The FBI has issued an alert about two threat groups, UNC6040 (ShinyHunters) and UNC6395, actively compromising Salesforce customers through vishing and OAuth token theft. Attackers use social engineering to gain access to Salesforce environments and exfiltrate sensitive data, sometimes leading to extortion attempts. The FBI recommends enhanced employee training, phishing-resistant MFA, and strict monitoring of third-party integrations to mitigate these threats.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Grubhub disclosed that it suffered a breach connected to the wave of attacks targeting Salesforce environments and associated extortion activity. The confirmation publicly tied Grubhub to the broader incident cluster and established it as an affected victim.
Initial story creation
The FBI issued a warning about data theft targeting Salesforce instances and linked the activity to ShinyHunters. The alert marked an early official acknowledgment of the campaign and its suspected attribution.
Workday said it was affected by two related 2025 incidents involving its Salesforce CRM environment, including a social-engineering campaign tied to ShinyHunters/UNC6040 and a separate Salesloft Drift integration compromise. The company said exposed data included business contact information and, in the Drift incident, a limited subset of support case details and related metadata, while its core HR, payroll, and financial systems were not compromised.
7 references tracked. Mallory keeps watching after this page renders.
security.org
Open sourceinfosecurity-magazine.com
Open sourcecybernews.com
Open sourcesalesforceben.com
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.