FBI warns of SForce platform attacks by UNC6040 and UNC6395

View profile for Michael Z.

CEO, CMO & Founder @ Crush10Media, Inc. | Cybersecurity Product Marketing

The FBI has released a FLASH alert on the targeting of SForce platforms by two cyber criminal groups. UNC6040 • Primary Tactics: UNC6040 specializes in voice phishing (vishing) campaigns to target SForce - they impersonate support. UNC6395 • Primary Tactics: UNC6395 also targets SForce. Instead of social engineering, they exploit compromised OAuth tokens. An OAuth token is a credential that allows an application to access resources on behalf of a user without sharing their password.

View organization page for FBI Cyber Division

209,091 followers

The FBI has released a FLASH alert on the targeting of Salesforce platforms by the cybercriminal groups UNC6040 and UNC6395, which are responsible for a surge in data theft and extortion attempts. Click for indicators of compromise (IOCs) and protect your organization: https://lnkd.in/dtbqTUTw

  • FBI FLASH alert dated September 12, 2025, warning about cybercriminal groups UNC6040 and UNC6395 targeting Salesforce for data theft and extortion.

To view or add a comment, sign in

Explore content categories