Salesforce – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 14 Sep 2025 22:57:24 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Salesforce – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/ https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/#respond Sun, 14 Sep 2025 22:57:24 +0000 https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/

FBI cyber

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations’ Salesforce environments to steal data and extort victims.

“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions,” reads the FBI’s FLASH advisory.

“Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms. The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.”

UNC6040 was first disclosed by Google Threat Intelligence (Mandiant) in June, who warned that since late 2024, threat actors were using social engineering and vishing attacks to trick employees into connecting malicious Salesforce Data Loader OAuth apps to their company’s Salesforce accounts.

In some cases, the threat actors impersonated corporate IT support personnel, who used renamed versions of the application called “My Ticket Portal.”

Once connected, the threat actors used the OAuth application to mass-exfiltrate corporate Salesforce data, which was then used in extortion attempts by the ShinyHunters extortion group.

In these early data theft attacks, ShinyHunters told BleepingComputer that they primarily targeted the “Accounts” and “Contacts” database tables, which are both used to store data about a company’s customers.

These data theft attacks were widespread, impacting large and well-known companies, such as Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, and Tiffany & Co.

Later data theft attacks in August also targeted Salesforce customers, but this time utilized stolen Salesloft Drift OAuth and refresh tokens to breach customers’ Salesforce instances.

This activity is tracked as UNC6395 and is believed to have occurred between August 8th and 18th, with the threat actors using the tokens to target the company’s support case information that was stored in Salesforce.

The exfiltrated data was then analyzed to extract secrets, credentials, and authentication tokens shared in support cases, including AWS keys, passwords, and Snowflake tokens. These credentials could then be used to pivot to other cloud environments for additional data theft.

Salesloft worked with Salesforce to revoke all Drift tokens and required customers to reauthenticate to the platform.

It was later revealed that the threat actors also stole Drift Email tokens, which were used to access emails for a small number of Google Workspace accounts.

An investigation by Mandiant determined the attack originated in March, when Salesloft’s GitHub repositories were compromised, allowing attackers to ultimately steal the Drift OAuth tokens.

Like the previous attacks, these new Salesloft Drift data theft attacks impacted numerous companies,  including Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, Palo Alto Networks, and many more.

While the FBI did not name the groups behind these campaigns, BleepingComputer was told by the ShinyHunters extortion group that they and other threat actors calling themselves “Scattered Lapsus$ Hunters, were behind both clusters of activity.

This group of hackers claims to have originated from and overlap with the Lapsus$, Scattered Spider, and ShinyHunters extortion groups.

On Thursday, the threat actors announced via a domain associated with BreachForums that they planned to “go dark” and stop discussing operations on Telegram.

However, in a parting post, the hackers claimed to have gained access to the FBI’s E-Check background check system and Google’s Law Enforcement Request system, publishing screenshots as proof.

If legitimate, this access would allow them to impersonate law enforcement and pull sensitive records of individuals.

When contacted by BleepingComputer, the FBI declined to comment, and Google did not respond to our email.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/feed/ 0 58467
Farmers Insurance data breach impacts 1.1M people after Salesforce attack https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/ https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/#respond Mon, 25 Aug 2025 19:29:05 +0000 https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/

Farmers Insurance sign

U.S. insurance giant Farmers Insurance has disclosed a data breach impacting 1.1 million customers, with BleepingComputer learning that the data was stolen in the widespread Salesforce attacks.

Farmers Insurance is a U.S.-based insurer that provides auto, home, life, and business insurance products. It operates through a network of agents and subsidiaries, serving more than 10 million households nationwide.

The company disclosed the data breach in an advisory on its website, saying that its database at a third-party vendor was breached on May 29, 2025.

“On May 30, 2025, one of Farmers’ third-party vendors alerted Farmers to suspicious activity involving an unauthorized actor accessing one of the vendor’s databases containing Farmers customer information (the “Incident”),” reads the data breach notification on its website.

“The third-party vendor had monitoring tools in place, which allowed the vendor to quickly detect the activity and take appropriate containment measures, including blocking the unauthorized actor. After learning of the activity, Farmers immediately launched a comprehensive investigation to determine the nature and scope of the Incident and notified appropriate law enforcement authorities.”

The company says that its investigation determined that customers’ names, addresses, dates of birth, driver’s license numbers, and/or last four digits of Social Security numbers were stolen during the breach.

Farmers began sending data breach notifications to impacted individuals on August 22, with a sample notification [1, 2] shared with the Maine Attorney General’s Office, stating that a combined total of 1,111,386 customers were impacted.

While Farmers did not disclose the name of the third-party vendor, BleepingComputer has learned that the data was stolen in the widespread Salesforce data theft attacks that have impacted numerous organizations this year.

BleepingComputer contacted Farmers with additional questions about the breach and will update the story if we receive a response.

The Salesforce data theft attacks

Since the beginning of the year, threat actors classified as ‘UNC6040’ or ‘UNC6240’ have been conducting social engineering attacks on Salesforce customers.

During these attacks, threat actors conduct voice phishing (vishing) to trick employees into linking a malicious OAuth app with their company’s Salesforce instances.

Once linked, the threat actors used the connection to download and steal the databases, which were then used to extort the company through email.

The extortion demands come from the ShinyHunters cybercrime group, who told BleepingComputer that the attacks involve multiple overlapping threat groups, with each group handling specific tasks to breach Salesforce instances and steal data.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

Other companies impacted in these attacks include Google, Cisco, Workday, Adidas, Qantas, Allianz Life, and the LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

 

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/feed/ 0 55095
ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/ https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/#respond Thu, 31 Jul 2025 08:07:00 +0000 https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/

Smiley face hacker

A wave of data breaches impacting companies like Qantas, Allianz Life, LVMH, and Adidas has been linked to the ShinyHunters extortion group, which has been using voice phishing attacks to steal data from Salesforce CRM instances.

