The FBI warned that cybercriminal groups UNC6040 and UNC6395 compromised Salesforce environments to steal data and extort victims. UNC6040, active since at least October 2024, used vishing calls impersonating IT support to obtain credentials or MFA codes and persuade employees to authorize malicious Salesforce connected apps, often modified Data Loader tools, enabling bulk API exfiltration. Some affected organizations later received cryptocurrency extortion demands attributed to ShinyHunters. Separately, UNC6395 abused compromised OAuth tokens for the Salesloft Drift integration in a widespread August 2025 campaign; Salesloft and Salesforce revoked active Drift access and refresh tokens on August 20, 2025.
The activity aligns with the financially motivated The Com ecosystem, a decentralized English-speaking criminal network associated with overlapping brands and participants including Scattered Spider, LAPSUS$, and ShinyHunters. Its operators commonly rely on help-desk impersonation, MFA fatigue, SIM swapping, adversary-in-the-middle phishing, identity-platform abuse, and SaaS/OAuth integrations rather than software exploits alone. Organizations should audit and remove unnecessary connected apps, rotate third-party integration credentials and tokens, restrict API and IP access, monitor Salesforce logs for abnormal bulk exports, enforce phishing-resistant MFA, and strengthen service-desk identity-verification and privileged-access processes.

Get the infrastructure and lures behind it.
17 events from the most recent confirmed update back to the earliest known activity.
A U.S. federal complaint linked the Flowers/Jubair cluster to approximately 120 intrusions, including at least 47 U.S. victims and more than $115 million in paid ransoms.
Owen Flowers and Thalha Jubair were each sentenced to 5.5 years in the UK for the 2024 Transport for London hack, which reportedly caused £29 million in losses and recovery costs.
Scattered LAPSUS$ Hunters was reported to have compromised SoundCloud, Betterment, and Crunchbase.
U.S. and French law enforcement seized BreachForums following public extortion campaigns targeting Salesforce.
The FBI, coordinated with DHS/CISA, issued FLASH-20250912-001 warning that UNC6040 and UNC6395 were compromising Salesforce environments for data theft and extortion. The advisory provided indicators of compromise and mitigation recommendations.
Salesloft, working with Salesforce, revoked all active Drift access and refresh tokens to terminate threat-actor access following the OAuth-token compromise.
UNC6395 conducted a widespread Salesforce data-theft campaign by abusing compromised OAuth tokens associated with the Salesloft Drift AI chatbot integration.
The Scattered LAPSUS$ Hunters Telegram channel emerged, combining Scattered Spider, LAPSUS$, and ShinyHunters branding to coordinate threats and publicize anticipated data leaks.
Noah Urban was sentenced in the United States to 10 years in prison and ordered to pay $13 million in restitution. The source describes him as the first convicted Scattered Spider member.
UK authorities arrested four suspects over the April retail attacks, while another UK national was separately arrested in Spain.
Scattered Spider was linked to attacks on Marks & Spencer, Co-op, and Harrods in the UK, in which DragonForce ransomware was deployed.
The U.S. Department of Justice indicted five alleged Scattered Spider members for campaigns spanning September 2021 through April 2023.
UNC6040 was observed operating from at least October 2024, using vishing and other social-engineering methods to obtain Salesforce access and exfiltrate data through APIs or malicious connected applications.
Alleged Scattered Spider member Tyler Buchanan was detained in Spain; the source states he was later extradited to the United States.
Scattered Spider was linked to breaches affecting MGM Resorts and Caesars Entertainment.
LAPSUS$ conducted prominent intrusions against Okta, Nvidia, and Microsoft, using a model centered on data theft and threatened disclosure.
ShinyHunters began operating approximately in 2019, initially focusing on exfiltrating and selling database records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
blog.pulsedive.com
Open sourceflashpoint.io
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.