Hackers are using a modified Salesforce app to trick employees and extort companies, Google says

Hackers are using a modified Salesforce app to trick employees and extort companies, Google says

Cybercriminals are deceiving employees at various companies across Europe and the Americas into downloading a tampered version of a Salesforce-related application, which allows them to harvest extensive data, infiltrate corporate cloud services, and extort these organizations, according to a report from Google released on Wednesday. The group of hackers, identified by the Google Threat Intelligence Group as UNC6040, has demonstrated a remarkable ability to persuade employees to install a modified version of Salesforce’s Data Loader—a proprietary tool designed for bulk data imports into Salesforce systems. Using deceptive phone calls, these hackers direct employees to a fraudulent Salesforce app setup page where they unwittingly approve the installation of the altered application, which mimics the legitimate Data Loader. Once installed, the hackers gain substantial access to query and extract sensitive data directly from compromised Salesforce environments. Furthermore, this access often allows them to navigate through the corporate networks of their victims, facilitating attacks on other cloud services and internal systems. The technical aspects of this operation suggest connections to a broader, loosely organized cybercriminal group known as “The Com,” which is associated with various small factions involved in cybercrime and, at times, violent activities. A spokesperson from Google informed Reuters that approximately 20 organizations have fallen victim to the UNC6040 campaign in recent months, with a number of these companies experiencing data breaches. In response, a Salesforce representative stated that there are no indications of any vulnerabilities within their platform being exploited. They characterized the phone calls used in these scams as targeted social engineering efforts aimed at exploiting individual users' cybersecurity awareness. While Salesforce acknowledged the occurrence of these attacks, they noted that only a limited number of customers have been affected, emphasizing that it is not a widespread issue. The company also issued a warning in a March 2025 blog post regarding voice phishing, or “vishing,” attacks, and the use of maliciously modified versions of Data Loader.

Sources : CNN

Published On : Jun 06, 2025, 06:20

Startups
Deadline Extended: Innovators Can Still Compete for the 2026 Joseph C. Belden Innovation Award

The quest for groundbreaking innovation continues, as the nomination period for the 2026 Joseph C. Belden Innovation Awa...

TechCrunch | Feb 19, 2026, 22:00
Deadline Extended: Innovators Can Still Compete for the 2026 Joseph C. Belden Innovation Award
Computing
Google Chrome Unleashes New Features to Enhance User Productivity Amid Browser Competition

In the ever-evolving landscape of web browsers, Google Chrome is stepping up its game with an array of fresh features ai...

TechCrunch | Feb 19, 2026, 18:55
Google Chrome Unleashes New Features to Enhance User Productivity Amid Browser Competition
Robotics
Toyota Embraces Humanoid Robots to Enhance Production at Canadian Plant

In a groundbreaking move, Toyota's Canadian manufacturing arm has integrated seven humanoid robots into its assembly lin...

TechCrunch | Feb 19, 2026, 20:50
Toyota Embraces Humanoid Robots to Enhance Production at Canadian Plant
AI
Lawsuit Claims ChatGPT Led Student to Psychosis, Sparking Concerns Over AI's Impact

A college student from Georgia, Darian DeCruise, has initiated legal action against OpenAI, asserting that a prior versi...

Ars Technica | Feb 19, 2026, 22:45
Lawsuit Claims ChatGPT Led Student to Psychosis, Sparking Concerns Over AI's Impact
Streaming
YouTube Unveils Conversational AI Feature for Smart TVs, Enhancing Viewer Interaction

YouTube is stepping up the competition in conversational AI, now extending its innovative tool to smart TVs, gaming cons...

TechCrunch | Feb 19, 2026, 20:50
YouTube Unveils Conversational AI Feature for Smart TVs, Enhancing Viewer Interaction
View All News