Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A phone call posing as IT support, followed by a user-approved connected app, was enough to give attackers a route into Salesforce customer data. In the campaign Google tracks as UNC6040, the attackers did not rely on a demonstrated flaw in Salesforce’s core platform: they persuaded employees to authorize malicious or modified applications and then used legitimate Salesforce access paths to query and export data.
That distinction matters. The incident is best understood as social engineering combined with OAuth and excessive or poorly governed access—not as proof that Salesforce itself was hacked. Here is how the campaign worked, what organizations should investigate, and which controls address the actual attack path.
What happened in the Salesforce vishing campaign?
Google Threat Intelligence Group (GTIG) reported on June 4, 2025, that a financially motivated threat cluster it tracks as UNC6040 was targeting Salesforce environments through voice phishing, or vishing. The attackers posed as internal IT-support staff and guided employees through steps that led them to authorize an attacker-controlled Salesforce connected application. Some of the applications were made to resemble Salesforce Data Loader.
Once authorized, an application could use the access granted to it to query and export data from the customer’s Salesforce environment. Google later reported additional variations, including custom applications and Python scripts. The methods and permissions differed across intrusions, so no single OAuth scope or permission combination should be assumed to apply to every victim.
#1 Best Overall
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Google’s campaign report describes the activity and its evolution; Dark Reading’s June 4, 2025 report covered the initial disclosure.
The attack chain: a call becomes an API route to CRM data
- Impersonation: An employee received a phone call or voice message from someone claiming to be IT support.
- Pretext: The caller used a support-related reason to build credibility and keep the victim following instructions.
- Authorization: The employee was directed to Salesforce connected-app settings and persuaded to approve an unfamiliar application.
- Access: The application received the access the user’s authorization and tenant configuration allowed. Depending on the setup, that could enable API access to Salesforce records.
- Collection: Attackers queried and exported data through Salesforce-supported mechanisms, including API and bulk-data workflows.
- Follow-on activity: In some cases, activity extended to other cloud services, including Okta or Microsoft 365. Extortion could follow later, sometimes months after the initial theft.
In short: phone call → support pretext → connected-app approval → OAuth/API access → data collection → possible cloud-account pivot and delayed extortion. Not every incident necessarily included every step.
Was Salesforce itself breached?
The reported intrusions compromised individual customer environments and data through social engineering and user-authorized application access. The cited reporting does not establish that UNC6040 exploited a vulnerability in Salesforce’s core infrastructure. Salesforce characterized the activity as targeted social engineering rather than evidence of an inherent flaw in its service.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11“Salesforce breach” can therefore mean several different things, and the distinction is important:
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
- Platform compromise: An attacker exploits Salesforce’s underlying service or infrastructure. The cited UNC6040 reporting did not show this.
- Tenant compromise: An attacker gains access to a particular organization’s Salesforce environment.
- Identity or app compromise: An attacker abuses a user’s identity or an application the user authorized.
- Data theft: The attacker uses that access to read or export records belonging to the customer.
For defenders, the response is not simply “wait for Salesforce to patch a vulnerability.” The priority is to investigate identities, connected apps, permissions, exports, and any related access to other services.
Why Data Loader mattered—and what it is not
Salesforce Data Loader is a legitimate tool for bulk importing, exporting, updating, and deleting records. Its ability to perform large-scale data operations makes it useful for authorized administrators and business processes—and attractive to an attacker who has acquired suitable access.
Data Loader itself is not the malware in this story. The concern was attacker-controlled or modified applications that imitated the tool or otherwise gained OAuth access. A familiar product name or Salesforce-like branding is not proof that an application is legitimate. Verify its owner, approved purpose, requested scopes, authorized users, and policy before granting access.
Connected apps use OAuth to let an application act on a user’s behalf within the access granted. Broad API access, refresh tokens, or offline access can increase the consequences of a bad authorization, but the exact scopes and resulting capabilities vary by application and tenant configuration. Google’s UNC6040 hardening recommendations call out permissions such as API Enabled, Manage Connected Apps, and Customize Application as areas to govern carefully. Those permissions are not interchangeable, and organizations should review their actual Salesforce configuration rather than assume every incident used all of them.
Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
What data could be exposed?
The data accessible to an attacker depends on the user’s permissions, the application’s authorized access, and the organization’s Salesforce objects and records. Potentially exposed information could include account, contact, lead, case, or other business records, as well as reports or files available through the compromised access.
