ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments — Threadlinqs Intelligence
As of 2026-07-26, ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments is a critical-severity supply chain threat attributed to ShinyHunters (UNC6040, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1711 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: ShinyHunters (UNC6040 · FINANCIAL
Two overlapping 2025 criminal campaigns compromised Salesforce environments at scale: UNC6040 used IT-support vishing calls to trick employees into authorizing a weaponized Salesforce Data Loader
This threat covers two technically distinct but operationally converging non-malware, identity-centric campaigns against the Salesforce SaaS ecosystem in 2025.
Campaign 1 -- UNC6040 (publicly reported by Google Threat Intelligence Group in June 2025): a financially motivated cluster specializing in voice phishing (vishing). Operators call English-speaking employees at multinational organizations, impersonate internal IT support, and talk the victim through authorizing a connected application in their company's Salesforce org. The group's signature technique abuses Salesforce's OAuth Device Flow: the attacker pre-configures a local instance of the (initially unmodified, later custom-built Python) Salesforce Data Loader tool, which generates an 8-character device code. The victim, believing they are completing an IT-support-directed setup step, is guided to Salesforce's legitimate device-verification page, enters the code, and authenticates -- silently issuing an OAuth access token to the attacker's Data Loader instance. The tool then listens for the successful authentication and begins slow, low-and-slow data exfiltration to avoid detection, later escalating to full-table exports once verified. UNC6040 also harvested credentials and MFA approvals directly during vishing calls for lateral movement into Okta and Microsoft 365. Google's own corporate Salesforce instance was compromised via this technique in June 2025. Extortion follow-up, tracked separately by Google as UNC6240, arrives weeks to months later via email/phone, demanding 4-20 BTC within 72 hours and invoking the ShinyHunters name.
Campaign 2 -- UNC6395: threat actors gained unauthorized access to Salesloft's GitHub organization between approximately March and June 2025, downloading private repository content as ZIP archives, adding a guest user, and conducting reconnaissance across both the Salesloft and Drift (Salesloft's AI-powered sales-engagement/chat product) application environments. This access was later used to pivot into Drift's AWS environment, where the actor obtained OAuth and refresh tokens issued for Drift's Salesforce, Google Workspace, Outlook, and other customer integrations. Beginning August 8, 2025 (confirmed exfiltration August 12-18), UNC6395 used the stolen Drift-Salesforce tokens to run systematic SOQL reconnaissance (COUNT() queries against Account, Opportunity, User, and Case objects) followed by bulk exports, specifically hunting exported data for AWS access keys (AKIA-prefixed), Snowflake tokens, plaintext passwords, and internal VPN/SSO URLs for follow-on access. The actor deleted its own Salesforce query jobs to reduce forensic visibility and routed exfiltration traffic through Tor exit nodes to complicate attribution. On August 9, compromised 'Drift Email' tokens were separately used to access a limited set of customer Google Workspace accounts. Salesloft and Salesforce revoked all Drift OAuth/refresh tokens and pulled Drift from the AppExchange on August 20, 2025; Google's Threat Intelligence Group published a public UNC6395 advisory on August 26, with scope expanded on August 28 to confirm impact beyond the core Salesforce integration.
Dozens of organizations across technology, cybersecurity, retail/luxury, insurance, aviation, and logistics sectors confirmed impact from the Drift token theft, including Cloudflare (104 exposed API tokens, rotated), Tenable, Palo Alto Networks, Zscaler, PagerDuty, SpyCloud, Proofpoint, Rubrik, Allianz Life, and Farmers Insurance. The FBI issued a FLASH/IC3 advisory (CSA-250912) on September 12, 2025 covering both clusters. In October 2025, a collective calling itself 'Scattered LAPSUS$ Hunters' -- claiming joint ShinyHunters, Scattered Spider, and Lapsus$ membership -- launched a Tor-hosted extortion/leak site listing over three dozen Salesforce victims (including Toyota, FedEx, Disney/Hulu, UPS, Adidas, Dior, Louis Vuitton, Chanel, Tiffany & Co., Cartier, Qantas, and Air France-KLM), demanding Sales
Target sectors: technology, cybersecurity, retail, luxury goods, insurance, aviation, logistics, automotive, entertainment, financial services
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1589, T1583, T1588, T1566, T1199, T1078, T1550, T1098, T1078, T1090