Executive Summary
In mid-2025, the FBI issued a critical alert warning organizations about two cybercriminal groups, UNC6040 and UNC6395, conducting coordinated data theft and extortion attacks targeting enterprise Salesforce environments. Attackers leveraged multiple initial access vectors—believed to include credential compromise and social engineering—to infiltrate Salesforce platforms, exfiltrating sensitive data at scale. The breach campaigns led to severe business interruptions, reputational damage, and raised concerns over cloud infrastructure security, particularly in environments perceived as “well-defended.” FBI guidance included new indicators of compromise and proactive defense measures for cloud-hosted SaaS platforms.
This incident marks a shift in threat actor focus toward high-value SaaS platforms, demonstrating the growing sophistication and persistence of financially-motivated attackers. It underscores the urgency for robust controls around identity, east-west traffic, and cloud-native visibility, as attack surfaces expand in digital-first enterprises.
Why This Matters Now
Attacks on Salesforce and other SaaS platforms are accelerating as cybercriminal groups develop advanced techniques to bypass traditional defenses and target business-critical data. Organizations must urgently reassess their SaaS security readiness, as these threats exploit identity gaps and cloud misconfigurations that are often overlooked in existing risk management programs.
Attack Path Analysis
The attackers initiated their campaign by exploiting weaknesses in Salesforce platform access, most likely via compromised credentials or misconfigured API endpoints. Upon gaining entry, they escalated their privileges within the Salesforce environment, possibly through manipulation of user roles or over-permissioned accounts. The threat actors then moved laterally across cloud workloads and internal regions, seeking additional data stores or expanding their foothold. To maintain persistence and evade detection, they leveraged encrypted channels or covert remote access tools for command and control. Sensitive data was ultimately exfiltrated out of the environment, using outbound channels likely designed to evade security controls. The attack culminated in damaging business impact through data theft and subsequent extortion activities.
Kill Chain Progression
Initial Compromise
Description
Exploited Salesforce access via stolen credentials, weak authentication, or misconfigured APIs to gain initial cloud entry.
Related CVEs
CVE-2025-20286
CVSS 9.9A critical vulnerability in Cisco Identity Services Engine (ISE) cloud deployments where identical credentials are used across all deployments of the same release version on the same cloud provider, posing a significant security risk.
Affected Products:
Cisco Identity Services Engine (ISE) – Affected versions prior to the patch release
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Exploit Public-Facing Application
Phishing
Modify Authentication Process
Email Collection
Transfer Data to Cloud Account
Automated Exfiltration
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for User Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Regulation (EU) 2022/2554) – ICT Risk Management
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Strong Identity Verification and Access Control
Control ID: Identity Pillar: Authentication
NIS2 Directive – Incident Handling and Security Policies
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
High risk from UNC6040/UNC6395 targeting Salesforce platforms for data theft, requiring enhanced zero trust segmentation and threat detection capabilities.
Financial Services
Critical exposure to Salesforce-based data theft attacks threatening customer data, demanding egress security controls and encrypted traffic protection measures.
Health Care / Life Sciences
Severe vulnerability to extortion attacks via Salesforce platforms, necessitating HIPAA-compliant multicloud visibility and anomaly response systems immediately.
Professional Training
Significant risk from targeted Salesforce data theft operations, requiring comprehensive east-west traffic security and inline intrusion prevention deployment.
Sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attackshttps://thehackernews.com/2025/09/fbi-warns-of-unc6040-and-unc6395.htmlVerified
- FBI Flash TLP Clear: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instanceshttps://www.aha.org/h-isac-white-reports/2025-09-12-fbi-flash-tlp-clear-cyber-criminal-groups-unc6040-and-unc6395-compromising-salesforce-instancesVerified
- FBI warns of cyber criminals targeting Salesforce platformshttps://www.aha.org/news/headline/2025-09-12-fbi-warns-cyber-criminals-targeting-salesforce-platformsVerified
- Beyond perimeter defense: Lessons from the recent Salesforce instance compromiseshttps://www.ibm.com/new/product-blog/beyond-perimeter-defense-lessons-from-the-recent-salesforce-instance-compromisesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Robust zero trust segmentation, least-privilege policies, traffic visibility, and egress controls would have significantly limited these campaigns, constraining initial access, preventing lateral movement, detecting anomalies, and stopping data exfiltration. CNSF-aligned controls enforce boundaries at the network, application, and workload layers, thereby reducing blast radius and ensuring policy enforcement across multi-cloud environments.
Control: Zero Trust Segmentation
Mitigation: Prevents unrestricted access to sensitive cloud resources from untrusted networks.
Control: Multicloud Visibility & Control
Mitigation: Detects suspicious privilege escalations or misconfigurations via policy audit trails.
Control: East-West Traffic Security
Mitigation: Blocks unauthorized lateral movement between workloads, regions, or services.
Control: Threat Detection & Anomaly Response
Mitigation: Surfaces anomalous remote access tool usage and unusual outbound communications for incident response.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized data exfiltration via managed, policy-based filtering of outbound traffic.
Reduces attack impact and extortion leverage by constraining adversary access and activity throughout the environment.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Customer Support
Estimated downtime: 7 days
Estimated loss: $5,000,000
Unauthorized access to sensitive customer data, including personal identifiable information (PII), financial records, and proprietary business information, leading to potential regulatory penalties and reputational damage.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy zero trust segmentation and least-privilege access for Salesforce and connected cloud assets to reduce unauthorized access risk.
- • Enforce strict east-west traffic controls and microsegmentation to halt lateral movement after initial compromise.
- • Enable centralized visibility across multi-cloud environments to detect policy violations and privilege escalations in real time.
- • Apply robust egress filtering and encrypted traffic inspection to block data exfiltration paths and detect covert channels.
- • Regularly audit access logs and incident detections, responding quickly to anomalies or indications of threat activity.



