startup Viral
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.