{"id":1922,"date":"2025-09-22T15:32:54","date_gmt":"2025-09-22T21:32:54","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/?p=1922"},"modified":"2025-10-02T21:15:31","modified_gmt":"2025-10-03T03:15:31","slug":"confederation-of-the-uncs-a-brief-look-into-a-series-of-the-salesforce-data-theft-exploit","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2025\/09\/22\/confederation-of-the-uncs-a-brief-look-into-a-series-of-the-salesforce-data-theft-exploit\/","title":{"rendered":"Confederation of the UNCs &#8211; A Brief Look into A Series of the Salesforce Data Theft Exploit"},"content":{"rendered":"\n<p class=\"has-small-font-size wp-block-paragraph\"><strong>CAUTION<\/strong>: This post is most-likely riddled with a prematurely conceived notion of someone who thinks they can fix cybersecurity for the defenders (<em>we have a lot of those, don\u2019t we?<\/em>), but hear me out and approach this from the point of view of someone who genuinely wants to work with another person (<em>and another person, and another person<\/em>) to discuss the very essence of cybersecurity, and how it <em>could<\/em> positively affect our daily lives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Overview<\/strong><\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">As you may already know, a lot of companies; multinational and small to medium companies alike; adopt the use of Customer Relationship Management Systems (CRMs) to interact with their end users and ultimately store customer data through these systems. Salesforce is a popularly adopted tool for most of them; so one can infer that a lot of companies use Salesforce, right? Right. <\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">In fact, according to an <a href=\"https:\/\/99firms.com\/research\/crm-statistics\/#gref:~:text=Salesforce%20has%20the%20biggest%20CRM%20software%20market%20share%20with%2019.8%25.\">August 2025 article<\/a>, Salesforce holds the largest CRM adoption in the market, for the seventh consecutive year, to a tune of 19.8% in the world, ahead of Oracle, SAP, Adobe and Microsoft. With these impressive stats, one would expect that they would be exempt from data thefts and exploits, right? Unfortunately, wrong. As we have seen so far from reading through our colleagues&#8217; blogposts, no one is immune from being hacked.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">This post will take a <em>really <\/em>brief look into a data theft that seems to have been targeted towards the CRM outfit of the company Salesforce and has affected several of their clients. I will also share my thoughts and recommendations based on research.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">To avoid boring you, I&#8217;ll keep my analysis to Salesforce and data privacy specifically so we don&#8217;t end up spending 20 years reading my post alone (looking forward to your comments &#8211; <em>hopefully praising me and telling me how I would end up carrying cybersecurity on my back, and how you revere my courage to sift through millions of articles to get here<\/em> &#8211; but I digress).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Super short Anatomy of the Breach \u2013 <\/strong><a href=\"https:\/\/www.seqrite.com\/blog\/google-salesforce-breach-unc6040-threat-research\/#:~:text=The%20attackers%20combined,actors%E2%80%99%20true%20location.\"><strong>an example<\/strong><\/a><strong> from the Google Exploit<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image is-style-default\"><img decoding=\"async\" width=\"2443\" height=\"2560\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-scaled.jpg\" alt=\"Photo via Unsplash: https:\/\/unsplash.com\/photos\/W4yclJTSPXc\" class=\"wp-image-1928 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-scaled.jpg 2443w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-286x300.jpg 286w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-977x1024.jpg 977w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-768x805.jpg 768w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-1466x1536.jpg 1466w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-1954x2048.jpg 1954w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/europeana-W4yclJTSPXc-unsplash-1568x1643.jpg 1568w\" data-sizes=\"(max-width: 2443px) 100vw, 2443px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 2443px; --smush-placeholder-aspect-ratio: 2443\/2560;\" \/><figcaption class=\"wp-element-caption\">An Anatomy tree from <a href=\"https:\/\/unsplash.com\/photos\/W4yclJTSPXc\">Unsplash<\/a> (May, 2024)<\/figcaption><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-small-font-size wp-block-paragraph\"><strong><a href=\"https:\/\/databreaches.net\/2025\/08\/08\/shinyhunters-sent-google-an-extortion-demand-shiny-comments-on-current-activities\/\">The Google breach<\/a><\/strong>&nbsp;became the highest-profile example of this method. In June 2025, attackers compromised a corporate Salesforce instance used to manage prospective Google Ads customer information. Attackers exposed approximately 2.55 million records, including business names, phone numbers, and sales follow-up notes. This is data with high value for phishing and fraud campaigns. Google stated that the data was largely public-facing and unrelated to Ads product systems, but the incident showed how attackers can weaponize even \u2018non-sensitive\u2019 CRM data once they exfiltrate it. GTIG confirmed the breach was part of the UNC6040\/ShinyHunters activity, with custom tools used to accelerate Salesforce data extraction.