The U.S. Federal Bureau of Investigation (FBI) issued a security alert on Friday warning that two hacker groups are targeting Salesforce instances for extortion and data theft. The alert provides indicators of compromise (IOCs) and additional protective guidance to help security teams determine if they have been attacked and prevent future incidents.

UNC6040: Voice phishing to obtain credentials

According to the FBI, a hacker group designated as UNC6040 gains access to target organizations' Salesforce accounts through voice phishing (vishing). Since October 2024, the group has used social engineering tactics to trick customer support personnel into handing over employee credentials.

Salesforce had previously issued a warning about such social engineering attacks in March of this year, and researchers from Google Threat Intelligence Group also issued an alert about UNC6040 in June.

UNC6395: Supply chain attack using OAuth tokens

Another group, UNC6395, relies on compromised OAuth tokens in Salesloft Drift, an AI chatbot integrated with Salesforce. Attackers steal data after compromising victims' Salesforce instances.

The FBI stated that as of the end of August, affected companies had revoked all active access and refreshed tokens, thereby preventing attackers from further accessing the Salesforce platform through Salesloft Drift. This supply chain attack could affect hundreds of organizations, and multiple security companies have disclosed that their customers may have been compromised.

Ransom demands linked to ShinyHunters

According to the FBI, some victims received ransom demands from hackers claiming to be ShinyHunters days to months after the data breach. Security researchers told Cybersecurity Dive, a sister publication of CFO Dive, that a threat group claiming ties to ShinyHunters, Scattered Spider, and Lapsus$ - which had previously claimed responsibility for hacks on high-profile targets such as Jaguar Land Rover - recently shut down its dark web site.

Jaguar Land Rover has not publicly discussed how hackers breached its systems, but has previously confirmed it is investigating the threat claims. Researchers suspect this is related to increased law enforcement activity, but it is unclear whether authorities have arrested any hackers. Experts also noted that attackers are more likely to rebrand under a different name rather than completely cease operations.

It remains unclear whether the attack on Jaguar Land Rover is related to the activities described in the FBI alert. The FBI did not respond to requests for comment.