Campaign · all campaigns
Salesforce Data ExfiltrationC0059 unknown
aka Salesforce Data Exfiltration
Last updated: 2026-08-20
About this actor
The [Salesforce Data Exfiltration](https://attack.mitre.org/campaigns/C0059) campaign began in October 2024 with financially-motivated threat actor UNC6040 using [Spearphishing Voice](https://attack.mitre.org/techniques/T1598/004) (vishing) to compromise corporate Salesforce instances for large-scale data theft and extortion. Following the initial data theft, victim organizations received extortion demands from a separate threat actor, UNC6240, who claimed to be the “ShinyHunters” group. The observed infrastructure and TTPs used during the [Salesforce Data Exfiltration](https://attack.mitre.org/campaigns/C0059) campaign overlap with those used by threat groups with suspected ties to the broader collective known as "The Com.” These overlaps could plausibly be the result of associated actors operating within the same communities and are not necessarily an indication of a direct operational relationship.(Citation: FBI Salesforce Data Theft SEP 2025)(Citation: Google Salesforce JUN 2025)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 27 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1020Automated Exfiltration ↗T1036Masquerading ↗T1059Command and Scripting Interpreter ↗T1059.006Python ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1083File and Directory Discovery ↗T1090Proxy ↗T1090.003Multi-hop Proxy ↗T1213Data from Information Repositories ↗T1213.004Customer Relationship Management Software ↗T1567Exfiltration Over Web Service ↗T1585Establish Accounts ↗T1585.002Email Accounts ↗T1586Compromise Accounts ↗T1586.002Email Accounts ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1598Phishing for Information ↗T1598.004Spearphishing Voice ↗T1608Stage Capabilities ↗T1608.005Link Target ↗T1671Cloud Application Integration ↗T1684Social Engineering ↗T1684.001Impersonation ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
AC-3 | 10 / 27 | 37% |
CM-6 | 10 / 27 | 37% |
SI-4 | 10 / 27 | 37% |
CA-7 | 9 / 27 | 33% |
AC-2 | 8 / 27 | 30% |
AC-6 | 8 / 27 | 30% |
CM-7 | 7 / 27 | 26% |
AC-4 | 6 / 27 | 22% |
CM-2 | 6 / 27 | 22% |
SI-3 | 6 / 27 | 22% |
AC-5 | 5 / 27 | 19% |
CM-5 | 5 / 27 | 19% |
IA-2 | 5 / 27 | 19% |
SC-7 | 5 / 27 | 19% |
SI-10 | 5 / 27 | 19% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Star Blizzard 0.26
- Operation AkaiRyū 0.24
- Silent Librarian 0.21
- Contagious Interview 0.18
- Cinnamon Tempest 0.18