During Salesforce Data Exfiltration, threat actors used API queries to automatically exfiltrate large volumes of data.3
campaign
Salesforce Data Exfiltration C0059
- First seen
- October 2004
- Last seen
- September 2025
- Created
- 22 October 2025
- Last modified
- 31 July 2026
The Salesforce Data Exfiltration campaign began in October 2024 with financially-motivated threat actor UNC6040 using Spearphishing Voice (vishing) to compromise corporate Salesforce instances for large-scale data theft and extortion. Following the initial data theft, victim organizations received extortion demands from a separate threat actor, UNC6240, who claimed to be the “ShinyHunters” group. The observed infrastructure and TTPs used during the Salesforce Data Exfiltration campaign overlap with those used by threat groups with suspected ties to the broader collective known as "The Com.” These overlaps could plausibly be the result of associated actors operating within the same communities and are not necessarily an indication of a direct operational relationship.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0059
During Salesforce Data Exfiltration, threat actors used voice calls to socially engineer victims into authorizing a modified version of the Salesforce Data Loader app.4
During Salesforce Data Exfiltration, threat actors used custom applications developed in python.5
During Salesforce Data Exfiltration, threat actors used compromised credentials for lateral movement.67
During Salesforce Data Exfiltration, threat actors queried customers' Salesforce environments to identify sensitive information for exfiltration.8
During Salesforce Data Exfiltration, threat actors used Mullvad VPN IPs to proxy voice phishing calls.9
Standing C0059
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
54th percentile · 54% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
77th percentile · 77% of 56 ATT&CK campaigns have this many tactics spanned or fewer.
45th percentile · 55% of 56 ATT&CK campaigns have more tools and malware.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
21st percentile · 79% of 56 ATT&CK campaigns have more detection rules per technique.
Detection coverage C0059
204 distinct rules cover the 18 techniques recorded for this campaign. The 206 technique-to-rule mappings resolve to 204 distinct rules, because one rule can cover several techniques. 151 Sigma · 53 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org