Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedConfirmed

UNC6040 vishes Salesforce customers into installing a rebranded Data Loader app

Approximately 20 Salesforce customer organisations, later including Google · Other · Multiple · June 4, 2025

What happened

Google Threat Intelligence disclosed in June 2025 a campaign by UNC6040 in which callers impersonating IT support telephoned employees and talked them into authorising a modified version of Salesforce's Data Loader tool, often rebranded as 'My Ticket Portal', against their company's Salesforce tenant. Around 20 organisations across hospitality, retail and education in the Americas and Europe were affected; Google later confirmed one of its own corporate Salesforce instances was among them.

How the deception worked

The caller posed as internal IT support and walked the employee to Salesforce's connected app setup page, instructing them to enter an eight-digit connection code. That code authorised an attacker-controlled OAuth application, a modified build of Salesforce's legitimate Data Loader utility renamed to look like an internal ticketing tool. Because the victim performed the authorisation themselves within a genuine Salesforce workflow, no credential theft or exploit was needed and the resulting access carried the user's own permissions. The attackers then bulk-exported CRM records via the API, and used harvested credentials to move laterally into Okta, Workplace and Microsoft 365. Extortion demands, branded as ShinyHunters, followed months later.

AI involvement · No AI reported

Google Threat Intelligence described live English-speaking callers; no synthetic voice was reported.

The control that would have caught it· our reading, not a claim from the sources

Restrict connected-app authorisation to administrators through Salesforce's API access control, allow-list approved OAuth applications, and train staff that IT will never guide them through granting an app access by phone.

Sources (1)

  1. Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App
    The Hacker News·thehackernews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.