Google confirms data breach after Salesforce database hack exposes customer data

Google confirms data breach after Salesforce database hack exposes customer data

Google has confirmed that a recent breach involved one of its Salesforce systems, which holds contact data for small and medium-sized businesses. The attack was executed by a cybercriminal group identified as UNC6040, which employs voice phishing, or 'vishing', to manipulate employees into granting access to sensitive resources. Using social engineering tactics, the attackers impersonated IT support staff during phone calls, persuading employees to authorize the installation of malicious software tied to their Salesforce environment. This breach enabled the hackers to gain access to and extract basic business contact information, most of which Google claims was already available publicly, before the situation was identified and contained. UNC6040 is particularly notorious for targeting Salesforce platforms, leveraging legitimate applications like the 'Data Loader' for bulk data management. However, their strategy involves creating counterfeit versions of these tools with deceptive names, such as 'My Ticket Portal,' to evade detection during their phishing attempts. Recently, the group has transitioned from using official tools to employing custom Python scripts for data theft, complicating efforts to trace their actions. Additionally, they reportedly utilize VPNs and the TOR network to obscure their identities and locations. Another associated group, UNC6240, has been linked to extortion efforts following these data thefts, reaching out to company personnel via email or phone with demands for bitcoin payments within 72 hours. These communications often claim to be from the hacking group 'ShinyHunters,' which is well-known in the cybercrime sector. Google's threat intelligence unit has expressed concern that the extortion group is likely to launch a website to publicly disclose the stolen data, a tactic commonly used by cybercriminals to exert pressure. The fundamental issue highlighted by this incident is that these attacks do not exploit vulnerabilities in Salesforce itself but rather capitalize on human error, tricking employees into granting access through seemingly normal IT support interactions. In light of these events, companies are being advised to enhance their access controls, restrict permissions to sensitive tools, limit application installations, and provide training for staff to better recognize social engineering scams.

Sources : Mint

Published On : Aug 07, 2025, 13:50

Gadgets
Kobo Joins Forces with StoryGraph to Challenge Amazon's Reading Dominance

In a significant move against Amazon’s established Kindle and Goodreads ecosystem, reading tracker StoryGraph has partne...

TechCrunch | Jun 29, 2026, 19:40
Kobo Joins Forces with StoryGraph to Challenge Amazon's Reading Dominance
Science
Could Early Detection Have Mitigated Ozone Layer Damage?

The global ban on substances that deplete the ozone layer is widely viewed as a successful environmental initiative that...

Ars Technica | Jun 29, 2026, 19:05
Could Early Detection Have Mitigated Ozone Layer Damage?
AI
California Partners with Anthropic for Discounted AI Services Amid Federal Tensions

In a significant move, Governor Gavin Newsom of California has entered into an agreement with Anthropic, allowing state ...

TechCrunch | Jun 29, 2026, 18:20
California Partners with Anthropic for Discounted AI Services Amid Federal Tensions
Cybersecurity
FBI Offers $10 Million Reward for Leads on Russian Hackers Targeting Signal and WhatsApp

In a significant move to combat cyber threats, federal authorities have announced a reward of up to $10 million for info...

Ars Technica | Jun 29, 2026, 22:10
FBI Offers $10 Million Reward for Leads on Russian Hackers Targeting Signal and WhatsApp
Cybersecurity
Supreme Court Limits Government Access to Personal Location Data

In a significant ruling on Monday, the Supreme Court affirmed that the Fourth Amendment guards an individual's "location...

Ars Technica | Jun 29, 2026, 20:05
Supreme Court Limits Government Access to Personal Location Data
View All News