Google confirms data breach after Salesforce database hack exposes customer data

Google confirms data breach after Salesforce database hack exposes customer data

Google has confirmed that a recent breach involved one of its Salesforce systems, which holds contact data for small and medium-sized businesses. The attack was executed by a cybercriminal group identified as UNC6040, which employs voice phishing, or 'vishing', to manipulate employees into granting access to sensitive resources. Using social engineering tactics, the attackers impersonated IT support staff during phone calls, persuading employees to authorize the installation of malicious software tied to their Salesforce environment. This breach enabled the hackers to gain access to and extract basic business contact information, most of which Google claims was already available publicly, before the situation was identified and contained. UNC6040 is particularly notorious for targeting Salesforce platforms, leveraging legitimate applications like the 'Data Loader' for bulk data management. However, their strategy involves creating counterfeit versions of these tools with deceptive names, such as 'My Ticket Portal,' to evade detection during their phishing attempts. Recently, the group has transitioned from using official tools to employing custom Python scripts for data theft, complicating efforts to trace their actions. Additionally, they reportedly utilize VPNs and the TOR network to obscure their identities and locations. Another associated group, UNC6240, has been linked to extortion efforts following these data thefts, reaching out to company personnel via email or phone with demands for bitcoin payments within 72 hours. These communications often claim to be from the hacking group 'ShinyHunters,' which is well-known in the cybercrime sector. Google's threat intelligence unit has expressed concern that the extortion group is likely to launch a website to publicly disclose the stolen data, a tactic commonly used by cybercriminals to exert pressure. The fundamental issue highlighted by this incident is that these attacks do not exploit vulnerabilities in Salesforce itself but rather capitalize on human error, tricking employees into granting access through seemingly normal IT support interactions. In light of these events, companies are being advised to enhance their access controls, restrict permissions to sensitive tools, limit application installations, and provide training for staff to better recognize social engineering scams.

Sources : Mint

Published On : Aug 07, 2025, 13:50

Cybersecurity
Facebook Rolls Out Payments in $725 Million Privacy Settlement Amid Cambridge Analytica Fallout

In a significant move, Facebook has begun distributing payments as part of its $725 million privacy settlement, a resolu...

Mint | Sep 13, 2025, 01:45
Facebook Rolls Out Payments in $725 Million Privacy Settlement Amid Cambridge Analytica Fallout
Automotive
Chinese EV Manufacturers Challenge European Giants at Major Auto Show

This week, Germany hosted one of the largest automotive exhibitions in the world, where the spotlight was firmly on dyna...

CNBC | Sep 13, 2025, 05:55
Chinese EV Manufacturers Challenge European Giants at Major Auto Show
Gaming
Hike's Closure Marks a Turning Point in India's Gaming Landscape

Hike, once celebrated as one of India's prominent unicorn startups, has succumbed to the recent crackdown on real-money ...

TechCrunch | Sep 13, 2025, 14:35
Hike's Closure Marks a Turning Point in India's Gaming Landscape
Computing
Big Tech's Data Centers Face Power Shutdowns Amid Energy Crises

In response to the surging energy demands of Big Tech's data centers, U.S. policymakers are exploring a controversial st...

Mint | Sep 13, 2025, 04:35
Big Tech's Data Centers Face Power Shutdowns Amid Energy Crises
Science
Urgent Call to Action: America's Space Missions at Risk as Funding Looms

As the deadline approaches for federal funding, 19 vital space missions focused on climate change, solar system explorat...

Ars Technica | Sep 12, 2025, 23:50
Urgent Call to Action: America's Space Missions at Risk as Funding Looms
View All News
Google confirms data breach after Salesforce database hack exposes customer data