Close Menu
Business Pro
  • Home
  • Business
  • Editor’s Choice
  • Economy
  • Energy
  • Finance
  • Investing
  • Metals
Trending Now

Financial data for May released: “Liquid money” increases, M1 growth rate rises significantly, and enterprises’ willingness to withdraw funds increases significantly

June 14, 2025

Streamline Your Workflow With This $30 Microsoft Office Professional Plus 2019 License

June 14, 2025

Trump reports more than $600 million in income from crypto, golf, licensing fees

June 14, 2025
Facebook X (Twitter) Instagram
Trending
  • Financial data for May released: “Liquid money” increases, M1 growth rate rises significantly, and enterprises’ willingness to withdraw funds increases significantly
  • Streamline Your Workflow With This $30 Microsoft Office Professional Plus 2019 License
  • Trump reports more than $600 million in income from crypto, golf, licensing fees
  • Israel-Iran attacks and the 2 other things that drove the stock market this week
  • Trump says U.S. will have ‘golden share’ in U.S. Steel after Nippon deal
  • Anne Wojcicki’s nonprofit wins bid to acquire genetic testing company 23andMe
  • Guangzhou Plans to Fully Abolish “Three Restrictions” on Housing; Will Other First-Tier Cities Follow Suit?
  • You’re Only Three Weeks Away From Reaching International Clients, Partners, and Customers
  • About
  • Privacy Policy
  • Terms
  • Contact
Facebook X (Twitter) Instagram
Business Pro
Subscribe
Saturday, June 14
  • Home
  • Business
  • Editor’s Choice
  • Economy
  • Energy
  • Finance
  • Investing
  • Metals
Business Pro
Home»Business
Business

Hackers are using a modified Salesforce app to trick employees and extort companies, Google says

Business ProBy Business ProJune 4, 20252 Mins Read
Facebook Twitter Pinterest LinkedIn Email WhatsApp Copy Link

Hackers are tricking employees at companies in Europe and the Americas into installing a modified version of a Salesforce-related app, allowing the hackers to steal reams of data, gain access to other corporate cloud services and extort those companies, Google said on Wednesday.

The hackers – tracked by the Google Threat Intelligence Group as UNC6040 – have “proven particularly effective at tricking employees” into installing a modified version of Salesforce’s Data Loader, a proprietary tool used to bulk import data into Salesforce environments, the researchers said.

The hackers use voice calls to trick employees into visiting a purported Salesforce connected app setup page to approve the unauthorized, modified version of the app, created by the hackers to emulate Data Loader.

If the employee installs the app, the hackers gain “significant capabilities to access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments,” the researchers said.

The access also frequently gives the hackers the ability to move throughout a customer’s network, enabling attacks on other cloud services and internal corporate networks.

Technical infrastructure tied to the campaign shares characteristics with suspected ties to the broader and loosely organized ecosystem known as “The Com,” known for small, disparate groups engaging in cybercriminal and sometimes violent activity, the researchers said.

A Google spokesperson told Reuters that roughly 20 organizations have been affected by the UNC6040 campaign, which has been observed over the past several months. A subset of those organizations had data successfully exfiltrated, the spokesperson said.

A Salesforce spokesperson told Reuters in an email that “there’s no indication the issue described stems from any vulnerability inherent in our platform.” The spokesperson said the voice calls used to trick employees “are targeted social engineering scams designed to exploit gaps in individual users’ cybersecurity awareness and best practices.”

The spokesperson declined to share the specific number of affected customers, but said that Salesforce was “aware of only a small subset of affected customers,” and said it was “not a widespread issue.”

Salesforce warned customers of voice phishing, or “vishing,” attacks and of hackers abusing malicious, modified versions of Data Loader in a March 2025 blog post.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Streamline Your Workflow With This $30 Microsoft Office Professional Plus 2019 License

Trump reports more than $600 million in income from crypto, golf, licensing fees

Anne Wojcicki’s nonprofit wins bid to acquire genetic testing company 23andMe

You’re Only Three Weeks Away From Reaching International Clients, Partners, and Customers

Anti-Trump protests cap a week of free speech stress tests across America

Google, Meta and Snap think this tech is the next big thing

Just In

Streamline Your Workflow With This $30 Microsoft Office Professional Plus 2019 License

June 14, 2025

Trump reports more than $600 million in income from crypto, golf, licensing fees

June 14, 2025

Israel-Iran attacks and the 2 other things that drove the stock market this week

June 14, 2025

Trump says U.S. will have ‘golden share’ in U.S. Steel after Nippon deal

June 14, 2025

Anne Wojcicki’s nonprofit wins bid to acquire genetic testing company 23andMe

June 14, 2025

Top News

Guangzhou Plans to Fully Abolish “Three Restrictions” on Housing; Will Other First-Tier Cities Follow Suit?

June 14, 2025

You’re Only Three Weeks Away From Reaching International Clients, Partners, and Customers

June 14, 2025

How credit cycling works and why it’s risky

June 14, 2025
Facebook X (Twitter) Instagram
© 2025 Business Pro. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Contact

Type above and press Enter to search. Press Esc to cancel.