Close Menu
TechurzTechurz
    What's Hot

    MCP startup Runlayer accuses Rippling of stealing its product idea

    July 28, 2026

    Ozlo’s Sleepbuds 2 build on Bose’s sleep earbud legacy

    July 28, 2026

    Cursor makes its biggest India push yet ahead of SpaceX acquisition with localized pricing

    July 28, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • MCP startup Runlayer accuses Rippling of stealing its product idea
    • Ozlo’s Sleepbuds 2 build on Bose’s sleep earbud legacy
    • Cursor makes its biggest India push yet ahead of SpaceX acquisition with localized pricing
    • Antares raises $470M to build nuclear reactors for the US military
    • Ilya Sutskever’s Safe Superintelligence partners with Nvidia to scale its AI research
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - Cybercriminals are stealing business Salesforce data with this simple trick – don’t fall for it
    Security

    Cybercriminals are stealing business Salesforce data with this simple trick – don’t fall for it

    TechurzBy TechurzJune 5, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Cybercriminals are stealing business Salesforce data with this simple trick - don't fall for it
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Mensent Photography/Getty

    Do you use Salesforce at your business? If so, then you’ll want to watch out for a new phishing attack in which hackers aim to steal your Salesforce data.

    In a blog post published Wednesday, Google’s Threat Intelligence Group explained how the attackers are using vishing, or voice phishing, to trick employees into granting access to Salesforce records. The goal is to steal large amounts of confidential data in an attempt to extort the victims. Here’s how it works.

    Impersonating IT support personnel, the cybercriminals behind the campaign call an unsuspecting employee at a targeted business. During the call, that employee is instructed to visit an alleged Salesforce setup page where they’re told to download and install an application called Salesforce Data Loader.

    Also: Clicked on a phishing link? 7 steps to take immediately to protect your accounts

    The Data Loader app itself is real and is used to import, export, or change Salesforce records by connecting to the internal database. But the version at the web page is a modified one that’s malicious and controlled by the attackers.

    Once the app is installed and connected, the hackers can access, query, and export sensitive Salesforce records for their own devious purposes. The data exfiltration typically occurs immediately after the group has gained access.

    In some cases, the criminals ask the employee for user credentials and multi-factor authentication codes through which they can export the Salesforce data. The attackers use Mullvad VPN IP addresses to access the Salesforce environments.

    They’ll also sign in with usernames and passwords captured through credential harvesting or vishing. Armed with those credentials, they can move laterally through a network where they capture data from other cloud-based platforms, including Microsoft 365 and Okta.

    Google

    In its post, Google identified the group behind the attack as UNC6040, which specializes in voice phishing as a form of social engineering. But UNC6040 may not be working alone.

    The actual extortion often doesn’t occur until several months after the initial attack. That could point to a second cybercrime group whose role is to monetize access to the data, according to Google. UNC6040 itself has even claimed to be working with hacking group ShinyHunters to pressure their victims into paying up.

    Further, Google’s Threat Intelligence researchers have discovered other attacks similar to those staged by UNC6040. These all share certain tactics, techniques, and procedures (TTPs), such as impersonating IT support in a vishing scam, targeting Okta credentials, and focusing on English-speaking users at multinational companies. Dubbing this loose collective “The Com,” Google acknowledged that these similarities could simply mean that the attackers are operating in the same community rather than directly joining forces.

    Also important to note is that the attacks don’t stem from any vulnerabilities in Salesforce or in the other cloud-based services. Rather, the criminals take advantage of a familiar and always reliable social engineering tactic. In these case, employees willingly acquiesce to the requests of an unknown caller impersonating a trusted or official entity. Despite all the employee warnings and training about phishing and vishing, scammers know that they can still find someone who will take the bait.

    “Salesforce has enterprise-grade security built into every part of our platform, and there’s no indication the issue described stems from any vulnerability inherent to our services,” a Salesforce spokesperson said in a statement to ZDNET. “Attacks like voice phishing are targeted social engineering scams designed to exploit gaps in individual users’ cybersecurity awareness and best practices.”

    Both Google and Salesforce offer tips on protecting your data from these types of scams. These include granting users only the permissions essential for their roles, managing access to connected applications, enforcing multi-factor authentication, setting up a limited range of trusted IP addresses for logins, looking at the security tools available through Salesforce Shield, and adding a specific security contact to your organization.

    Get the morning’s top stories in your inbox each day with our Tech Today newsletter.

    Business Cybercriminals data dont fall Salesforce simple stealing Trick
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleRefi Rates Fall, but Still Near 7%: Today’s Mortgage Refinance Rates for June 5, 2025
    Next Article Don’t be fooled into thinking AI is coming for your job – here’s the truth
    Techurz
    • Website

    Related Posts

    Opinion

    MCP startup Runlayer accuses Rippling of stealing its product idea

    July 28, 2026
    Opinion

    Anthropic, Blackstone bet the next trillion-dollar AI business is implementation, not models

    July 15, 2026
    Opinion

    Why this CEO thinks video games make better training data than the internet

    July 8, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.