Google described large-scale theft in multiple investigations but did not establish one universal record count for the campaign. Do not treat a criminal claim, a count from one victim, or a figure for records accessed as a verified total for all UNC6040 activity. In an August 2025 update, Google said an affected Google Salesforce instance contained contact information and notes for small and medium-sized businesses, and that the data retrieved in that case was basic, largely public business information. That example should not be generalized to other victims.
Why a delayed extortion demand still matters
Google observed data collection beginning soon after access in some intrusions, while extortion attempts could arrive months later. A demand received today may relate to an earlier OAuth grant or export; the date of the threat message is not necessarily the date of the theft.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Unlike endpoint ransomware, SaaS data theft can be quiet. Attackers may use valid application and API pathways rather than encrypting computers or disrupting operations. Normal-looking service access does not prove that activity was authorized, and ordinary interactive-login alerts alone may miss the most useful evidence.
Rank #4
- Passwordless World - A revolutionary new way to protect your account info. By being FIDO2 certified by the world’s largest ecosystem for standard-based, interoperable authentication, FIDO2 makes everyday log-in experience effortless and passwordless yet more secure than generic password style security. **Note: FIDO2 does NOT support Mac log-in.
- Online Account Protection - FIDO2 key is backward compatible with U2F protocol and works with the newest Chrome browser with operating systems such as: Windows, macOS, or Linux. U2F can be supported and protected on all websites that follow U2F protocols.
- Multi-factored Authentication - Built-in, advanced HOTP (One Time Password) technology that completes the unique multi-factored authentication process. Eliminate worry and help prevent losing your account info to theft, phishing, hacking, or other online scams. Note: Only Enterprise Users using Azure Active Directory can access Windows Hello log-in via Thetis FIDO2 Security Key.
- Compact And Durable - 360° design with rotating aluminum alloy cover that shields the USB connector when not in use. Tough and durable alloy protects FIDO2 key from daily wear-and-tear, accidental drops, and scratches.
- Portable Design - ultra-portable design allows you to take your FIDO key anywhere you need it.
Google separately tracks some later extortion activity associated with these intrusions as UNC6240. Some actors claimed affiliation with ShinyHunters, but those names should not be collapsed into a definitive identity for UNC6040. Google’s analysis notes that overlapping techniques, shared infrastructure, or claimed relationships do not by themselves prove common operational control. See its technical analysis of vishing threats for that attribution context.
If you suspect an incident: contain access and preserve evidence
Coordinate with your incident-response, Salesforce, identity, legal, and privacy teams. The steps below are a starting point, not a substitute for a forensic investigation or legal advice.
- Revoke suspicious app access. Identify and revoke unauthorized connected-app grants and associated OAuth tokens. Preserve relevant configuration and event evidence first where practical, so containment does not erase information investigators need.
- Contain affected identities. Suspend or restrict accounts where compromise is suspected. Reset credentials and review MFA factors and recent changes. Do not assume that removing an app alone addresses stolen credentials, other tokens, or persistence.
- Inspect connected apps. Look for new, unfamiliar, renamed, or unexpectedly owned applications, including names or branding resembling Data Loader, support portals, ticketing systems, or internal tools. Review scopes, permitted users, policies, and authorization times.
- Scope data access. Determine which objects, reports, files, attachments, and records were queried or exported, and over what period. Distinguish data viewed from data actually exported when available evidence allows.
- Review Salesforce telemetry. Examine Setup Audit Trail, Login History, LoginEvent or LoginEventStream, PermissionSetEvent, API Event Monitoring, Report Event Monitoring, List View Event Monitoring, Bulk API results, file events, and API anomaly events where available to your organization.
- Correlate other systems. Review Okta, Microsoft 365/Entra ID, Google Workspace, VPN, endpoint, email, and help-desk records for the affected users, time windows, and source IPs. Investigate any later access to other SaaS accounts.
- Preserve the human evidence. Retain relevant help-desk tickets, reported call details, email or voice messages, and user timelines alongside technical logs. These can help establish how the authorization occurred.
- Escalate appropriately. Follow your incident plan for legal, privacy, cyber-insurance, regulator, customer, and law-enforcement notifications. Applicable obligations depend on jurisdiction and the data involved.
Useful investigative signals include a newly authorized app, unexpected app ownership or broad scopes, an unusual API or query burst, many small test queries followed by rapid extraction, large report or bulk exports, mass file downloads, privilege changes, or Salesforce access from unfamiliar VPN or Tor infrastructure. A source-IP match followed by access to Okta or Microsoft 365 can also be a useful lead, but IP reputation is not proof on its own. Google’s defensive guidance discusses telemetry and patterns to examine.