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">The attackers combined three core vectors:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\"><strong>Voice<\/strong><strong>\u2011phishing (vishing)<\/strong> \u2013 The IT staff was impersonated in a convincing phone call, persuading a Google employee to approve a malicious application connected to Salesforce, a rapid\u2011reply extortion scheme demanding Bitcoin payments within 72 hrs.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>OAuth app abuse<\/strong> \u2013 they then deployed custom Python scripts that emulated Salesforce\u2019s Data Loader, allowing automated bulk exports.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Anonymity layers<\/strong> \u2013 Mullvad VPN\u2011initiated calls followed by TOR\u2011based data exfiltration, which anonymized the actors\u2019 true location (SEQRITE Blog, 2025).<\/li>\n<\/ul>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">The group behind this exploit has been revealed to be the ShinyHunters, a.k.a the UNC6040, a.k.a UNC6240, UNC6395 or UNC5537 depending on the victim. That said, every victim has one thing in common: data theft via the CRM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Confirmed Salesforce CRM-related breaches in 2025 so far (<\/strong><a href=\"https:\/\/cloudprotection.withsecure.com\/blog\/salesforce-attacks-in-2025\/\"><strong>Source<\/strong><\/a><strong>)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\"><strong>Google<\/strong>: breach disclosed in August but traced to activity in June. Targeted Salesforce <strong>CRM<\/strong> instance used for prospective Google Ads customer data. Impacted records included basic business contact details and related sales notes for SMB customers.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Salesloft-Drift hack<\/strong>: Attackers stole OAuth tokens through the Drift integration, leading Salesforce to shut down all Salesloft connections. The stolen tokens were then used to pull data directly from Salesforce accounts. Confirmed victims include security companies like Zscaler, Palo Alto Networks, Proofpoint, Tenable, Qualys and Cloudflare.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Workday<\/strong>: July disclosure of a third-party <strong>CRM<\/strong> breach exposing business contact data (names, emails, phone numbers). While Salesforce was not named, the case reflects how attackers target high-value SaaS and identity data to enable further exploits.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Allianz Life:<\/strong> Similarly, a July breach via a third-party cloud <strong>CRM<\/strong> impacted 1.4 million customers. Tied to social engineering tactics seen in the Salesforce campaign.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>LVMH brands (Louis Vuitton, Dior, Tiffany &amp; Co.), Adidas<\/strong>: late July disclosures tied to the same Salesforce-focused campaign. (Court filings in the Qantas case referenced Salesforce objects like Accounts\/Contacts.)<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Chanel<\/strong>: activity detected July 25, disclosed Aug 4; personal contact data exposed; tied to the <strong>same wave of Salesforce data-theft extortion<\/strong>.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Farmers Insurance:<\/strong> May breach via a third-party database exposed data of 1.1 million customers (names, addresses, driver\u2019s license details, partial SSNs). Linked to the <strong>broader vishing campaign<\/strong>.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Coca-Cola (Middle East):<\/strong> disclosed May; data leak affecting ~1,000 employees in UAE, Oman, and Bahrain. Salesforce file access was reported to be <strong>part of the chain<\/strong>.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Coca-Cola Europacific Partners (CCEP):<\/strong> breach exposed over 23M Salesforce records (accounts, cases, contacts, products) via <strong>dashboards<\/strong>.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>UK retailers (M&amp;S, Co-op, Harrods):<\/strong> May ransomware\/data theft incidents; similar social-engineering and access-abuse tactics were observed.<\/li>\n\n\n\n<li class=\"has-small-font-size\"><strong>Aviation sector (Hawaiian Airlines, WestJet, KLM, Air France):<\/strong> targeted June\u2013July. While not confirmed as Salesforce compromises, the entry methods (help-desk manipulation, MFA bypass) mirror those used in <strong>CRM breaches<\/strong>.<\/li>\n<\/ul>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">This data theft exploit seems like a very targeted data theft campaign aimed at Salesforce\u2019s clients, who also mostly happen to be large companies that we all know; which begs the question (at least for me): why? Why does a company like Salesforce seem to be an easy target with a product that is very well known and majorly adopted for end user data management? <\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">The answer is straightforward: Salesforce is one of the biggest SaaS companies that handles sensitive customer information, and access to these kinds of data create a beautiful loop of &#8220;collecting&#8221; on royalties for adversaries. It&#8217;s been so bad this year that <a href=\"https:\/\/www.ic3.gov\/CSA\/2025\/250912.pdf\">the FBI has issued a FLASH alert<\/a> to companies alike so that they can tighten their systems against these kinds of attacks.