CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise Scale
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
      • Do You Need a Managed IT Provider?
      • Could Your Business Survive an IT Outage?
      • Would Your Business Survive a Cyber Attack?
    • News & Updates
    • Blog
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
    • IT Outage Calculator
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed Service Provider Cybersecurity Houston
Shane June 5th, 2025

UNC6040: The Voice Phishing Attack Aiming for Your Salesforce Information

Cybercriminals Use Fake IT Support Calls to Steal Salesforce Data in Months-Long Extortion Scheme

Voice Phishing Alert
UNC6040 Never Hacks Salesforce. They Just Call an Employee and Ask Them to Open the Door.

This voice phishing group bypasses your technical controls entirely - by convincing a person on the phone to authorize a fake data-export app. Here is exactly how it works.

TL;DR
UNC6040 is a financially motivated group, tracked by Google's threat intelligence team, that runs voice phishing (vishing) attacks against organizations using Salesforce. Rather than exploiting a Salesforce vulnerability, an operator phones an employee, impersonates IT support, and talks them into authorizing a malicious version of Salesforce's Data Loader app (renamed to something like "My Ticket Portal"). The attackers then export large volumes of data, move laterally into Okta and Microsoft 365, and often wait months before extorting the victim - sometimes claiming ties to ShinyHunters. Defense is about people and access controls, not a patch.
📞 How the Attack Works 🎯 Who Is Behind It 🛡️ How to Defend 🚀 How CinchOps Helps

UNC6040 is a voice phishing group that steals Salesforce data not by breaking into the software, but by phoning an employee and talking them into authorizing a malicious data-export app.

Google's Threat Intelligence Group identified UNC6040 as a financially motivated actor running vishing campaigns against Salesforce customers. What makes the group dangerous is that it sidesteps technical security entirely and targets the weakest link in any chain: people. Operators impersonate IT support in convincing phone calls, and their fluent English and grasp of corporate IT make the deception land - especially at multinational companies.

The short version: there is no Salesforce vulnerability to patch here. The vulnerability is a helpful employee who trusts a phone call - which is why the defense is training and access control, not a software update.

How the UNC6040 Attack Works

Five phases, and the whole thing turns on one authorized app.

The attack moves from a phone call to a fake app authorization to mass data theft - then quietly waits months before the extortion demand arrives.

  • Phase 1 - Initial contact. An operator phones an employee, posing as IT support and referencing internal processes or a current issue to build credibility.
  • Phase 2 - Malicious app authorization. On the call, they walk the victim to Salesforce's connected-app setup and have them authorize a modified, unauthorized version of Salesforce's Data Loader - renamed to something innocuous like "My Ticket Portal."
  • Phase 3 - Data exfiltration. With the app authorized, the attackers use its legitimate export functionality to pull large volumes of data, which looks routine to monitoring tools.
  • Phase 4 - Lateral movement. They move beyond Salesforce into Okta, Microsoft 365, and Workplace - collecting communications, authorization tokens, and confidential documents.
  • Phase 5 - Delayed extortion. Often months later, they make an extortion demand - sometimes claiming affiliation with the ShinyHunters group to raise the pressure.
Diagram of the UNC6040 voice phishing attack pathway against Salesforce
The UNC6040 attack pathway - Source: Mandiant.

The delay is what makes it so damaging: an organization can be compromised for months without knowing, while the attackers quietly expand their access before ever revealing themselves.

Who Is Behind It - and Who Is at Risk

A loosely organized crew, an opportunistic target list.

UNC6040's tactics overlap with "The Com," a loose collective of cybercriminals - and because the campaign is opportunistic, any organization using Salesforce could be a target.

The group's fingerprints include fake IT-support calls, a focus on Okta credentials, English-speaking employees at multinationals, and commercial VPNs (notably Mullvad) to mask activity - and the same infrastructure has hosted Okta phishing panels, pointing to a broader cloud-compromise toolkit. Around 20 organizations have been confirmed affected, primarily in the Americas and Europe. Risk is highest for:

  • Observed sectors. Education, hospitality, and retail have been targeted.
  • Multinationals with English-speaking branches and widespread Salesforce use.
  • Organizations with thin security training and no strict controls on data-export tools.

How to Defend Against It

Because the attack targets people, so must the defense - backed by tight access controls.

Protection is a mix of Salesforce hardening, least-privilege access, and - above all - a culture where employees verify IT-support requests before acting on them.

  • Audit connected apps. Review every connected application in Salesforce and remove anything unrecognized; tighten Data Loader permissions to only who needs them.
  • Lock down data export. Restrict the "API Enabled" permission to essential staff, apply least privilege, and require an approval process before any new connected app is installed.
  • Monitor for bulk access. Use Transaction Security Policies and Event Monitoring to flag large data downloads and unusual access patterns, and add IP-based login restrictions.
  • Verify every "IT support" call. Train employees to confirm requests through an independent channel - never authorize an app or share access because a caller asked.
  • Run vishing-focused awareness training. Teach the red flags of social engineering and set clear procedures for authorizing tools or granting data access.

