Back to News
Market Impact: 0.35

Hackers abuse modified Salesforce app to steal data, extort companies, Google says

GOOGLCRM
Technology & InnovationCybersecurity & Data PrivacyCompany FundamentalsLegal & LitigationManagement & Governance
Hackers abuse modified Salesforce app to steal data, extort companies, Google says

Google's Threat Intelligence Group reports that hackers, identified as UNC6040, are using social engineering via voice calls to trick employees at European and American companies into installing a modified version of Salesforce's Data Loader app. This allows the hackers to exfiltrate sensitive data from Salesforce environments, potentially gaining access to other cloud services and internal networks, impacting roughly 20 organizations. Salesforce acknowledges the issue as a social engineering scam exploiting user cybersecurity awareness, stating it's not a widespread vulnerability in their platform and that they had warned customers of such attacks in March 2023.

Analysis

Google's Threat Intelligence Group has identified a hacking campaign by a group tracked as UNC6040, with suspected links to "The Com" ecosystem, targeting companies in Europe and the Americas. The hackers employ voice calls to socially engineer employees into installing a modified, unauthorized version of Salesforce's Data Loader application. This grants the attackers significant capabilities to access, query, and exfiltrate sensitive information from compromised Salesforce customer environments, and can lead to broader network infiltration and extortion. Approximately 20 organizations have been affected over several months, with a subset experiencing confirmed data exfiltration. Salesforce stated that the attacks do not stem from an inherent platform vulnerability but are social engineering scams exploiting user cybersecurity awareness. The company noted it had warned customers about such "vishing" attacks and malicious Data Loader versions in a March 2023 blog post, characterizing the impact as affecting "only a small subset of affected customers" and not a "widespread issue," while declining to specify the number of affected customers. The situation reflects a moderately negative sentiment for Salesforce (CRM), while Google (GOOGL), as the reporting entity, maintains a neutral sentiment.

AllMind AI Terminal