Home Cyber Security

A Phone Call Is All It Takes: Hackers Target Salesforce Users in Vishing Scheme

Cybercriminals are making phone calls to corporate employees—and walking away with millions in stolen data.

Google Cloud’s security team has uncovered a new campaign by a hacker group known as UNC6040, which uses voice phishing—or “vishing”—to manipulate people into handing over access to powerful business software like Salesforce.

The attackers don’t need malware or zero-day exploits. Instead, they impersonate IT staff and convince employees to install what looks like a routine tool, called Data Loader. In reality, it’s a modified version designed to silently extract company data.

“Once the malicious app is connected, it’s game over,” said Google Threat Intelligence researchers. “The attackers can pull massive amounts of sensitive data directly from Salesforce.”

In some cases, the criminals lie low for months before demanding ransoms. They’ve even claimed ties to infamous groups like ShinyHunters to scare companies into paying up.

These scams are highly targeted, especially at staff in English-speaking offices of global firms. Once inside Salesforce, the attackers often pivot to other cloud platforms like Okta and Microsoft 365.

Google says companies need to take user training and app access seriously. Recommendations include stronger controls on app permissions, IP-based login rules, and broader use of multi-factor authentication (MFA).

It should be noted that no Salesforce systems are being exploited – merely the users who are tricked into thinking they are speaking to a legitimate source.

It’s a stark reminder: even the most secure systems can be breached when the weak link is human trust.