Also known as: tracked as, UNC6040, UNC6240
UNC6395 targets a wide range of industries—including finance, telecommunications, education, government, manufacturing, and healthcare—across multiple countries such as the United Kingdom, Russia, China, Vietnam, Brazil, and the United States. The actor routinely exploits OAuth tokens issued to Salesforce organizations, either via open‑source credential scanners like TruffleHog or through compromised third‑party integrations such as Salesloft Drift, in order to gain read access to thousands of Salesforce instances. Once inside, UNC6395 deploys custom scripts that mimic the official Data Loader and utilizes modified browser extensions (e.g., AuraInspector) to expand its foothold across Experience Cloud environments. The group then performs large‑volume API queries to exfiltrate hundreds of millions of Salesforce records, often targeting sensitive items such as AWS access keys, Snowflake tokens, and user passwords. Beyond data theft, the actor employs voice‑based phishing (vishing) delivered over anonymizing networks like Mullvad VPN or Tor to coerce victims into authorizing malicious tools and credentials. It also issues extortion demands tied to potential public leaks of exfiltrated information, adding a ransomware component to its revenue model.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6395, also known as ShinyHunters, is a financially motivated threat actor that leverages OAuth token theft, misconfigured Salesforce Experience Cloud, and voice‑based phishing to exfiltrate massive volumes of data from over 700 organizations worldwide. Using legitimate API endpoints and custom Python scripts, the group harvests credentials such as AWS keys and Snowflake tokens, then threatens victims with extortion if their data is leaked. The actor’s operations combine supply‑chain compromise, lateral movement, and extortion tactics to maximize financial gain.
Goals & Targeting
UNC6395’s strategic objectives center on financial gain through the collection and monetization of high‑value identity and access data. By harvesting OAuth tokens, AWS keys, and other privileged credentials, the actor positions itself to facilitate credential stuffing, lateral movement, or direct financial theft in target organizations. The focus on large institutions across multiple sectors amplifies the potential payout while also creating significant reputational risk for victims.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6395 follows a multi‑stage, patient operational cadence that begins with supply‑chain compromise and token theft, followed by the deployment of malicious extensions or scripts within compromised Salesforce environments. The actor typically moves through three phases: first, credential collection via OAuth tokens; second, data discovery and bulk export using legitimate APIs; third, extortion messaging tied to potential leaks. Victim profiles skew toward large organizations with extensive Salesforce usage, but smaller institutions have also been observed. The group maintains operational opacity by deleting query jobs while leaving logs intact, thereby reducing forensic footprints yet preserving audit trails for analysis. Notable operations include an August 2025 incident that compromised 760 salesforce orgs and exfiltrated ~1.5 B records, a March 2026 attack on Experience Cloud using a custom AuraInspector scanner paired with a ransom demand, and repeated use of vishing over anonymized voice channels to coerce credential disclosure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information base is reasonably high in confidence regarding the actor’s financial motivation, use of OAuth token theft, and exploitation of Salesforce environments, as corroborated by multiple independent reports and technical analysis. However, gaps remain around precise attribution dates, full toolchain details outside publicly documented open‑source tools, and a comprehensive understanding of the actor’s internal structure or funding model. Additional evidence would strengthen confidence in the overall threat profile.
No campaigns linked yet.
No observed data linked yet.
26
Techniques
37
Tools
0
Campaigns
8
IOCs
0
Observed Data
11
Tactics