Skip to content
NetarxImpact Database
Vishing (Voice Phishing)Suspected AI-enabledConfirmed

Google's own Salesforce instance hit by UNC6040 IT-support vishing

Google · Technology · United States · June 2025

What happened

Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.

How the deception worked

Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.

AI involvement · Suspected AI-enabled

EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.

The control that would have caught it· our reading, not a claim from the sources

Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.

Sources (5)

  1. Salesforce customers duped by series of social-engineering attacks
    CyberScoop·cyberscoop.comOpen ↗
  2. Google confirms Salesforce CRM breach, faces extortion threat
    Security Affairs·securityaffairs.comOpen ↗
  3. FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups
    Security Affairs·securityaffairs.comOpen ↗
  4. Google Among Victims in Ongoing Salesforce Data Theft Campaign
    Infosecurity Magazine·infosecurity-magazine.comOpen ↗
  5. ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications
    EclecticIQ·blog.eclecticiq.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.