The Containment Era is here. →Explore

Executive Summary

In mid-2025, the FBI issued a critical alert warning organizations about two cybercriminal groups, UNC6040 and UNC6395, conducting coordinated data theft and extortion attacks targeting enterprise Salesforce environments. Attackers leveraged multiple initial access vectors—believed to include credential compromise and social engineering—to infiltrate Salesforce platforms, exfiltrating sensitive data at scale. The breach campaigns led to severe business interruptions, reputational damage, and raised concerns over cloud infrastructure security, particularly in environments perceived as “well-defended.” FBI guidance included new indicators of compromise and proactive defense measures for cloud-hosted SaaS platforms.

This incident marks a shift in threat actor focus toward high-value SaaS platforms, demonstrating the growing sophistication and persistence of financially-motivated attackers. It underscores the urgency for robust controls around identity, east-west traffic, and cloud-native visibility, as attack surfaces expand in digital-first enterprises.

Why This Matters Now

Attacks on Salesforce and other SaaS platforms are accelerating as cybercriminal groups develop advanced techniques to bypass traditional defenses and target business-critical data. Organizations must urgently reassess their SaaS security readiness, as these threats exploit identity gaps and cloud misconfigurations that are often overlooked in existing risk management programs.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breaches exposed shortcomings in east-west traffic monitoring, identity-based policy enforcement, and encrypted traffic controls, highlighting compliance risks in NIST, HIPAA, and PCI frameworks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Robust zero trust segmentation, least-privilege policies, traffic visibility, and egress controls would have significantly limited these campaigns, constraining initial access, preventing lateral movement, detecting anomalies, and stopping data exfiltration. CNSF-aligned controls enforce boundaries at the network, application, and workload layers, thereby reducing blast radius and ensuring policy enforcement across multi-cloud environments.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Prevents unrestricted access to sensitive cloud resources from untrusted networks.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Detects suspicious privilege escalations or misconfigurations via policy audit trails.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocks unauthorized lateral movement between workloads, regions, or services.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Surfaces anomalous remote access tool usage and unusual outbound communications for incident response.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized data exfiltration via managed, policy-based filtering of outbound traffic.

Impact (Mitigations)

Reduces attack impact and extortion leverage by constraining adversary access and activity throughout the environment.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
  • Customer Support
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to sensitive customer data, including personal identifiable information (PII), financial records, and proprietary business information, leading to potential regulatory penalties and reputational damage.

Recommended Actions

  • Deploy zero trust segmentation and least-privilege access for Salesforce and connected cloud assets to reduce unauthorized access risk.
  • Enforce strict east-west traffic controls and microsegmentation to halt lateral movement after initial compromise.
  • Enable centralized visibility across multi-cloud environments to detect policy violations and privilege escalations in real time.
  • Apply robust egress filtering and encrypted traffic inspection to block data exfiltration paths and detect covert channels.
  • Regularly audit access logs and incident detections, responding quickly to anomalies or indications of threat activity.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image