In June, Google’s Threat Intelligence Group (GTIG) warned that threat actors tracked as UNC6040 were targeting Salesforce customers in social engineering attacks.

In these attacks, the threat actors impersonated IT support staff in phone calls to targeted employees, attempting to persuade them into visiting Salesforce’s connected app setup page. On this page, they were told to enter a “connection code”, which linked a malicious version of Salesforce’s Data Loader OAuth app to the target’s Salesforce environment.

In some cases, the Data Loader component was renamed to “My Ticket Portal,” to make it more convincing in the attacks.

Prompt to enter connection code
Prompt to enter connection code
Source: Google

GTIG says that these attacks were usually conducted through vishing (voice phishing), but credentials and MFA tokens were also stolen through phishing pages that impersonated Okta login pages.

Around the time of this report, multiple companies reported data breaches involving third-party customer service or cloud-based CRM systems.

LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co. each disclosed unauthorized access to a customer information database, with Tiffany Korea notifying customers the attackers breached a “vendor platform used for managing customer data.”

Adidas, Qantas, and Allianz Life also reported breaches involving third-party systems, with Allianz confirming it was a third-party customer relationship management platform.

“On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life),” an Allianz Life spokesperson told BleepingComputer.

While BleepingComputer has learned that the Qantas data breach also involved a third-party customer relationship management platform, the company will not confirm it is Salesforce. However, previous reporting from local media claims the data was stolen from Qantas’ Salesforce instance.

Furthermore, court documents state that the threat actors targeted “Accounts” and “Contacts” database tables, both of which are Salesforce objects.

While none of these companies have publicly named Salesforce, BleepingComputer has since confirmed that all were targeted in the same campaign detailed by Google.

The attacks have not led to public extortion or data leaks yet, with BleepingComputer learning that the threat actors are attempting to privately extort companies over email, where they name themselves as ShinyHunters.

It is believed that when these extortion attempts fail, the threat actors will release stolen information in a long wave of leaks, similar to ShinyHunter’s previous Snowflake attacks.

Who is ShinyHunters

The breaches have caused confusion among the cybersecurity community and the media, including BleepingComputer, with the attacks attributed to Scattered Spider (tracked by Mandiant as UNC3944), as those threat actors were also targeting the aviation, retail, and insurance sectors around the same time and demonstrated similar tactics.

However, threat actors associated with Scattered Spider tend to perform full-blown network breaches, culminating with data theft and, sometimes, ransomware. ShinyHunters, tracked as UNC6040, on the other hand, tends to focus more on data-theft extortion attacks targeting a particular cloud platform or web application.

It is BleepingComputer’s and some security researchers’ belief that both UNC6040 and UNC3944 consist of overlapping members that communicate within the same online communities. The threat group is also believed to overlap with “The Com,” a network of experienced English-speaking cybercriminals.

“According to Recorded Future intelligence, the overlapping TTPs between known Scattered Spider and ShinyHunters attacks indicate likely some crossover between the two groups,” Allan Liska, an Intelligence Analyst for Recorded Future, told BleepingComputer.

Other researchers have told BleepingComputer that ShinyHunters and Scattered Spider appear to be operating in lockstep, targeting the same industries at the same time, making it harder to attribute attacks.

Some also believe that both groups have ties to threat actors from the now-defunct Lapsus$ hacking group, with reports indicating that one of the recently arrested Scattered Spider hackers was also in Lapsus$.

Another theory is that ShinyHunters is acting as an extortion-as-a-service, where they extort companies on behalf of other threat actors in exchange for a revenue share, similar to how ransomware-as-a-service gangs operate.

This theory is supported by previous conversations BleepingComputer has had with ShinyHunters, where they claimed not to be behind a breach, but just acting as the seller of the stolen data.

These breaches include PowerSchool, Oracle Cloud, the Snowflake data-theft attacks, AT&T, NitroPDF, Wattpad, MathWay, and many more.

ShinyHunters leaking attempting to sell AT&T data breach
ShinyHunters leaking attempting to sell AT&T data breach
Source: BleepingComputer

To muddy the waters further, there have been numerous arrests of people linked to the name “ShinyHunters,” including those who have been arrested for the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.

Yet even after these arrests, new attacks occur with companies receiving extortion emails stating, “We are ShinyHunters,” referring to themselves as a “collective.”

Protecting Salesforce instances from attacks

In a statement to BleepingComputer, Salesforce emphasized that the platform itself was not compromised, but rather, customers’ accounts are being breached via social engineering.

“Salesforce has not been compromised, and the issues described are not due to any known vulnerability in our platform. While Salesforce builds enterprise-grade security into everything we do, customers also play a critical role in keeping their data safe — especially amid a rise in sophisticated phishing and social engineering attacks,” Salesforce told BleepingComputer.

“We continue to encourage all customers to follow security best practices, including enabling multi-factor authentication (MFA), enforcing the principle of least privilege, and carefully managing connected applications. For more information, please visit: https://www.salesforce.com/blog/protect-against-social-engineering/.”

Salesforce is urging customers to strengthen their security posture by:

  • Enforcing trusted IP ranges for logins
  • Following the principle of least privilege for app permissions
  • Enabling multi-factor authentication (MFA)
  • Restricting use of connected apps and managing access policies
  • Using Salesforce Shield for advanced threat detection, event monitoring, and transaction policies
  • Adding a designated Security Contact for incident communication

Further details on these mitigations can be found in Salesforce’s guidance linked above.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/feed/ 0 50648