I Need IT Support Now
Managed Service Provider Cybersecurity Houston
Shane

UNC6040: The Voice Phishing Attack Aiming for Your Salesforce Information

Cybercriminals Use Fake IT Support Calls to Steal Salesforce Data in Months-Long Extortion Scheme

Voice Phishing Alert
UNC6040 Never Hacks Salesforce. They Just Call an Employee and Ask Them to Open the Door.

This voice phishing group bypasses your technical controls entirely - by convincing a person on the phone to authorize a fake data-export app. Here is exactly how it works.

TL;DR
UNC6040 is a financially motivated group, tracked by Google's threat intelligence team, that runs voice phishing (vishing) attacks against organizations using Salesforce. Rather than exploiting a Salesforce vulnerability, an operator phones an employee, impersonates IT support, and talks them into authorizing a malicious version of Salesforce's Data Loader app (renamed to something like "My Ticket Portal"). The attackers then export large volumes of data, move laterally into Okta and Microsoft 365, and often wait months before extorting the victim - sometimes claiming ties to ShinyHunters. Defense is about people and access controls, not a patch.

UNC6040 is a voice phishing group that steals Salesforce data not by breaking into the software, but by phoning an employee and talking them into authorizing a malicious data-export app.

Google's Threat Intelligence Group identified UNC6040 as a financially motivated actor running vishing campaigns against Salesforce customers. What makes the group dangerous is that it sidesteps technical security entirely and targets the weakest link in any chain: people. Operators impersonate IT support in convincing phone calls, and their fluent English and grasp of corporate IT make the deception land - especially at multinational companies.

The short version: there is no Salesforce vulnerability to patch here. The vulnerability is a helpful employee who trusts a phone call - which is why the defense is training and access control, not a software update.

How the UNC6040 Attack Works

Five phases, and the whole thing turns on one authorized app.

The attack moves from a phone call to a fake app authorization to mass data theft - then quietly waits months before the extortion demand arrives.

  • Phase 1 - Initial contact. An operator phones an employee, posing as IT support and referencing internal processes or a current issue to build credibility.
  • Phase 2 - Malicious app authorization. On the call, they walk the victim to Salesforce's connected-app setup and have them authorize a modified, unauthorized version of Salesforce's Data Loader - renamed to something innocuous like "My Ticket Portal."
  • Phase 3 - Data exfiltration. With the app authorized, the attackers use its legitimate export functionality to pull large volumes of data, which looks routine to monitoring tools.
  • Phase 4 - Lateral movement. They move beyond Salesforce into Okta, Microsoft 365, and Workplace - collecting communications, authorization tokens, and confidential documents.
  • Phase 5 - Delayed extortion. Often months later, they make an extortion demand - sometimes claiming affiliation with the ShinyHunters group to raise the pressure.
Diagram of the UNC6040 voice phishing attack pathway against Salesforce
The UNC6040 attack pathway - Source: Mandiant.

The delay is what makes it so damaging: an organization can be compromised for months without knowing, while the attackers quietly expand their access before ever revealing themselves.

Who Is Behind It - and Who Is at Risk

A loosely organized crew, an opportunistic target list.

UNC6040's tactics overlap with "The Com," a loose collective of cybercriminals - and because the campaign is opportunistic, any organization using Salesforce could be a target.

The group's fingerprints include fake IT-support calls, a focus on Okta credentials, English-speaking employees at multinationals, and commercial VPNs (notably Mullvad) to mask activity - and the same infrastructure has hosted Okta phishing panels, pointing to a broader cloud-compromise toolkit. Around 20 organizations have been confirmed affected, primarily in the Americas and Europe. Risk is highest for:

  • Observed sectors. Education, hospitality, and retail have been targeted.
  • Multinationals with English-speaking branches and widespread Salesforce use.
  • Organizations with thin security training and no strict controls on data-export tools.

How to Defend Against It

Because the attack targets people, so must the defense - backed by tight access controls.

