What happened
Google Threat Intelligence Group disclosed in August 2025 that one of Google's own corporate Salesforce instances had been affected in June 2025 by UNC6040, the voice-phishing crew it had documented in June. The exposed data was confined to business names, phone numbers and sales notes for small and medium businesses, largely publicly available. ShinyHunters claimed 2.55 million records and demanded roughly 20 bitcoin. The wider campaign affected roughly 20 organisations across hospitality, retail and education.
How the deception worked
Operators phoned employees claiming to be IT support resolving a non-existent support ticket, then walked the target to a fake Salesforce Setup Connect page and had them enter an eight-digit code. That code authorised an OAuth connected app, a modified version of Salesforce's Data Loader, into the tenant. The trick is that no password or MFA factor is ever stolen; the victim performs a legitimate, fully authenticated authorisation, and the attacker's tool inherits the victim's data rights and exports records in bulk through a sanctioned API path.
AI involvement · Suspected AI-enabled
EclecticIQ reported the same actor set abused AI voice-agent platforms such as Bland AI and Vapi to automate vishing calls at scale; AI use in the Google call specifically is not confirmed.
The control that would have caught it· our reading, not a claim from the sources
Restricting which connected apps can be authorised in Salesforce, and requiring admin approval for new OAuth grants, removes the step the caller is actually trying to trigger.
Sources (5)
- Salesforce customers duped by series of social-engineering attacksCyberScoop·cyberscoop.comOpen ↗
- Google confirms Salesforce CRM breach, faces extortion threatSecurity Affairs·securityaffairs.comOpen ↗
- FBI warns of Salesforce attacks by UNC6040 and UNC6395 groupsSecurity Affairs·securityaffairs.comOpen ↗
- Google Among Victims in Ongoing Salesforce Data Theft CampaignInfosecurity Magazine·infosecurity-magazine.comOpen ↗
- ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud ApplicationsEclecticIQ·blog.eclecticiq.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.