FBI Issues Warning: Two Hacker Groups Launch Ransomware and Data Theft Attacks Against Salesforce Instances
The FBI issued an alert on Friday, warning that two hacker groups, UNC6040 and UNC6395, are attacking Salesforce instances. UNC6040 has been using vishing to obtain employee credentials since October 2024, while UNC6395 conducts supply chain attacks through compromised OAuth tokens from Salesloft Drift. Some victims have received ransom demands claiming to be from ShinyHunters.

The U.S. Federal Bureau of Investigation (FBI) issued a security alert on Friday warning that two hacker groups are targeting Salesforce instances for extortion and data theft. The alert provides indicators of compromise (IOCs) and additional protective guidance to help security teams determine if they have been attacked and prevent future incidents.
UNC6040: Voice phishing to obtain credentials
According to the FBI, a hacker group designated as UNC6040 gains access to target organizations' Salesforce accounts through voice phishing (vishing). Since October 2024, the group has used social engineering tactics to trick customer support personnel into handing over employee credentials.
Salesforce had previously issued a warning about such social engineering attacks in March of this year, and researchers from Google Threat Intelligence Group also issued an alert about UNC6040 in June.
UNC6395: Supply chain attack using OAuth tokens
Another group, UNC6395, relies on compromised OAuth tokens in Salesloft Drift, an AI chatbot integrated with Salesforce. Attackers steal data after compromising victims' Salesforce instances.
The FBI stated that as of the end of August, affected companies had revoked all active access and refreshed tokens, thereby preventing attackers from further accessing the Salesforce platform through Salesloft Drift. This supply chain attack could affect hundreds of organizations, and multiple security companies have disclosed that their customers may have been compromised.
Ransom demands linked to ShinyHunters
According to the FBI, some victims received ransom demands from hackers claiming to be ShinyHunters days to months after the data breach. Security researchers told Cybersecurity Dive, a sister publication of CFO Dive, that a threat group claiming ties to ShinyHunters, Scattered Spider, and Lapsus$ - which had previously claimed responsibility for hacks on high-profile targets such as Jaguar Land Rover - recently shut down its dark web site.
Jaguar Land Rover has not publicly discussed how hackers breached its systems, but has previously confirmed it is investigating the threat claims. Researchers suspect this is related to increased law enforcement activity, but it is unclear whether authorities have arrested any hackers. Experts also noted that attackers are more likely to rebrand under a different name rather than completely cease operations.
It remains unclear whether the attack on Jaguar Land Rover is related to the activities described in the FBI alert. The FBI did not respond to requests for comment.