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">When companies agree on what their security architecture looks like, they surely are not able to consider the level of security that their vendors&#8217; products have. Though they do their due diligence prior to doing business with these vendors, the onus is on both parties to determine the level of acceptable risk that the relationship would bring. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why is this considered a threat?<\/strong><\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">Since people make up an organization, they sometimes represent the entry point into gaining access to a company&#8217;s sensitive information or even proprietary products and these days, the lines are beginning to blur between people&#8217;s personal and corporate lives, whereas security is important for both.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">With social engineering still going strong (<em>and developing a very hard coconut head in the process<\/em>), people are sadly still the weakest link to security but also the most important component to the very thing that security stands for. For adversaries, there are lots of possibilities to selling people&#8217;s data. They could range from using these data to gain information for the purpose of laterally moving through a person&#8217;s life as if elevating privileges in a network, to even causing people to lose their lives in extremely dangerous ways.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">At the heart of this exploit is social engineering through voice phishing, and this would not have been possible without people at its helm. I certainly am not placing blame because these things can happen to anyone including me, but where do we go from here? Security training in companies is being adopted more, however what happens when people log out for the day? How does the company ensure that its assets doesn&#8217;t bleed through its defenses for an employee who also uses their personal phone for work, for example?<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">Seeing the alarming number of clients that have been affected by this theft, as well as the need to make sure that data is secure, I wonder if Salesforce has any plans in place to update the features of their CRM product to include the protection of data in some way, to prepare for a contingency like the event of a data theft.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"1024\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-1024x1024.jpg\" alt=\"\" class=\"wp-image-1936 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-1024x1024.jpg 1024w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-300x300.jpg 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-150x150.jpg 150w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-768x768.jpg 768w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-1536x1536.jpg 1536w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-2048x2048.jpg 2048w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-600x600.jpg 600w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/anastasiia-ornarin-WuziDcvdICY-unsplash-1568x1568.jpg 1568w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/1024;\" \/><figcaption class=\"wp-element-caption\">My best representation of how I feel about my &#8220;thoughts&#8221;. Also with many thanks Photo by&nbsp;<a href=\"https:\/\/unsplash.com\/@ornarin?utm_content=creditCopyText&amp;utm_medium=referral&amp;utm_source=unsplash\">Anastasiia Ornarin<\/a>&nbsp;via&nbsp;<a href=\"https:\/\/unsplash.com\/photos\/a-drawing-of-a-persons-shadow-with-a-yellow-object-in-the-middle-of-WuziDcvdICY?utm_content=creditCopyText&amp;utm_medium=referral&amp;utm_source=unsplash\">Unsplash<\/a> (September, 2023)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Thoughts on what a warped journey this is, its effect on privacy, and more thoughts from me<\/strong><\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">Cryptography embodies secrecy and secrecy is the big brother of privacy (at least that&#8217;s my own layman way of looking at it). We all have the right to choice when it comes to revealing anything about ourselves. I believe that everyone&#8217;s personal data is sensitive, and the utmost care should be applied when handling it. Revealing this data should be at our own discretion and approval, and whoever is protecting them should also do so with the highest priority in mind. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-large-font-size wp-block-paragraph\">Stealing or accessing a person&#8217;s information without permission is absolutely deplorable, and sadly, the way we feel about it is not strong enough to stop it.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">So I&#8217;m just here wondering if we should edit our defense strategy to include planning for contingencies. If after we literally build our defenses to be as formidable as Alcatraz, adversaries still gain access to our data and steal them, how do we make sure that the stolen data is totally unusable and we can picture them letting out a frustrated yell because all their plans turned to ashes? If the tables were turned, that&#8217;s how they&#8217;d like us to feel, right? Since adversaries are always looking to <em>break <\/em>our defenses, could we also look into sending them on journeys of <s>no return<\/s> endless frustrations?