Threat Intelligence / Actor / UNC6040
UNC6040
As of 2026-07-14, UNC6040 is a threat actor tracked by Threadlinqs Intelligence across 8 threats spanning phishing, data breach, threat actor. ATT&CK coverage spans 86 techniques across 15 tactics in 8 of 8 tracked threats. Most-observed techniques: T1567 (Exfiltration Over Web Service), T1078 (Valid Accounts), T1213 (Data from Information Repositories).
ATT&CK techniques observed
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 8 of 8 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 7 of 8 tracked threats
- T1213 Data from Information Repositories — Collection — observed in 7 of 8 tracked threats
- T1530 Data from Cloud Storage — Collection — observed in 7 of 8 tracked threats
- T1566 Phishing — Initial Access — observed in 7 of 8 tracked threats
- T1657 Financial Theft — Impact — observed in 7 of 8 tracked threats
- T1199 Trusted Relationship — Initial Access — observed in 6 of 8 tracked threats
- T1528 Steal Application Access Token — Credential Access — observed in 6 of 8 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movement — observed in 6 of 8 tracked threats
- T1552 Unsecured Credentials — Credential Access — observed in 6 of 8 tracked threats
- T1588 Obtain Capabilities — Resource Development — observed in 6 of 8 tracked threats
- T1087 Account Discovery — Discovery — observed in 5 of 8 tracked threats
- T1537 Transfer Data to Cloud Account — Exfiltration — observed in 5 of 8 tracked threats
- T1580 Cloud Infrastructure Discovery — Discovery — observed in 5 of 8 tracked threats
- T1583 Acquire Infrastructure — Resource Development — observed in 5 of 8 tracked threats
Tracked threats
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access — HIGH
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted — HIGH
- ShinyHunters Leaks 5.1 Million Panera Bread Customer Records — HIGH
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass — HIGH
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks — HIGH
- Panera Bread Data Breach - 5.1 Million Accounts Exposed — MEDIUM
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft — HIGH
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →