Executive Summary
In mid-2025, a coordinated cybercriminal campaign led by UNC6395 and affiliates of Muddled Libra targeted Salesforce tenants via a multi-stage supply chain attack stemming from infiltrated third-party integrations such as Salesloft and Drift. Attackers used advanced social engineering and process exploitation rather than technological vulnerabilities to gain access to Salesforce customer data—including sensitive records like accounts, contacts, and opportunities. The operation highlighted the growing focus on data theft extortion tactics and the use of encrypted communications, with threat actors actively marketing stolen data through Telegram channels under monikers like "Scattered LAPSUS$ Hunters." The impact has been significant for retailers and digital platform users, driving urgent defensive and policy changes at Salesforce and affected enterprises.
This incident underscores an accelerating threat shift in 2025: attackers are increasingly leveraging social engineering and the SaaS supply chain to circumvent traditional defenses, monetizing access through extortion rather than ransomware. The event has intensified industry efforts to tighten access controls and enforce encryption, amid persistent regulatory and law enforcement actions.
Why This Matters Now
The surge in data theft-extortion attacks exploiting trusted platforms like Salesforce signals an urgent need for stronger SaaS security, real-time monitoring, and policy enforcement. As cybercriminal groups adapt quickly to access restrictions, organizations face heightened risk of customer data loss, reputational damage, and compliance violations if proactive controls are not implemented immediately.
Attack Path Analysis
Adversaries initiated access via sophisticated social engineering to obtain valid cloud/SaaS credentials, exploiting end-user trust in Salesforce and third-party SaaS tools. Next, the attackers escalated privileges by abusing compromised accounts or poorly restricted OAuth permissions to increase data access. They then moved laterally across connected applications, possibly leveraging east-west cloud pathways and privileged APIs to gather more data. Command and control was established through covert outbound SaaS or remote access channels to orchestrate data theft and manage operations. Data was subsequently exfiltrated through bulk downloads or API exports, often over unmonitored or insufficiently restricted egress paths. The attack concluded with the extortion of victim organizations, data sale, or, in some cases, preparation for RaaS extortion with potential business disruption.
Kill Chain Progression
Initial Compromise
Description
Attackers used spear-phishing and social engineering to entice users into sharing Salesforce or third-party SaaS credentials, likely exploiting legitimate but misused connected app flows.
Related CVEs
CVE-2025-43697
CVSS 7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data.
Affected Products:
Salesforce OmniStudio – before Spring 2025
Exploit Status:
no public exploitCVE-2025-43698
CVSS 7.5FlexCard SOQL data source bypasses field-level security, exposing all field data for records.
Affected Products:
Salesforce OmniStudio – before Spring 2025
Exploit Status:
no public exploitCVE-2025-43699
CVSS 5.3FlexCard 'Required Permissions' field can be bypassed due to client-side enforcement.
Affected Products:
Salesforce OmniStudio – before Spring 2025
Exploit Status:
no public exploitCVE-2025-43700
CVSS 7.5FlexCard 'View Encrypted Data' permission not enforced, returning plaintext for encrypted data to unauthorized users.
Affected Products:
Salesforce OmniStudio – before Spring 2025
Exploit Status:
no public exploitCVE-2025-43701
CVSS 5.3FlexCard allows guest users to access values for Custom Settings.
Affected Products:
Salesforce OmniStudio – before Spring 2025
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Phishing
Valid Accounts
Signed Binary Proxy Execution: User Execution
Supply Chain Compromise
Data from Local System
Transfer Data to Cloud Account
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-factor Authentication for All Access to CDE
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 6
CISA Zero Trust Maturity Model 2.0 – Verification of User and Device Access
Control ID: Identity Pillar: Authentication and Access Management
NIS2 Directive – Technical and Organizational Measures, Incident Handling
Control ID: Art. 21(2), (d), (f)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Salesforce platform attacks and supply chain compromises targeting SaaS environments expose critical customer data through social engineering and application vulnerabilities.
Retail Industry
Data theft extortion campaigns specifically targeting retail customer databases shift from traditional POS malware to cloud-based data exfiltration tactics.
Financial Services
Salesforce CRM data breaches expose sensitive financial customer records while threat actors pivot from ransomware to data theft monetization models.
Information Technology/IT
Zero trust segmentation failures and inadequate east-west traffic monitoring enable lateral movement and unencrypted data exfiltration in hybrid cloud environments.
Sources
- Data Is the New Diamond: Latest Moves by Hackers and Defendershttps://unit42.paloaltonetworks.com/data-is-the-new-diamond-latest-moves-by-hackers-and-defenders/Verified
- Salesloft breached to steal OAuth tokens for Salesforce data-theft attackshttps://www.techradar.com/pro/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacksVerified
- UNC6395 Targets Salesloft in Drift OAuth Token Theft Campaignhttps://www.thaicert.or.th/en/2025/08/29/unc6395-targets-salesloft-in-drift-oauth-token-theft-campaign/Verified
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attackshttps://thecyberpost.com/news/hackers/fbi-warns-of-unc6040-and-unc6395-targeting-salesforce-platforms-in-data-theft-attacks/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
CNSF-aligned controls such as Zero Trust Segmentation, egress security, encryption, multicloud visibility, and inline threat prevention would have severely constrained the adversary's ability to move laterally, exfiltrate data, or operate undetected by segmenting sensitive applications, enforcing least privilege, and monitoring for anomalous data flows.
Control: Multicloud Visibility & Control
Mitigation: Abnormal login attempts and new SaaS integrations would be rapidly detected and alerted.
Control: Zero Trust Segmentation
Mitigation: Movement from compromised identities is limited due to identity-based segmentation and least privilege.
Control: East-West Traffic Security
Mitigation: Lateral movement between workloads or regions is prevented by microsegmentation and internal flow controls.
Control: Cloud Firewall (ACF) & Inline IPS (Suricata)
Mitigation: C2 traffic is detected, blocked, or alerted on via egress filtering and signature-based inspection.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized data exfiltration is detected and prevented at egress points.
Extortion-related threats and post-exfil anomaly are detected and responded to rapidly.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Marketing
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to sensitive customer data, including personal information and credentials, leading to potential identity theft and financial fraud.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation and least privilege to restrict movement and access across sensitive workloads and SaaS platforms.
- • Implement egress filtering, inline IPS, and centralized monitoring to detect and prevent data exfiltration and command & control activities.
- • Leverage multicloud visibility solutions to baseline normal activity, rapidly detect anomalous logins, and flag unauthorized SaaS integrations.
- • Apply policy-based encryption to protect data-in-transit—including SaaS to SaaS and cross-region flows—against interception or packet sniffing.
- • Strengthen incident response processes and threat detection tooling to reduce dwell time from initial compromise to extortion or data leakage.