Would Your Team Hang Up - or Help?

UNC6040 succeeds because one employee trusts one phone call. A free assessment tests your Salesforce access controls and your team's resistance to social engineering.

Get Your Free Assessment →
100% Free

Free Security & Social-Engineering Assessment

Could a fake IT-support call walk your team into authorizing a data-export app? Get a FREE assessment of your defenses against vishing and account takeover.

Get Your Free Assessment

The thing that unsettles people about UNC6040 is that nothing was "hacked." A person answered the phone, believed a helpful voice, and clicked authorize. That is the attack. Which is exactly why you cannot buy your way out of it with one more tool - you have to train for it.
Shane Stevens, CEO, CinchOps - LinkedIn

People and Access, Hardened Together

CinchOps pairs Salesforce and cloud-access hardening with the awareness training that stops vishing - so a single phone call cannot open your data - as part of everyday managed IT and cybersecurity.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, treating every phone call to your organization as a potential attack vector to defend.

  • Salesforce security hardening. Assessments and configuration that lock down connected apps and data-export tools.
  • Awareness training. Programs built for modern social engineering, including vishing and fake IT-support calls.
  • Access control and MFA. Least-privilege policies and multi-factor authentication across your cloud services.
  • Monitoring and response. Alerting on unusual data access, plus incident response planning for when something slips through.
  • Ongoing partnership. Regular audits and guidance as the threats evolve - preventing incidents, not just reacting to them.

Every phone call to your organization is a potential attack vector - and it can be turned into a strength. Contact CinchOps to build a security culture that resists even a convincing voice on the line.

Frequently Asked Questions

What is UNC6040?

UNC6040 is a financially motivated cybercriminal group, tracked by Google's Threat Intelligence Group, that runs voice phishing (vishing) attacks against organizations using Salesforce. It compromises Salesforce instances for large-scale data theft and later extortion - not by exploiting Salesforce, but by manipulating employees over the phone.

How does the UNC6040 vishing attack work?

An operator phones an employee, impersonating IT support, and talks them into authorizing a malicious version of Salesforce's Data Loader app - often renamed to something like "My Ticket Portal." Once authorized, the attackers export large volumes of data, move laterally into Okta and Microsoft 365, and often wait months before making an extortion demand.

Is this a vulnerability in Salesforce?

No. UNC6040 does not exploit a technical flaw in Salesforce. It abuses legitimate functionality - the connected-app authorization and Data Loader export tools - after tricking an employee into granting access. That is why the defense is user training and access control rather than a patch.

Who is at risk from UNC6040?

Because the campaign is opportunistic, any organization using Salesforce could be targeted. Risk is highest for multinationals with English-speaking branches, companies with widespread Salesforce use, and organizations with limited security training or weak controls on data-export tools. Around 20 organizations, mainly in the Americas and Europe, have been confirmed affected.

How can we protect our organization from vishing attacks?

Audit connected apps and Data Loader permissions, restrict the "API Enabled" permission and require approval for new connected apps, monitor for bulk data downloads with Transaction Security Policies and Event Monitoring, and add IP-based login restrictions. Most importantly, train employees to verify any IT-support request through an independent channel before authorizing anything.

Discover More

What If an Employee Falls for a Phishing Email?
What Is Identity and Access Management?
CinchOps Cybersecurity Services

Sources

  • Google Cloud (Mandiant), The Cost of a Call: From Voice Phishing to Data Extortion
  • CISA, Avoiding Social Engineering and Phishing Attacks
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

March 12th, 2026
IT Order
Is Your Technology Working for Your Business or Is Your Business Working Around Your Technology?

From Duct Tape IT to Designed IT – You Built This Business to Do What You’re Great At

October 24th, 2025
Managed Service Provider Houston Cybersecurity
Ransomware Attacks on Critical Infrastructure Surge 34% in 2025: Is Your Houston Business at Risk?

How Ransomware-As-A-Service Platforms Fuel The 4,701 Cyberattacks Recorded In 2025 – Layered Defense Strategy Essential As Traditional Perimeter Security Proves Inadequate

March 25th, 2026
World Map
The 2026 U.S. Intelligence Threat Assessment: What It Means for Houston Cybersecurity

Key Cybersecurity Takeaways from the 2026 U.S. Threat Report – Ransomware Groups Just Got Faster – Your Defenses Need To Keep Up

October 7th, 2025
Managed Service Provider Houston Cybersecurity
Comcast 2025 Cybersecurity Threat Report: What Houston Businesses Need to Know

From Reconnaissance To Ransomware: Understanding The Four Stages Of Modern Cyber Attacks – How Attackers Use AI, Proxies, And Valid Accounts To Breach Houston Companies

June 9th, 2026
Managed IT Houston
Phishing Simulation Small Business: What the Results Actually Reveal

The Click Rate Is The Start, Not The Verdict – Coaching Beats Shaming Every Single Time

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery (BCDR)
  • Cloud Services
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy