A wave of data breaches affecting companies including Qantas, Allianz Life, LVMH and Adidas has been linked to the ShinyHunters, which uses voice phishing (vishing) attacks to steal data from Salesforce CRM.
See also: Salesforce Tableau flaws allow code execution

In June, Google's Threat Intelligence Group (GTIG) warned that cybercriminals codenamed UNC6040 were targeting Salesforce customers through social engineering.
In these attacks, the attackers pretend to be support technicians in phone calls to employees of the targeted companies, trying to convince them to visit the Salesforce Connected Apps settings page. There, they are asked to enter a “connection code,” which connects a malicious version of the Data Loader application (which uses OAuth) to the target’s Salesforce environment. In some cases, the Data Loader component was renamed “My Ticket Portal” to make it seem more convincing.
GTIG reports that these attacks were primarily carried out through vishing (voice phishing), but they also found that credentials and MFA codes were stolen through deceptive websites that pretended to be Okta login pages .
Around the same time period, many companies reported data breaches related to external customer service providers or cloud-based CRM systems.
See also: Allianz Life: Data breach affects customers
LVMH subsidiaries such as Louis Vuitton, Dior and Tiffany & Co. disclosed unauthorized access to databases with customer information, while Tiffany Korea informed its customers that attackers had breached a “supplier platform used to manage customer data.”

Adidas, Qantas and Allianz Life also reported breaches related to external systems, with Allianz confirming it was a third-party customer relationship management platform.
According to BleepingComputer, the Qantas data breach is also related to a third-party customer relationship management platform, but the company has not confirmed whether it was Salesforce. However, previous local media reports have suggested that the data was stolen from Qantas' Salesforce environment.
Additionally, court documents reveal that the cybercriminals targeted the “Accounts” and “Contacts” data tables, which are objects within Salesforce. While none of the companies have publicly named Salesforce, BleepingComputer confirms that they were all targets of the same campaign, as described by Google.
So far, the attacks have not resulted in public extortion or data leaks. However, BleepingComputer reports that the attackers are attempting to extort companies privately via email, posing as ShinyHunters.
See also: Hackers target Salesforce accounts in extortion attacks
It is estimated that, if the extortion attempts fail, the perpetrators will proceed to massively publicize the stolen data, following the same tactics they used in their previous attacks through Snowflake.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
