What Salesforce Organizations Need to Know About the Growing Vishing Threat from UNC6040

Varonis’ analysis of UNC604’s vishing attacks on Salesforce shows how social engineering and API flaws are used to bypass MFA and steal CRM data. Threat actors abuse service accounts and phishing kits to impersonate users, exposing gaps in identity governance and monitoring. Varonis recommends anomaly detection, permission management, and real-time log analysis to stop these threats without disrupting sales.

Key Protection Strategies

  • Neutralize Social Engineering: Detect unusual login patterns
  • Secure API Access: Monitor high-risk integrations (OAuth abuse up 300% in 2024)
  • Right-Size Permissions: Revoke stale service account privileges
  • Threat Hunting: Correlate user behaviour with UNC604 TTPs

Fill in the details below and download your copy now and arm yourself with the tools for success!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Our recommendation

Subscribe to Insights2Content

Get the latest growth hacks and trends in your inbox

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
© 2024 Insights2Content All Rights Reserved.
Website Made by Kodewave