What Salesforce Organizations Need To Know About The Growing Vishing Threat From UNC6040
Varonis, Friday, July 25th, 2025
Learn about the vishing threat from UNC6040 targeting Salesforce environments and how to protect your organization from data breaches and extortion.
Google's Threat Intelligence Group (GTIG) has disclosed a financially motivated threat cluster, UNC6040, that specializes in voice phishing (vishing) campaigns designed to breach organizations' Salesforce environments for large-scale data theft and eventual extortion.
This is especially critical for Salesforce organizations because attackers like UNC6040 specifically target platforms storing vast amounts of sensitive customer and operational data. As a central hub for client information, sales pipelines, and business operations, Salesforce is both a valuable resource and an attractive target. A successful breach could result not only in data loss, but in regulatory consequences, reputational damage, and financial extortion. Understanding and defending against vishing threats is critical to safeguard the integrity of Salesforce environments and maintain trust with clients, partners, and stakeholders.