Executive Summary
In mid-2025, cybercriminal threat clusters UNC6040 and UNC6395 launched coordinated attacks targeting the Salesforce environments of major global enterprises, leveraging supply chain compromises, OAuth token abuse, and social engineering tactics. Attackers tricked employees into authorizing malicious OAuth apps or exploited stolen access tokens, enabling mass data exfiltration from Salesforce—including sensitive 'Accounts', 'Contacts', and support case records containing credentials and cloud secrets. Stolen information was subsequently used by the ShinyHunters extortion group for ransom threats and further infiltrations, impacting organizations such as Google, Cisco, Adidas, and major cybersecurity firms.
This incident exemplifies a growing wave of attacks exploiting trusted third-party platforms and identity federation weaknesses to compromise cloud SaaS data at scale. The sophisticated multi-stage approach highlights urgent risks related to SaaS supply chains, the need for robust OAuth governance, and increased vigilance toward privilege escalation via indirect access vectors.
Why This Matters Now
The prevalence of SaaS, federated identity, and supply chain interdependencies has made token theft and OAuth exploitation a leading attack vector in 2025. Organizations face urgent pressure to address gaps in SaaS governance, token lifecycle management, and real-time anomaly detection to prevent cascading breaches across interconnected cloud platforms.
Attack Path Analysis
Attackers initially compromised Salesforce environments using social engineering and supply chain vectors—specifically OAuth token abuse and malicious app connections. They escalated privileges by obtaining or forging access tokens, allowing broad access within Salesforce instances. The threat actors then moved laterally by accessing additional customer data, secrets, and tokens stored in Salesforce support cases, including sensitive credentials. They established command and control by maintaining persistent access through OAuth and refresh tokens for continued data harvesting. Large volumes of sensitive data—including customer records and authentication secrets—were rapidly exfiltrated to external infrastructure. Finally, attackers monetized the breach through extortion, public doxing, and potential further cloud pivots using harvested credentials, impacting customer privacy and business operations.
Kill Chain Progression
Initial Compromise
Description
Threat actors obtained initial access via social engineering (vishing) and supply chain compromise (Salesloft Drift OAuth token theft), tricking users into authorizing malicious or compromised OAuth applications in Salesforce.
Related CVEs
CVE-2025-53690
CVSS 9.8A critical deserialization vulnerability in Sitecore XP, XM, and Experience Commerce (prior to v9.0) allows unauthenticated remote code execution due to an insecure ASP.NET machine key.
Affected Products:
Sitecore XP – < 9.0
Sitecore XM – < 9.0
Sitecore Experience Commerce – < 9.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing via Service
Valid Accounts: Cloud Accounts
Use Alternate Authentication Material: Web Session Cookie
Steal Application Access Token
Account Manipulation: Additional Cloud Credentials
Data from Cloud Storage Object
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Resource Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Incident Response Plan and Procedures
Control ID: 12.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Session and Credential Management
Control ID: Identity Pillar: Continuous Authentication
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21(2)
ISO/IEC 27001:2022 – Information Security in Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Salesforce supply chain attacks enable mass data exfiltration through OAuth compromises, requiring enhanced egress security and zero trust segmentation for SaaS platforms.
Financial Services
Customer data theft from Salesforce platforms exposes sensitive financial records, demanding encrypted traffic protection and multicloud visibility for regulatory compliance.
Information Technology/IT
IT support impersonation tactics and stolen OAuth tokens create widespread vulnerability requiring threat detection capabilities and secure hybrid connectivity solutions.
Professional Training
Organizations using Salesforce for customer management face data exfiltration risks, necessitating anomaly response systems and application-level security controls.
Sources
- FBI warns of UNC6040, UNC6395 hackers stealing Salesforce datahttps://www.bleepingcomputer.com/news/security/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/Verified
- FBI FLASH Alert on UNC6040 and UNC6395https://www.ic3.gov/Media/News/2025/220914.aspxVerified
- Salesforce Security Advisory on OAuth Token Compromisehttps://help.salesforce.com/s/articleView?id=000385678&type=1Verified
- Mandiant Report on UNC6040 and UNC6395https://www.mandiant.com/resources/unc6040-unc6395-salesforce-data-theftVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Application of Zero Trust Network Segmentation, egress filtering, east-west visibility, and anomaly detection would have significantly hindered attackers’ lateral movement, API data harvesting, and mass exfiltration efforts across cloud SaaS and hybrid environments.
Control: Multicloud Visibility & Control
Mitigation: Centralized monitoring of OAuth app connections and anomalous access patterns detected suspicious third-party integrations.
Control: Zero Trust Segmentation
Mitigation: Identity-based policy segmentation limited scope of OAuth app permissions and access.
Control: East-West Traffic Security
Mitigation: East-west microsegmentation and workload-to-workload traffic controls blocked unauthorized API/data flows.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous API consumption or unusual data transfer patterns were baselined and rapidly alerted.
Control: Egress Security & Policy Enforcement
Mitigation: Stringent egress controls detected and blocked abnormal outbound flows consistent with data exfiltration.
Security fabric and inline enforcement reduces blast radius and increases detection of extortion follow-on tactics.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Customer Support
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to Salesforce instances led to the exfiltration of sensitive customer data, including contact information, support case details, and potentially credentials such as AWS keys and passwords. This exposure increases the risk of further targeted attacks and data misuse.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation to restrict OAuth app and user permissions to least privilege by identity and namespace.
- • Deploy robust east-west and egress policy enforcement to block lateral API pivoting and unauthorized data exfiltration.
- • Centralize multicloud/SaaS visibility to rapidly surface unauthorized token usage, unusual third-party app integrations, and mass data access events.
- • Continuously monitor for credential leakage and anomalous data flows with automated threat and anomaly response across hybrid and SaaS environments.
- • Audit and limit sensitive data and secrets stored in cloud SaaS support cases, ensuring strong workload and application isolation.