Free tools Windows power users keep installed
One-click scans. No signup required.
How to reduce the chance of a repeat
Make help-desk verification resistant to vishing
- Require independent verification for requests involving password resets, MFA changes, app authorization, API access, remote access, or administrative privileges.
- Do not verify a caller using a number or link supplied by that caller. Call back using a known internal directory or established help-desk channel.
- Adopt a clear rule: employees should not approve OAuth requests, change MFA, or install software under a caller’s direction.
- Give help-desk staff and privileged users specific practice against phone-based pretexts. A caller who knows internal terminology is still unverified.
Limit Salesforce permissions and bulk-data access
- Grant API Enabled only to users and service accounts that need it. Review profiles and permission sets regularly.
- Restrict Manage Connected Apps and Customize Application to a small, trusted administrator group.
- Apply least privilege to Data Loader and other bulk-data tools. Use dedicated accounts for necessary integration work rather than broad API access for ordinary users.
- For bulk-access accounts, define the permitted application, source IPs, schedule, and expected export volume. Monitor deviations from that baseline.
Govern connected apps and OAuth access
- Maintain an inventory or allowlist of approved apps, with an owner and documented business purpose for each.
- Require administrative review before users authorize new integrations. Restrict which users can approve apps and inspect scopes before granting access.
- Review connected-app policies, permitted users, IP restrictions, and tokens periodically. Remove grants that are no longer needed.
- Alert on new authorizations, changed app policies, or apps requesting broad API or offline access.
Use authentication and network controls as layers
- Enforce MFA for Salesforce users and administrators. Where your identity architecture supports it, consider phishing-resistant methods such as FIDO2 security keys or passkeys.
- Use trusted IP ranges and profile login ranges where operationally feasible; define approved corporate egress or managed VPN ranges to support remote work.
- Apply connected-app IP and user restrictions where appropriate, and investigate access from Tor, commercial VPNs, unfamiliar locations, or unusual networks.
- Remember that MFA protects a login, but it cannot by itself make a user-approved malicious app safe. Review both the identity event and the authorization being granted.
Monitor activity beyond interactive logins
Prioritize alerts for new connected-app authorizations followed by API activity; unusual Query, QueryMore, or QueryAll volume; bulk API downloads; atypical report exports; large file or attachment downloads; permission changes; new service or integration users; and cross-service activity involving the same identity or source. Login history is useful, but valid OAuth and API use means a login-only strategy can miss the theft.
Salesforce Shield, Event Monitoring, and transaction-security controls may provide useful visibility, but availability and capabilities depend on edition, licensing, configuration, and logging entitlements. Check your organization’s actual coverage and retention. Salesforce’s Security Guide provides platform security and configuration reference material. Google also offers broader SaaS defense guidance.
Practical trade-offs to plan for
- Least privilege versus convenience: Restricting API or bulk-data access may disrupt legitimate integrations. Identify those processes, use narrowly scoped dedicated accounts, and define normal activity before tightening controls.
- IP restrictions versus remote work: Strict ranges can block remote employees or contractors. Use managed VPN or known corporate egress ranges rather than leaving access unrestricted—or setting restrictions without a recovery path.
- App governance versus integration needs: Blocking every connected app can break business workflows. An approval process, allowlist, scoped access, periodic token review, and alerting are more sustainable.
- Threat indicators versus certainty: VPN and Tor use can be suspicious, but attackers can change infrastructure or use other proxies. Treat network reputation as one signal, not a standalone verdict.
- Detection versus retention: Delayed extortion makes historical investigation important. Retain the relevant Salesforce and identity logs long enough to examine old authorizations and exports under your organization’s policy and obligations.
What organizations should do now
- Inventory Salesforce connected apps and remove grants with no verified owner or business need.
- Review who has API access and who can manage connected apps or customize the application.
- Search available logs for new OAuth grants, unusual API/query volume, bulk exports, report activity, and large file downloads.
- Require an out-of-band callback through a known channel for support requests that touch credentials, MFA, connected apps, or privileges.
- Confirm which Event Monitoring and identity logs are enabled, how long they are retained, and who investigates alerts.
- Correlate Salesforce activity with identity-provider and other SaaS logs, then test the response process with a realistic authorization-abuse scenario.
The central lesson is straightforward: a trusted employee can be persuaded to grant a powerful application legitimate access. Defending Salesforce data therefore requires more than MFA or phishing awareness; it takes verified support procedures, tightly governed permissions and apps, and monitoring of the API and export activity that follows authorization.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

