cognitive cybersecurity intelligence

News and Analysis

Search

FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration

FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration

The Federal Bureau of Investigation (FBI) has released a flash alert detailing the activities of two cybercriminal groups, UNC6040 and UNC6395, that are actively compromising Salesforce environments to steal data for extortion purposes.

The advisory, published by the FBI on September 12, 2025, provides indicators of compromise (IOCs) and defensive measures to help organizations protect against these ongoing campaigns that leverage distinct tactics to achieve their objectives.

Here is the detailed coverage of Lessons from Salesforce/Salesloft Drift Data Breaches – Detailed Case Study.

UNC6040’s Social Engineering Campaign

Since at least October 2024, the group tracked as UNC6040 has been using social engineering, particularly voice phishing (vishing), to gain initial access.

The threat actors call an organization’s help desk, posing as IT support staff, attempting to resolve a fake technical issue. During these calls, they persuade employees to either share their credentials or grant the attackers access to the company’s Salesforce instance.

A key tactic involves tricking employees into authorizing a malicious “connected app” within the Salesforce portal. This app is often a modified version of the legitimate Salesforce Data Loader tool.

By convincing a user with sufficient privileges to approve the application, UNC6040 gains persistent access via OAuth tokens issued by Salesforce.

This method can bypass security controls like multi-factor authentication (MFA) and password resets, as the activity appears to originate from a trusted, integrated application.

The attackers then use API queries to exfiltrate large volumes of data. Following the data theft, some victims have received extortion emails from the notorious “ShinyHunters” group, demanding payment to prevent the public release of the stolen information.

UNC6395 Exploits Third-Party Integration

The second group, UNC6395, employed a different method to breach Salesforce instances. In August 2025, these actors exploited compromised OAuth tokens associated with the Salesloft Drift application, an AI-powered chatbot that integrates with Salesforce.

By using these compromised third-party tokens, the group was able to access and exfiltrate data from the victim’s Salesforce environment, highlighting the security risks posed by third-party application integrations.

In response to this campaign, Salesloft and Salesforce collaborated to revoke all active access and refresh tokens for the Drift application on August 20, 2025. This action successfully terminated the threat actors’ access to the compromised Salesforce platforms through this specific vector.250912.pdf

The FBI has released an extensive list of IOCs, including IP addresses, malicious URLs, and user-agent strings associated with both UNC6040 and UNC6395, to help network defenders detect and block related activity. The agency strongly recommends that organizations take several steps to mitigate the risk of compromise.

Of course, here is the table with the Indicators of Compromise, with the IP addresses formatted as requested.

UNC6040 Indicators of Compromise

IoC TypeIndicatorIP Address13.67.175[.]79IP Address20.190.130[.]40IP Address20.190.151[.]38IP Address20.190.157[.]160IP Address20.190.157[.]98IP Address23.145.40[.]165IP Address23.145.40[.]167IP Address23.145.40[.]99IP Address23.162.8[.]66IP Address23.234.69[.]167IP Address23.94.126[.]63IP Address31.58.169[.]85IP Address31.58.169[.]92IP Address31.58.169[.]96IP Address34.86.51[.]128IP Address35.186.181[.]1IP Address37.19.200[.]132IP Address37.19.200[.]141IP Address37.19.200[.]154IP Address37.19.200[.]167IP Address37.19.221[.]179IP Address38.22.104[.]226IP Address45.83.220[.]206IP Address51.89.240[.]10IP Address64.95.11[.]225IP Address64.95.84[.]159IP Address66.63.167[.]122IP Address67.217.228[.]216IP Address68.235.43[.]202IP Address68.235.46[.]22IP Address68.235.46[.]202IP Address68.235.46[.]151IP Address68.235.46[.]208IP Address68.63.167[.]122IP Address69.246.124[.]204IP Address72.5.42[.]72IP Address79.127.217[.]44IP Address83.147.52[.]41IP Address87.120.112[.]134IP Address94.156.167[.]237IP Address96.44.189[.]109IP Address96.44.191[.]141IP Address96.44.191[.]157IP Address104.223.118[.]62IP Address104.193.135[.]221IP Address141.98.252[.]189IP Address146.70.165[.]47IP Address146.70.168[.]239IP Address146.70.173[.]60IP Address146.70.185[.]47IP Address146.70.189[.]47IP Address146.70.189[.]111IP Address146.70.198[.]112IP Address146.70.211[.]55IP Address146.70.211[.]119IP Address146.70.211[.]183IP Address147.161.173[.]90IP Address149.22.81[.]201IP Address151.242.41[.]182IP Address151.242.58[.]76IP Address163.5.149[.]152IP Address185.141.119[.]136IP Address185.141.119[.]138IP Address185.141.119[.]151IP Address185.141.119[.]166IP Address185.141.119[.]168IP Address185.141.119[.]181IP Address185.141.119[.]184IP Address185.141.119[.]185IP Address185.209.199[.]56IP Address191.96.207[.]201IP Address192.198.82[.]235IP Address195.54.130[.]100IP Address196.251.83[.]162IP Address198.44.129[.]56IP Address198.44.129[.]88IP Address198.244.224[.]200IP Address198.54.130[.]100IP Address198.54.130[.]108IP Address198.54.133[.]123IP Address205.234.181[.]14IP Address206.217.206[.]14IP Address206.217.206[.]25IP Address206.217.206[.]26IP Address206.217.206[.]64IP Address206.217.206[.]84IP Address206.217.206[.]104IP Address206.217.206[.]124IP Address208.131.130[.]53IP Address208.131.130[.]71IP Address208.131.130[.]91URLLogin[.]salesforce[.]com/setup/connect?user_code=aKYF7V5NURLLogin.salesforce.com/setup/connect?user_code=8KCQGTVUURLhttps://help[victim][.]comURLhttps://login[.]salesforce[.]com/setup/connectURLhttp://64.95.11[.]112/hello.phpURL91.199.42.164/login

UNC6395 Indicators of Compromise

IoC TypeIndicatorIP Address208.68.36[.]90IP Address44.215.108[.]109IP Address154.41.95[.]2IP Address176.65.149[.]100IP Address179.43.159[.]198IP Address185.130.47[.]58IP Address185.207.107[.]130IP Address185.220.101[.]33IP Address185.220.101[.]133IP Address185.220.101[.]143IP Address185.220.101[.]164IP Address185.220.101[.]167IP Address185.220.101[.]169IP Address185.220.101[.]180IP Address185.220.101[.]185IP Address192.42.116[.]20IP Address192.42.116[.]179IP Address194.15.36[.]117IP Address195.47.238[.]83IP Address195.47.238[.]178User-AgentSalesforce-Multi-Org-Fetcher/1.0User-AgentSalesforce-CLI/1.0User-Agentpython-requests/2.32.4User-AgentPython/3.11 aiohttp/3.12.15

Key recommendations include training employees, especially call center staff, to recognize and report phishing and vishing attempts.

The FBI also advises enforcing phishing-resistant MFA across all possible services, applying the principle of least privilege to user accounts, and implementing strict IP-based access restrictions.

Furthermore, organizations should continuously monitor network logs and API usage for anomalous behavior indicative of data exfiltration and regularly review all third-party application integrations connected to their software platforms, rotating API keys and credentials frequently.

Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
The post FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts