Blog

A Disturbance in Salesforce: How Human Error Became Cybersecurity's Biggest Threat

The ShinyHunters cybergang is exploiting human error to breach Salesforce databases at major corporations. Learn how vishing attacks are bypassing technical security measures and what your company can do to protect itself.

In an increasingly technological world, cybersecurity is crucial to the success and survival of businesses big and small. As a result, an entire industry has emerged around cybersecurity, providing innovative ways to lock down corporate networks and stay one step ahead of the countless ill-intentioned bad actors trying to exploit them or shut them down. But a hacking campaign headed by a particular cybergang has been showing that these innovations do little to mitigate one of cybersecurity’s biggest threats: human error.

Since May, well-meaning employees from several big-name corporations have inadvertently let hackers from the ShinyHunters cybergang access Salesforce-based databases within their companies. Salesforce is a software company with a popular customer relations management (CRM) platform that many companies use, and ShinyHunters has singled their customers out in a campaign that’s claimed victims like Google, Adidas, Allianz Life, Chanel, Louis Vuitton, Workday, and many others. Few of these companies have actually confirmed it was their Salesforce-based databases that were breached, but investigations from reporters and researchers have led them to attribute these data breaches to the ShinyHunters’ campaign.

The Attackers’ Methods

According to a report from the Google Threat Intelligence Group, “The Cost of a Call: From Voice Phishing to Data Extortion”, ShinyHunters, or UNC6040 as these researchers call them, is “a financially motivated threat cluster that specializes in voice phishing (vishing) campaigns specifically designed to compromise organizations’ Salesforce instances for large-scale data theft and subsequent extortion”. This “vishing” involves operators of the gang impersonating IT workers to trick employees into authorizing a malicious connected app to their organization’s Salesforce portal: a modified version of Salesforce’s Data Loader. This authorization gives ShinyHunters’ hackers the ability to “access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments”.

Rather than currently engaging in public extortion attempts or data leaks with the information they steal, ShinyHunters is reportedly privately extorting their victims via email. However, according to reporting from Lawrence Abrams of the BleepingComputer news site, the ShinyHunters gang has confirmed to them that they “will perform a mass sale or leak of companies that do not pay a ransom in the future”, possibly by preparing a data leak site. Some of this data may already be publicly available, so it’s of little worth to the cybergang. But for the companies that have lost potentially more sensitive data, the pressure is on to pay before the gang finally decides to punish them.

What to Do

Salesforce has warned their customers to take measures against these hacks, such as employing MFA or their app Salesforce Shield, but as pointed out by the researchers at Google: “in all observed cases, attackers relied on manipulating end users, not exploiting any vulnerability inherent to Salesforce.” The error here can’t be patched by a corporation, because it’s not computers allowing hackers in with buggy code but well-meaning employees who lacked the training to recognize ShinyHunter’s scam.

Which means that if you want to protect your corporation from ShinyHunter’s tactics, you should start by providing better training to your employees. At Crimson Vista, we offer services such as SecurityHub through which we can provide better training and guidance for employees to deal with not just ShinyHunters, but any hacker or cybergang employing social engineering tactics to break into your network. Remember, cybersecurity isn’t just about technology and software, it’s a mindset that everyone in your company should have.

Key Takeaways

  • Human error remains the weakest link: Despite advanced security measures, social engineering attacks continue to be effective
  • Voice phishing (vishing) is evolving: Attackers are becoming more sophisticated in their impersonation techniques
  • Employee training is critical: Technical solutions alone cannot prevent attacks that exploit human psychology
  • Multi-factor authentication is essential: MFA provides an additional layer of security against unauthorized access
  • Incident response planning matters: Organizations should have plans in place for detecting and responding to potential breaches

How Crimson Vista Can Help

At Crimson Vista, we understand that cybersecurity is not just a technology problem—it’s a people problem. Our comprehensive approach includes:

  • SecurityHub: Training and guidance for employees to recognize and respond to social engineering attacks
  • Security awareness programs: Regular training sessions to keep your team updated on the latest threats
  • Incident response planning: Help your organization prepare for and respond to security incidents
  • Security audits: Identify vulnerabilities in your systems and processes before attackers do

Don’t wait until your organization becomes the next victim. Contact us today to learn how we can help strengthen your cybersecurity posture.

Sources

Continue

Keep reading.