{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa"},"incident":{"title":"UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app","date":"2025-06-04","date_precision":"day","victim_org":"Approximately 20 Salesforce customer organisations, later including Google","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"Google Threat Intelligence described live English-speaking callers; no synthetic voice was reported.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"No aggregate loss figure; extortion demands followed the intrusions by several months.","records_affected":null,"threat_actor":"UNC6040, with extortion branded as ShinyHunters (UNC6240)","summary":"Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.","how_it_worked":"The caller posed as internal IT support and walked the employee to Salesforce's connected app setup page, instructing them to enter an eight-digit connection code. That code authorised an attacker-controlled OAuth application, a modified build of Salesforce's legitimate Data Loader utility renamed to look like an internal ticketing tool. Because the victim performed the authorisation themselves within a genuine Salesforce workflow, no credential theft or exploit was needed and the resulting access carried the user's own permissions. The attackers then bulk-exported CRM records via the API, and used harvested credentials to move laterally into Okta, Workplace and Microsoft 365. Extortion demands, branded as ShinyHunters, followed months later.","lessons":"Restrict connected-app authorisation to administrators through Salesforce's API access control, allow-list approved OAuth applications, and train staff that IT will never guide them through granting an app access by phone.","confidence":"Confirmed","sources":[{"title":"Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App","url":"https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-unc6040-vishes-salesforce-customers-into-installing-a-rebranded-data-loa"}}