Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
voice-social-engineeringcloud-service-vulnerabilitybreach-disclosure-notificationdata-exfiltration-method

Salesforce-Targeted Data Breaches Impacting Google, Workday, and Others via Social Engineering

Updated 2mo agoFirst seen Oct 3, 202518 sources

A coordinated wave of cyberattacks in 2025 targeted organizations using Salesforce’s CRM platform, resulting in significant data breaches at major companies including Google and Workday. Attackers exploited the inherent trust and connectivity of cloud-based CRM systems, focusing on social engineering rather than technical vulnerabilities. Workday confirmed that attackers accessed a database containing business contact information for up to 11,000 corporate customers and 70 million individual user records, with the breach discovered in early August 2025. Google also disclosed that its Salesforce instance used for Google Ads leads was compromised, leading to the theft of over 2.5 million customer records, including business contact details and sales notes for small and mid-sized clients. Cisco and other organizations were also listed among the victims of this campaign. The threat group responsible, identified as UNC6040 and associated with ShinyHunters, used telephone-based social engineering (vishing) to trick employees into granting access or sharing credentials. Attackers convinced targets to use a modified, unauthorized version of the Salesforce Data Loader app, which enabled them to exfiltrate sensitive data from Salesforce environments. Mandiant, working with Google, provided proactive defense recommendations, emphasizing that the attacks did not exploit Salesforce vulnerabilities but rather relied on manipulating end users. The attackers’ tactics included delayed extortion demands, sometimes occurring months after the initial compromise. The breaches highlighted the risks of interconnected cloud services and the importance of robust identity and access management. Security experts stressed the need for organizations to harden their Salesforce and other cloud assets against social engineering. The incidents underscored the growing trend of targeting SaaS platforms through human factors rather than technical flaws. Lessons from these breaches include the necessity of employee training, multi-factor authentication, and vigilant monitoring of third-party integrations. The scale and sophistication of the attacks demonstrated the evolving threat landscape for cloud-based business applications. Organizations are urged to review their incident response plans and ensure that all users are aware of the risks posed by social engineering campaigns. The breaches serve as a warning for enterprises to reassess their security posture around cloud CRM platforms and to implement layered defenses against both technical and human-centric threats.

Share:
Salesforce-Targeted Data Breaches Impacting Google, Workday, and Others via Social Engineering
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 15, 20262mo ago

McGraw Hill discloses limited breach tied to Salesforce webpage misconfiguration

McGraw Hill said unauthorized access affected a webpage hosted on Salesforce as part of a broader misconfiguration impacting multiple organizations. The company said its Salesforce accounts, customer databases, internal systems, and sensitive data were not compromised, and that it secured the affected webpages and began an investigation with Salesforce.

Educational company McGraw Hill says Salesforce misconfiguration led to data leak | The Record from Recorded Future News
Oct 10, 20259mo ago

Federal authorities shutter the Salesforce extortion site

U.S. federal authorities took down the ShinyHunters-linked extortion site used to pressure Salesforce customers. The action disrupted the group's public leak-and-ransom operation.

Oct 7, 20259mo ago

Salesforce says it will not pay extortion demands

Salesforce informed customers and the public that it would not negotiate with or pay the attackers behind the Salesforce-related extortion campaign. Reports said the leak site threatened publication if demands were not met by October 10.

Oct 3, 20259mo ago

Salesforce denies platform compromise and aids affected customers

Salesforce said its platform was not hacked and that it had no indication of a compromise or exploitation of a known vulnerability. The company began supporting customers named on the extortion site while emphasizing the intrusions affected customer environments, not Salesforce itself.

Group claims theft of nearly 1 billion Salesforce-linked records

The actor told reporters it had stolen almost 1 billion records tied to Salesforce customer environments, including personally identifiable information, and publicized the claim through its leak operation. Multiple outlets reported the same claim on October 3.

Extortion site launches listing about 39–40 alleged Salesforce victims

The threat actor launched a dark-web leak site naming roughly 39 to 40 alleged victim organizations and threatening to publish stolen Salesforce-related customer data unless ransoms were paid. The site marked a shift from covert intrusions to public extortion.

Oct 1, 20259mo ago

Google tracks Salesforce-focused vishing campaign as UNC6040

Google Threat Intelligence Group documented a social-engineering campaign targeting organizations that use Salesforce, in which attackers vished IT help desks and induced installation of a modified Salesforce Data Loader. Google linked the activity to UNC6040 and noted infrastructure overlaps with the wider 'The Com' cybercriminal ecosystem.

Sep 30, 20259mo ago

Attackers compromise Salesforce customers in wave spanning May to September

An actor using the names ShinyHunters and 'Scattered LAPSUS$ Hunters' breached multiple Salesforce customer environments through vishing rather than a Salesforce platform exploit. Victim listings later indicated intrusions occurred across May through September 2025.

Sep 15, 20259mo ago

FBI warns of two Salesforce-targeting campaigns and publishes IOCs

The FBI issued an alert warning that UNC6040 and UNC6395 were targeting Salesforce environments for data theft and extortion. The notice described UNC6040's vishing activity and UNC6395's abuse of Salesloft Drift OAuth tokens, and included indicators of compromise and defensive guidance for organizations.

FBI warns about 2 campaigns targeting Salesforce instances | Cybersecurity Dive
Jul 1, 20251y ago

UK police arrest four youths over retailer cyberattacks

UK police arrested four people under the age of 21 in connection with disruptive 2025 cyberattacks targeting British retailers including Marks & Spencer, Co-op, and Jaguar Land Rover. The same actor later claimed responsibility for those incidents as part of its broader extortion branding.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

46 LINKEDOpen in app
Organizations
41 linked
SalesforceRockstar GamesSalesforceMatch GroupBumbleRockstar GamesMcGraw-HillMatch GroupCanada GooseCanada GooseGoogleCisco SystemsJaguar Land RoverSalesloftShinyHuntersScattered SpiderThomson ReutersUNC6395The ComAmazon Web ServicesZscalerUNC6040The Walt Disney CompanyScattered Lapsus$ HuntersPalo Alto NetworksTenableQualysOktaHBO MaxCloudflareDriftToyota Motor CorporationMcDonald'sWorkdayProofpointMicrosoft CorporationBritish PoliceIkeaMarks & SpencerCo-opCybersecurity Dive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.