Executive Summary
In early 2024, the FBI’s Internet Crime Complaint Center (IC3) issued an alert detailing active campaigns by threat groups UNC6040 and UNC6395 targeting Salesforce customer environments. The attackers leveraged phishing and social engineering to obtain valid Salesforce credentials, subsequently exploiting misconfigurations and inadequate security controls in customer cloud instances. This enabled unauthorized access to sensitive data, including customer information and corporate records, leading to multiple data theft and extortion attempts. Salesforce itself was not breached, but its customers suffered direct operational impacts due to data compromise and disruption.
This incident underscores a rising trend of advanced threat actors targeting supply chain and SaaS ecosystems, exploiting both human and technical gaps in cloud security. As cloud adoption accelerates, enterprises must address credential hygiene, proper configuration, and real-time anomaly detection to thwart similar attacks.
Why This Matters Now
This case spotlights urgent risks in SaaS supply chains and highlights the vulnerability of cloud customer configurations to well-coordinated threat groups. With attackers increasingly exploiting trusted SaaS platforms and targeting user accounts, organizations must act quickly to enhance cloud posture, implement zero trust, and boost monitoring to avert similar breaches.
Attack Path Analysis
Threat actors exploited weaknesses in Salesforce authentication or customer configuration to gain initial access to cloud accounts. They then attempted to escalate privileges through manipulation of permissions or stolen credentials. The adversaries searched for internal data sources and pivoted across cloud workloads to broaden their foothold. They established command and control using outbound connections to remote infrastructure. Sensitive customer data was prepared for and moved out of the cloud environment. Ultimately, attackers could have posed a threat of data leak, extortion, or further business disruption.
Kill Chain Progression
Initial Compromise
Description
Attackers gained initial access to Salesforce customer environments by exploiting weak authentication, misconfigurations, or phishing for user credentials.
MITRE ATT&CK® Techniques
Valid Accounts
Cloud Service Accounts
Remote Services: Cloud Services
Brute Force: Password Guessing
Exploit Public-Facing Application
Modify Authentication Process: Web Portal
Data from Cloud Storage Object
Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
NIS2 Directive – Risk Management Measures and Security Policies
Control ID: Art. 21(2)
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
CISA Zero Trust Maturity Model 2.0 – Identity Management and Access Control
Control ID: IDENTITY-1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Salesforce-dependent software companies face cloud service attacks from UNC6040/UNC6395, requiring enhanced egress security, zero trust segmentation, and multicloud visibility controls.
Financial Services
Financial institutions using Salesforce CRM systems vulnerable to threat actors targeting cloud platforms, necessitating encrypted traffic protection and compliance with regulatory frameworks.
Health Care / Life Sciences
Healthcare organizations leveraging Salesforce for patient data management exposed to cloud service attacks, demanding HIPAA-compliant threat detection and secure hybrid connectivity.
Marketing/Advertising/Sales
Sales and marketing firms heavily reliant on Salesforce platforms targeted by FBI-warned threat actors, requiring comprehensive cloud firewall and anomaly detection capabilities.
Sources
- FBI Warns of Threat Actors Hitting Salesforce Customershttps://www.darkreading.com/cyberattacks-data-breaches/fbi-warns-threat-actors-salesforce-customersVerified
- Salesforce Data Exfiltration, Campaign C0059https://attack.mitre.org/campaigns/C0059Verified
- Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortionhttps://www.fbi.gov/news/press-releases/cyber-criminal-groups-unc6040-and-unc6395-compromising-salesforce-instances-for-data-theft-and-extortionVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, robust monitoring, and strict egress controls would have helped to limit the adversary’s access scope, rapidly detect anomalous movement, and prevent large-scale data exfiltration from the Salesforce environment. Distributed policy enforcement and east-west visibility reduce the window for privilege escalation and lateral movement across workloads.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline policy checks and threat detection increase early compromise visibility.
Control: Zero Trust Segmentation
Mitigation: Limits scope of compromised credentials and unauthorized privilege escalation.
Control: East-West Traffic Security
Mitigation: Detects and prevents unauthorized inter-workload communications.
Control: Threat Detection & Anomaly Response
Mitigation: C2 traffic detection triggers alerts and disrupts attacker control.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents, inspects, and alerts on anomalous or large-scale outbound data flows.
Continuous monitoring and forensics enable rapid response and post-incident remediation.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Marketing Campaigns
Estimated downtime: 5 days
Estimated loss: $500,000
Unauthorized access to sensitive customer data, including personally identifiable information (PII) and proprietary business information, leading to potential regulatory penalties and reputational damage.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce identity-based segmentation and least privilege access within cloud SaaS environments.
- • Deploy distributed policy enforcement and real-time threat detection to monitor for unusual access and movement.
- • Strictly control and monitor all egress traffic with FQDN filtering and inline IPS to prevent exfiltration.
- • Ensure east-west traffic and API calls are visible and subject to consistent security policies.
- • Establish comprehensive centralized visibility and logging across all multicloud and SaaS assets for rapid incident detection and response.



