UNC6040 / ShinyHunters Salesforce vishing campaign
Campaign
Summary
Hide ▲
Show ▼
UNC6040 / ShinyHunters is tied to a vishing-driven Salesforce campaign that has affected multiple organizations, including Workiva. Workiva said attackers accessed a third-party CRM system and stole a limited set of business contact data, including names, email addresses, phone numbers, and support ticket content, while its own platform was not compromised. Google/Mandiant separately said the group tricks employees into using a modified unauthorized Salesforce Data Loader app or otherwise granting access, which can lead to credential theft, Salesforce data exfiltration, and possible spillover into Okta and Microsoft 365.
Related Happenings
Charter Communications hit by network compromise linked to ShinyHunters
Incident
H score70
First: 26.05.2026 22:46
Last: 26.05.2026 22:46
Sources 1
About this happening:
Charter Communications confirmed a data breach tied to ShinyHunters extortion, with the company saying it is alerting authorities and that no sensitive personal...
Charter Communications hit by network compromise linked to ShinyHunters
IncidentAbout this happening: Charter Communications confirmed a data breach tied to ShinyHunters extortion, with the company saying it is alerting authorities and that no sensitive personal...
Latest development: 29.05.2026 11:29
Have I Been Pwned analyzed leaked Charter Communications data and confirmed that the incident affected 4.9 million accounts, with exposed records including names, email addresses, job titles, phone numbers, and physical addresses. The published data also included a subset of about 85,000 records from an internal employee directory.
Instructure user personal information breach
Data Leak
H score81
First: 04.05.2026 01:16
Last: 04.05.2026 01:16
Sources 1
About this happening:
Instructure confirmed a data breach that exposed users' personal information, putting students, teachers, and staff at risk across affected institutions. The exposed mater...
Instructure user personal information breach
Data LeakAbout this happening: Instructure confirmed a data breach that exposed users' personal information, putting students, teachers, and staff at risk across affected institutions. The exposed mater...
UNC6692 email bombing and Microsoft Teams impersonation campaign
Campaign
H score32
First: 25.04.2026 18:07
Last: 25.04.2026 18:07
Sources 1
About this happening:
UNC6692 is running a social-engineering campaign that uses email bombing and Microsoft Teams impersonation to push targets toward remote access and initial compromise....
UNC6692 email bombing and Microsoft Teams impersonation campaign
CampaignAbout this happening: UNC6692 is running a social-engineering campaign that uses email bombing and Microsoft Teams impersonation to push targets toward remote access and initial compromise....
BlackFile vishing extortion campaign targeting retail and hospitality organizations
Campaign
H score37
First: 24.04.2026 21:26
Last: 24.04.2026 21:26
Sources 1
About this happening:
The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
BlackFile vishing extortion campaign targeting retail and hospitality organizations
CampaignAbout this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
UNC6783 BPO compromise campaign targeting downstream companies
Campaign
H score65
First: 09.04.2026 00:46
Last: 09.04.2026 00:46
Sources 1
About this happening:
UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
UNC6783 BPO compromise campaign targeting downstream companies
CampaignAbout this happening: UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
Timeline
-
02.10.2025 00:17 3 articles · 9mo ago
UNC6040 Salesforce vishing campaign and hardening guidance
Technical Analysis UpdateGoogle and Mandiant describe UNC6040 as a vishing-driven campaign that has repeatedly compromised Salesforce instances, including Google's, by tricking employees into using a modified, unauthorized Salesforce Data Loader app or otherwise granting access, enabling credential theft, Salesforce data exfiltration, and possible lateral movement into Okta and Microsoft 365; Mandiant also recommends live video identity proofing, out-of-band verification for high-risk requests such as MFA resets, strict handling of third-party access requests, and a clear process for reporting suspicious communications.
Show sources
- Google Sheds Light on ShinyHunters' Salesforce Tactics — www.darkreading.com — 02.10.2025 00:17
- Google Sheds Light on ShinyHunters' Salesforce Tactics — www.darkreading.com — 02.10.2025 00:17
- SaaS giant Workiva discloses data breach after Salesforce attack — www.bleepingcomputer.com — 03.09.2025 19:40