Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Massive cyberattack against Salesforce users – global giants among victims

Salesforce Salesforce

A massive wave of sophisticated cyberattacks is targeting companies that use Salesforce – and the tech giant Google have now confirmed that they too have been affected.

Big brands affected

International companies that Dior, Allianz, Adidas, Chanel, Pandora, Qantas, Air France and KLM have been victimsNow Google has also revealed that one of their Salesforce databases, with contact information for small and medium-sized businesses, was compromised in June 2025.

A growing threat: UNC6040 & social engineering in focus

Google Threat Intelligence Group (GTIG) has identified the hacker group as UNC6040They use an advanced form of social engineering where employees call pretending to be IT support (voice phishing or “vishingDuring the call, they are tricked into installing a fake version of Salesforce Data Loader via an app connection, giving attackers extensive access to both Salesforce and other cloud services such as Octa and Microsoft 365.

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

The infrastructure of the attacks shares characteristics with the loosely organized cybercriminal network “The Com“.

Data exfiltration and extortion

Google reports that around 20 organizations have been affected, and in several cases data has been exfiltrated. In some breaches, data has been extracted in small amounts before the asset was demolished – in other cases, entire database tables have been downloaded.

In some cases, the extortions have not begun until several months after the breach — often with actors claiming to represent the notorious group. ShinyHunters, which increases the burden of blame on the victim.

Google and Salesforce respond

Google has rushed to analyze and restrict access to the database and finds that only publicly available company information was stolen, such as names and contact information — but no sensitive data.

Salesforce emphasizes that the attack did not occur through vulnerabilities in their platform but through targeted manipulation of users. They point out that only a limited number of customers were affected and advise companies against installing unknown connected apps or entering codes without verification.

Security experts' recommendations — what should organizations do?

To resist this form of attack urges experts to a combination of training, technical measures and regular monitoring:

MeasureDescription
Education and awareness-raisingEducate employees about the risks of vishing and connected apps—especially Salesforce administrators.
Limited app permissionsAssign “API Enabled” and permissions to add connected apps only to necessary and trusted administrators.
Whitelist and connection controlImplement processes for approval, allowlisting, and monitoring of connected third-party applications.
IP and MFA protectionImplement IP restrictions, block access via commercial VPNs (e.g. Mullvad), and require multi-factor authentication (MFA).
Monitoring and automatic responseUse Salesforce Shield to detect unusual downloads, create transaction-based security policies, and review logs for anomalies.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT