Cyber Scammers Unleash Salesforce Data Loader Heist: 20 Organizations Duped!

Scattered-Spider-like scammers, tracked as UNC6040, duped employees at 20 organizations into installing a modified version of Salesforce’s Data Loader, stealing sensitive data in the process. These cyber tricksters impersonated IT support, targeting various sectors for large-scale data theft and extortion. Who knew cybercrime could be this organized?

Pro Dashboard

Hot Take:

When it comes to cybercrime, UNC6040 has taken “fake it ’til you make it” to new heights. It turns out, the best tech support is the one that never calls you asking for your passwords!

Key Points:

  • UNC6040, a group of cybercriminals, targets organizations using voice-phishing tactics.
  • Their tactics involve impersonating IT support to install a modified Salesforce Data Loader.
  • This scam affects approximately 20 organizations across various sectors in the Americas and Europe.
  • They leverage an Okta phishing panel to gain credentials and multifactor authentication codes.
  • Salesforce has issued guidance to help organizations protect themselves from these types of attacks.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?