<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">To give a possibly naive and unsolicited opinion, perhaps Salesforce could improve their CRM product with an update that includes the ability hash or mask customer data as a form of <a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/defense-in-depth#:~:text=Defense%20in%20depth%20is%20a,cause%20of%20a%20security%20breach.\">defence-in-depth<\/a> or privacy preserving cryptography in their clients\u2019 adoption of the product? This new feature would support <a href=\"https:\/\/www.datasunrise.com\/knowledge-center\/dynamic-data-masking\/#:~:text=Dynamic%20data%20masking%20is%20a%20real%2Dtime%20technique,to%20unauthorized%20users%E2%80%94without%20modifying%20the%20source%20database.\">dynamic data masking<\/a> specifically. I&#8217;m being specific about the &#8216;dynamic&#8217; part because, while researching materials for this post, I stumbled upon a Salesforce community post where someone asked about Salesforce using static data masking for its CRM and the response was that they didn&#8217;t use it for live production environments since the original data would be affected. For this reason, they only made static data masking possible in a sandbox environment.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">The good thing about dynamic data masking is that it does ensure that the raw data is well preserved especially in a live production environment, by only showing masked results to unauthorized users. This may not sound like much, but it could be a good first step into creating a form of defence around storing customer data. Also, since Salesforce already uses dynamic data masking for their <a href=\"https:\/\/help.salesforce.com\/s\/articleView?id=data.c360_a_dynamic_data_masking_policies.htm&amp;type=5#:~:text=Data%20Cloud%20protects%20sensitive%20data%20by%20encrypting%20it%20at%20rest%2C%20which%20prevents%20unauthorized%20access%20even%20if%20the%20database%20is%20compromised.%20With%20dynamic%20data%20masking%2C%20authorized%20users%20can%20view%20the%20data%2C%20but%20sensitive%20data%20is%20masked%20to%20prevent%20them%20from%20seeing%20it%20in%20plaintext.\">Data Cloud product<\/a>, this update should be considered <em>possible<\/em> to implement, all things considered. <\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">Even though they may never get to see this post, I&#8217;m sending the Salesforce Team lots of great ideas to <em>hopefully <\/em>put a final end to this Campaign of the UNCs forever!<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"577\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/dan-nelson-ah-HeguOe9k-unsplash-1024x577.jpg\" alt=\"\" class=\"wp-image-1935 lazyload\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/577;width:756px;height:auto\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/dan-nelson-ah-HeguOe9k-unsplash-1024x577.jpg 1024w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/dan-nelson-ah-HeguOe9k-unsplash-300x169.jpg 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/dan-nelson-ah-HeguOe9k-unsplash-768x433.jpg 768w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/dan-nelson-ah-HeguOe9k-unsplash-1536x865.jpg 1536w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/dan-nelson-ah-HeguOe9k-unsplash-2048x1154.jpg 2048w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/dan-nelson-ah-HeguOe9k-unsplash-1568x883.jpg 1568w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><figcaption class=\"wp-element-caption\">Hoping for a brighter day with this picture. Sourced from&nbsp;<a href=\"https:\/\/unsplash.com\/@danny144?utm_content=creditCopyText&amp;utm_medium=referral&amp;utm_source=unsplash\">Dan Nelson<\/a>&nbsp;via&nbsp;<a href=\"https:\/\/unsplash.com\/photos\/black-iphone-5-beside-brown-framed-eyeglasses-and-black-iphone-5-c-ah-HeguOe9k?utm_content=creditCopyText&amp;utm_medium=referral&amp;utm_source=unsplash\">Unsplash<\/a> (March, 2020)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended Mitigations<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"has-small-font-size\">As this is company based, a good recommendation would be for companies to review how they store data, and tighten their data privacy policies both internally and in collaboration with their vendors<\/li>\n\n\n\n<li class=\"has-small-font-size\">Companies should regularly review accesses\/privileges to make sure that the principle of least privilege stays true in terms of Identity and Access<\/li>\n\n\n\n<li class=\"has-small-font-size\">Any Intrusion Detection approach should be combined with Intrusion Prevention to ensure rapid response and resolution of potential breaches<\/li>\n\n\n\n<li class=\"has-small-font-size\">Constant education does help, so security awareness training materials should be updated, revamped and refreshed for employee usage. A welcome addition to this would also be to have this content include maintaining security even outside the workplace<\/li>\n\n\n\n<li class=\"has-small-font-size\">Learn from other people&#8217;s incidents and yours, then use the knowledge to strengthen incident response processes. <\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Conclusion<\/strong><\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">No one is immune to privacy and security breaches, Cryptography can be that flavour to help defenses taste better, and I sincerely hope that someday soon, we can truly approach the word &#8220;security&#8221; with a lot of flair and success.