A group of financially motivated cyberscammers who specialize in Scattered-Spider-like fake IT support phone calls managed to trick employees at about 20 organizations into installing a modified version of Salesforce’s Data Loader that allows the criminals to steal sensitive data. From a report: Google Threat Intelligence Group (GTIG) tracks this crew as UNC6040, and in research published today said they specialize in voice-phishing campaigns targeting Salesforce instances for large-scale data theft and extortion.
These attacks began around the beginning of the year, GTIG principal threat analyst Austin Larsen told The Register. “Our current assessment indicates that a limited number of organizations were affected as part of this campaign, approximately 20,” he said. “We’ve seen UNC6040 targeting hospitality, retail, education and various other sectors in the Americas and Europe.” The criminals are really good at impersonating IT support personnel and convincing employees at English-speaking branches of multinational corporations into downloading a
Leave a Reply