The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Professional Training
Breach intelligence, attack campaigns, and threat reports targeting the Professional Training sector.
Explore Other Sectors
Professional Training Threat Reports
FBI Alert: UNC6040 & UNC6395 Target Salesforce in Sophisticated Data Theft and Extortion Attack
In mid-2025, the FBI issued a critical alert warning organizations about two cybercriminal groups, UNC6040 and UNC6395, conducting coordinated data theft and extortion attacks targeting enterprise Salesforce environments. Attackers leveraged multiple initial access vectors—believed to include credential compromise and social engineering—to infiltrate Salesforce platforms, exfiltrating sensitive data at scale. The breach campaigns led to severe business interruptions, reputational damage, and raised concerns over cloud infrastructure security, particularly in environments perceived as “well-defended.” FBI guidance included new indicators of compromise and proactive defense measures for cloud-hosted SaaS platforms. This incident marks a shift in threat actor focus toward high-value SaaS platforms, demonstrating the growing sophistication and persistence of financially-motivated attackers. It underscores the urgency for robust controls around identity, east-west traffic, and cloud-native visibility, as attack surfaces expand in digital-first enterprises.
8 months ago
Kill Chain
Salesloft Drift OAuth Breach Compromises Salesforce: 2025 Supply Chain Attack Analysis
In August 2025, a supply chain attack leveraging the Salesloft Drift integration was used to compromise customer Salesforce instances. Threat actors exploited compromised OAuth credentials between August 8-18, enabling them to perform automated, high-volume data exfiltration from sensitive Salesforce objects such as Account, Contact, Case, and Opportunity records. Following exfiltration, the attackers reportedly scanned acquired data for credentials and leveraged anti-forensic tactics, including deletion of query logs, to obscure their activities. Salesloft promptly revoked all relevant tokens and notified impacted customers, while security teams advised immediate credential rotations and log investigation for signs of compromise. This incident spotlights the risks associated with third-party SaaS integrations and highlights the sophistication of attackers targeting popular business platforms. As OAuth-based attacks and API exploitations become more common, organizations must enhance supply chain monitoring, review privilege access, and adopt zero trust principles to mitigate similar breaches.
8 months ago
Kill Chain
2025 Salesforce Supply Chain Breach Unveiled: UNC6040 and UNC6395’s Advanced OAuth Attacks
In mid-2025, cybercriminal threat clusters UNC6040 and UNC6395 launched coordinated attacks targeting the Salesforce environments of major global enterprises, leveraging supply chain compromises, OAuth token abuse, and social engineering tactics. Attackers tricked employees into authorizing malicious OAuth apps or exploited stolen access tokens, enabling mass data exfiltration from Salesforce—including sensitive 'Accounts', 'Contacts', and support case records containing credentials and cloud secrets. Stolen information was subsequently used by the ShinyHunters extortion group for ransom threats and further infiltrations, impacting organizations such as Google, Cisco, Adidas, and major cybersecurity firms. This incident exemplifies a growing wave of attacks exploiting trusted third-party platforms and identity federation weaknesses to compromise cloud SaaS data at scale. The sophisticated multi-stage approach highlights urgent risks related to SaaS supply chains, the need for robust OAuth governance, and increased vigilance toward privilege escalation via indirect access vectors.
8 months ago
Kill Chain
WhatsApp GhostPairing: 2024 Account Takeover Campaign Exploits Device Linking
In June 2024, cyber attackers launched widespread account takeover campaigns targeting WhatsApp users by exploiting the platform’s legitimate device-linking feature. This method, known as 'GhostPairing,' allows threat actors to hijack user accounts without requiring the victim’s credentials or multi-factor authentication codes. By intercepting or tricking users into sharing device-linking codes, attackers can remotely pair new devices to victims’ WhatsApp accounts, thus gaining complete access to conversations, contacts, and stored media. The campaign appears automated and has affected users globally, sparking concerns over the resilience of messaging platform identity controls. This incident highlights rising abuse of legitimate features and growing sophistication of social engineering tactics to bypass traditional security controls. Similar account compromise techniques are increasingly observed across the industry, prompting urgent calls for strengthened identity verification and robust monitoring of device association activities.
9 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports