financetom
Technology
financetom
/
Technology
/
Hackers abuse modified Salesforce app to steal data, extort companies, Google says
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Hackers abuse modified Salesforce app to steal data, extort companies, Google says
Jun 4, 2025 7:22 AM

By AJ Vicens

June 4 (Reuters) - Hackers are tricking employees at

companies in Europe and the Americas into installing a modified

version of a Salesforce ( CRM )-related app, allowing the hackers to

steal reams of data, gain access to other corporate cloud

services and extort those companies, Google said on Wednesday.

The hackers - tracked by the Google Threat Intelligence

Group as UNC6040 - have "proven particularly effective at

tricking employees" into installing a modified version of

Salesforce's ( CRM ) Data Loader, a proprietary tool used to bulk import

data into Salesforce ( CRM ) environments, the researchers said.

The hackers use voice calls to trick employees into visiting

a purported Salesforce ( CRM ) connected app setup page to approve the

unauthorized, modified version of the app, created by the

hackers to emulate Data Loader.

If the employee installs the app, the hackers gain

"significant capabilities to access, query, and exfiltrate

sensitive information directly from the compromised Salesforce ( CRM )

customer environments," the researchers said.

The access also frequently gives the hackers the ability to

move throughout a customer's network, enabling attacks on other

cloud services and internal corporate networks.

Technical infrastructure tied to the campaign shares

characteristics with suspected ties to the broader and loosely

organized ecosystem known as "The Com," known for small,

disparate groups engaging in cybercriminal and sometimes violent

activity, the researchers said.

A Google spokesperson did not share additional

details about how many companies have been targeted as part of

the campaign, which has been observed over the past several

months.

A Salesforce ( CRM ) spokesperson told Reuters in an email that

"there's no indication the issue described stems from any

vulnerability inherent in our platform." The spokesperson said

the voice calls used to trick employees "are targeted social

engineering scams designed to exploit gaps in individual users'

cybersecurity awareness and best practices."

The spokesperson declined to share the specific number

of affected customers, but said that Salesforce ( CRM ) was "aware of

only a small subset of affected customers," and said it was "not

a widespread issue."

Salesforce ( CRM ) warned customers of voice phishing, or "vishing,"

attacks and of hackers abusing malicious, modified versions of

Data Loader in a March 2025 blog post.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Japan considers new legislation to back advanced chipmaking
Japan considers new legislation to back advanced chipmaking
Jun 4, 2024
TOKYO, June 4 (Reuters) - Japan plans to look into legislation to support the commercial production of advanced semiconductors, a draft of this year's long-term economic policy plan seen by Reuters shows. The long-term roadmap, which is crafted each year as a key document highlighting the administration's policy priorities, is expected to be finalised around June 21. In order to...
Evaluating PTC: Insights From 7 Financial Analysts
Evaluating PTC: Insights From 7 Financial Analysts
Jun 4, 2024
Ratings for PTC were provided by 7 analysts in the past three months, showcasing a mix of bullish and bearish perspectives. In the table below, you'll find a summary of their recent ratings, revealing the shifting sentiments over the past 30 days and comparing them to the previous months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total Ratings 2 3...
Expert Outlook: Lattice Semiconductor Through The Eyes Of 9 Analysts
Expert Outlook: Lattice Semiconductor Through The Eyes Of 9 Analysts
Jun 4, 2024
9 analysts have expressed a variety of opinions on Lattice Semiconductor ( LSCC ) over the past quarter, offering a diverse set of opinions from bullish to bearish. The table below offers a condensed view of their recent ratings, showcasing the changing sentiments over the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat...
Deep Dive Into Procore Technologies Stock: Analyst Perspectives (8 Ratings)
Deep Dive Into Procore Technologies Stock: Analyst Perspectives (8 Ratings)
Jun 4, 2024
During the last three months, 8 analysts shared their evaluations of Procore Technologies ( PCOR ) , revealing diverse outlooks from bullish to bearish. Summarizing their recent assessments, the table below illustrates the evolving sentiments in the past 30 days and compares them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total Ratings 3 4 1 0...
Copyright 2023-2025 - www.financetom.com All Rights Reserved