Protection is a mix of Salesforce hardening, least-privilege access, and - above all - a culture where employees verify IT-support requests before acting on them.

  • Audit connected apps. Review every connected application in Salesforce and remove anything unrecognized; tighten Data Loader permissions to only who needs them.
  • Lock down data export. Restrict the "API Enabled" permission to essential staff, apply least privilege, and require an approval process before any new connected app is installed.
  • Monitor for bulk access. Use Transaction Security Policies and Event Monitoring to flag large data downloads and unusual access patterns, and add IP-based login restrictions.
  • Verify every "IT support" call. Train employees to confirm requests through an independent channel - never authorize an app or share access because a caller asked.
  • Run vishing-focused awareness training. Teach the red flags of social engineering and set clear procedures for authorizing tools or granting data access.

Would Your Team Hang Up - or Help?

UNC6040 succeeds because one employee trusts one phone call. A free assessment tests your Salesforce access controls and your team's resistance to social engineering.

Get Your Free Assessment →
100% Free

Free Security & Social-Engineering Assessment

Could a fake IT-support call walk your team into authorizing a data-export app? Get a FREE assessment of your defenses against vishing and account takeover.

Get Your Free Assessment

The thing that unsettles people about UNC6040 is that nothing was "hacked." A person answered the phone, believed a helpful voice, and clicked authorize. That is the attack. Which is exactly why you cannot buy your way out of it with one more tool - you have to train for it.
Shane Stevens, CEO, CinchOps - LinkedIn

People and Access, Hardened Together

CinchOps pairs Salesforce and cloud-access hardening with the awareness training that stops vishing - so a single phone call cannot open your data - as part of everyday managed IT and cybersecurity.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, treating every phone call to your organization as a potential attack vector to defend.

  • Salesforce security hardening. Assessments and configuration that lock down connected apps and data-export tools.
  • Awareness training. Programs built for modern social engineering, including vishing and fake IT-support calls.
  • Access control and MFA. Least-privilege policies and multi-factor authentication across your cloud services.
  • Monitoring and response. Alerting on unusual data access, plus incident response planning for when something slips through.
  • Ongoing partnership. Regular audits and guidance as the threats evolve - preventing incidents, not just reacting to them.

Every phone call to your organization is a potential attack vector - and it can be turned into a strength. Contact CinchOps to build a security culture that resists even a convincing voice on the line.

Frequently Asked Questions

What is UNC6040?

UNC6040 is a financially motivated cybercriminal group, tracked by Google's Threat Intelligence Group, that runs voice phishing (vishing) attacks against organizations using Salesforce. It compromises Salesforce instances for large-scale data theft and later extortion - not by exploiting Salesforce, but by manipulating employees over the phone.

How does the UNC6040 vishing attack work?

An operator phones an employee, impersonating IT support, and talks them into authorizing a malicious version of Salesforce's Data Loader app - often renamed to something like "My Ticket Portal." Once authorized, the attackers export large volumes of data, move laterally into Okta and Microsoft 365, and often wait months before making an extortion demand.

Is this a vulnerability in Salesforce?

No. UNC6040 does not exploit a technical flaw in Salesforce. It abuses legitimate functionality - the connected-app authorization and Data Loader export tools - after tricking an employee into granting access. That is why the defense is user training and access control rather than a patch.

Who is at risk from UNC6040?

Because the campaign is opportunistic, any organization using Salesforce could be targeted. Risk is highest for multinationals with English-speaking branches, companies with widespread Salesforce use, and organizations with limited security training or weak controls on data-export tools. Around 20 organizations, mainly in the Americas and Europe, have been confirmed affected.

How can we protect our organization from vishing attacks?

Audit connected apps and Data Loader permissions, restrict the "API Enabled" permission and require approval for new connected apps, monitor for bulk data downloads with Transaction Security Policies and Event Monitoring, and add IP-based login restrictions. Most importantly, train employees to verify any IT-support request through an independent channel before authorizing anything.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506