WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) FBI Flash: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) FBI Flash: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion

TLP:CLEAR

Author: Chase Snow

Created: Thursday, September 18, 2025 - 15:01

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: The FBI has recently released a FLASH report to draw awareness and disseminate indicators of compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions. Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms.

Analyst Note: These financially motivated groups are primarily targeting Salesforce users with voice phishing (vishing) attacks, tricking employees into connecting malicious apps to their company accounts. The groups claiming responsibility for these attacks state that they are part of the ShinyHunters, Scattered Spider, and Lapsus$ extortion groups, and are now calling themselves “Scattered Lapsus$ Hunters.” ShinyHunters has recently claimed to have stolen 1.5 billion Salesforce records. These groups are tracked as UNC6040 and UNC6395 by Google.

Original Source: https://www.ic3.gov/CSA/2025/250912.pdf

Additional Reading:

  • FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups
  • ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
  • The Cost of a Call: From Voice Phishing to Data Extortion

Related WaterISAC PIRs: 6, 10, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar