onlyTrustedInfo.comonlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Reading: Hackers abuse modified Salesforce app to steal data, extort companies, Google says
Share
onlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Search
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
  • Advertise
  • Advertise
© 2025 OnlyTrustedInfo.com . All Rights Reserved.
Tech

Hackers abuse modified Salesforce app to steal data, extort companies, Google says

Last updated: June 5, 2025 12:30 am
OnlyTrustedInfo.com
Share
3 Min Read
Hackers abuse modified Salesforce app to steal data, extort companies, Google says
SHARE

By AJ Vicens

(Reuters) -Hackers are tricking employees at companies in Europe and the Americas into installing a modified version of a Salesforce-related app, allowing the hackers to steal reams of data, gain access to other corporate cloud services and extort those companies, Google said on Wednesday.

The hackers – tracked by the Google Threat Intelligence Group as UNC6040 – have “proven particularly effective at tricking employees” into installing a modified version of Salesforce’s Data Loader, a proprietary tool used to bulk import data into Salesforce environments, the researchers said.

The hackers use voice calls to trick employees into visiting a purported Salesforce connected app setup page to approve the unauthorized, modified version of the app, created by the hackers to emulate Data Loader.

If the employee installs the app, the hackers gain “significant capabilities to access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments,” the researchers said.

The access also frequently gives the hackers the ability to move throughout a customer’s network, enabling attacks on other cloud services and internal corporate networks.

Technical infrastructure tied to the campaign shares characteristics with suspected ties to the broader and loosely organized ecosystem known as “The Com,” known for small, disparate groups engaging in cybercriminal and sometimes violent activity, the researchers said.

A Google spokesperson told Reuters that roughly 20 organizations have been affected by the UNC6040 campaign, which has been observed over the past several months. A subset of those organizations had data successfully exfiltrated, the spokesperson said.

A Salesforce spokesperson told Reuters in an email that “there’s no indication the issue described stems from any vulnerability inherent in our platform.” The spokesperson said the voice calls used to trick employees “are targeted social engineering scams designed to exploit gaps in individual users’ cybersecurity awareness and best practices.”

The spokesperson declined to share the specific number of affected customers, but said that Salesforce was “aware of only a small subset of affected customers,” and said it was “not a widespread issue.”

Salesforce warned customers of voice phishing, or “vishing,” attacks and of hackers abusing malicious, modified versions of Data Loader in a March 2025 blog post.

(Reporting by AJ Vicens in Detroit; Editing by Leslie Adler and Franklin Paul)

You Might Also Like

Uranus’s Radiation Mystery Solved: Ancient Solar Wind Event Explains Decades-Old Voyager 2 Data

iOS 18.5 makes it easier to get the old Apple Mail design back

Juno Data Reveals Europa’s Ice Shell May Be Up to 39km Thick, Reshaping Habitable Ocean Models

Coinbase CEO says he ‘went rogue’ and fired some employees who didn’t adopt AI after being told to

Apple TV+ just canceled its longest-running comedy series

Share This Article
Facebook X Copy Link Print
Share
Previous Article Why AI acts so creepy when faced with being shut down Why AI acts so creepy when faced with being shut down
Next Article HELOC rates jump to near 2025 highs; home equity loans tick up too HELOC rates jump to near 2025 highs; home equity loans tick up too

Latest News

Cameron Brink’s All-White Statement: Fashion Meets a Full-Strength Return for the Sparks
Cameron Brink’s All-White Statement: Fashion Meets a Full-Strength Return for the Sparks
Sports May 11, 2026
Binghamton’s Historic Rally Sets Up David vs. Goliath Showdown with Oklahoma
Binghamton’s Historic Rally Sets Up David vs. Goliath Showdown with Oklahoma
Sports May 11, 2026
SEC Dominance: Alabama Claims No. 1 Seed as Conference Floods NCAA Softball Bracket
SEC Dominance: Alabama Claims No. 1 Seed as Conference Floods NCAA Softball Bracket
Sports May 11, 2026
Frustration Boils Over: Wembanyama’s Ejection Alters Spurs’ Trajectory
Frustration Boils Over: Wembanyama’s Ejection Alters Spurs’ Trajectory
Sports May 11, 2026
//
  • About Us
  • Contact US
  • Privacy Policy
onlyTrustedInfo.comonlyTrustedInfo.com
© 2026 OnlyTrustedInfo.com . All Rights Reserved.