<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><em>Thank you for making it this far. Your time is truly invaluable to me, and I wish you the highest of scores!<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>References:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Msmash. \u201cGoogle Suffers Data Breach in Ongoing Salesforce Data Theft Attacks\u201d. <em>SlashDot<\/em>, 6 August 2025. \u00a0https:\/\/tech.slashdot.org\/story\/25\/08\/06\/1556252\/google-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Abrams, Lawrence. \u201cGoogle suffers data breach in ongoing Salesforce data theft attacks\u201d. <em>BleepingComputer<\/em>, 6 August 2025. https:\/\/www.bleepingcomputer.com\/news\/security\/google-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jones, David. \u201cFBI warns about 2 campaigns targeting Salesforce instances\u201d. <em>Cybersecurity Dive<\/em>, 15 September 2025. https:\/\/www.cybersecuritydive.com\/news\/fbi-warns-campaigns-salesforce-instances\/760129\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cGoogle Salesforce Breach: A Deep dive into the chain and extent of the compromise\u201d. <em>Seqrite Blog<\/em>, 2 September 2025. https:\/\/www.seqrite.com\/blog\/google-salesforce-breach-unc6040-threat-research\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mustonen, Elisa. \u201cSalesforce attacks in 2025: Why cyber criminals are targeting Salesforce\u201d. <em>Cloud Protection for Salesforce<\/em>,14 September 2025.https:\/\/cloudprotection.withsecure.com\/blog\/salesforce-attacks-in-2025\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Arthur. \u201cGoogle Salesforce Hack: Causes, Risks and Your Next Steps\u201d. <em>Heydata<\/em>, 12 August 2025. https:\/\/heydata.eu\/en\/magazine\/google-salesforce-hack-shinyhunters-risks<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cDynamic Data Masking\u201d. <em>Data <\/em>Sunrise. https:\/\/www.datasunrise.com\/knowledge-center\/dynamic-data-masking\/#:~:text=Dynamic%20data%20masking%20is%20a%20real%2Dtime%20technique,to%20unauthorized%20users%E2%80%94without%20modifying%20the%20source%20database. Accessed 22 September 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gordon, Will. \u201cThe Importance of Data Privacy and Compliance\u201d. <em>Nutshell<\/em>, 10 July 2025. https:\/\/www.nutshell.com\/blog\/data-privacy-and-compliance#:~:text=When%20using%20a%20CRM%20to%20collect%20and,of%20customers%2C%20employees%2C%20and%20the%20business%20itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cDynamic Data Masking Policies in Data Cloud\u201d. <em>Salesforce<\/em>. https:\/\/help.salesforce.com\/s\/articleView?id=data.c360_a_dynamic_data_masking_policies.htm&amp;type=5#:~:text=Data%20Cloud%20protects%20sensitive%20data%20by%20encrypting%20it%20at%20rest%2C%20which%20prevents%20unauthorized%20access%20even%20if%20the%20database%20is%20compromised.%20With%20dynamic%20data%20masking%2C%20authorized%20users%20can%20view%20the%20data%2C%20but%20sensitive%20data%20is%20masked%20to%20prevent%20them%20from%20seeing%20it%20in%20plaintext. Accessed 22 September 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CAUTION: This post is most-likely riddled with a prematurely conceived notion of someone who thinks they can fix cybersecurity for the defenders (we have a lot of those, don\u2019t we?), but hear me out and approach this from the point of view of someone who genuinely wants to work with another person (and another person, &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2025\/09\/22\/confederation-of-the-uncs-a-brief-look-into-a-series-of-the-salesforce-data-theft-exploit\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Confederation of the UNCs &#8211; A Brief Look into A Series of the Salesforce Data Theft Exploit&#8221;<\/span><\/a><\/p>\n","protected":false},"author":724,"featured_media":1927,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[8,1],"tags":[21,6,55,37,28,54,57,11],"class_list":["post-1922","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-isec-601","category-uncategorized","tag-cryptography","tag-data-breach","tag-data-privacy","tag-hack","tag-isec601","tag-privacy","tag-salesforce","tag-security","entry"],"featured_image_src":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/flyd-zAhAUSdRLJ8-unsplash-600x400.jpg","featured_image_src_square":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/09\/flyd-zAhAUSdRLJ8-unsplash-600x600.jpg","author_info":{"display_name":"Dami Ogunnupebi","author_link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/author\/dami-ogunnupebi\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/users\/724"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/comments?post=1922"}],"version-history":[{"count":18,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1922\/revisions"}],"predecessor-version":[{"id":2040,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1922\/revisions\/2040"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media\/1927"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media?parent=1922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/categories?post=1922"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/tags?post=1922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}