Securing the Orbital Frontier: Northrop Grumman and Aeronix Target Data Throughput
A new strategic partnership aims to overhaul space-based encryption hardware to support the high-speed data demands of modern military satellite networks.

In the relentless cat-and-mouse game of cybersecurity, a new, disquieting twist on an old deception is proving remarkably effective, preying not on software vulnerabilities but on the very human instinct to trust.
This time, the target is the rich trove of confidential business data housed within Salesforce, and the weapon is as deceptively simple as a phone call.
Google’s Threat Intelligence Group recently pulled back the curtain on a sophisticated phishing campaign, revealing how cybercriminals are leveraging “vishing,” or voice phishing, to trick unsuspecting employees into handing over the keys to their company’s Salesforce records.
This isn’t about exploiting a flaw in Salesforce’s robust enterprise-grade security; it’s about exploiting a momentary lapse in judgment, a fleeting moment of misplaced compliance.
Imagine the scene: an employee receives a call, the caller ID perhaps spoofed, the voice on the other end calm, authoritative, claiming to be from IT support.
A sense of urgency is subtly conveyed, a technical issue needing immediate resolution.
The employee is then directed to what appears to be a legitimate Salesforce setup page, a seemingly innocuous step in a busy workday.
On this page, they are instructed to download and install an application called Salesforce Data Loader.
This is where the trap snaps shut.
The Salesforce Data Loader app is, in reality, a legitimate tool used by businesses to manage their Salesforce records – importing, exporting, and modifying data.
But the version offered on the criminals’ fabricated webpage is a Trojan horse, a malicious replica controlled by the attackers.
Once installed and connected, this rogue application grants the cybercriminals unfettered access.
They can query, export, and exfiltrate sensitive Salesforce records with alarming speed, often immediately after gaining access.
In some brazen instances, they even directly solicit user credentials and multi-factor authentication codes during the call, a testament to their audacity and the power of social engineering.
The group behind this cunning operation has been identified by Google as UNC6040, a name now etched into the growing lexicon of cyber threats.
Their specialty is voice phishing, a form of social engineering that bypasses many traditional email filters and relies on the immediacy and perceived authority of a live conversation.
What makes this campaign particularly insidious is its long game.
Data exfiltration might happen in minutes, but the actual extortion – the moment the victims realize the full, painful cost of their stolen data – often doesn’t materialize for several months.
This delay suggests a potential division of labor within the criminal underworld, where one group, like UNC6040, specializes in gaining initial access and data theft, while another takes on the role of monetization.
UNC6040 itself has even boasted of collaborating with the notorious hacking group ShinyHunters, amplifying the pressure on their victims to pay up.
Beyond UNC6040, Google’s researchers have observed a broader ecosystem of similar attacks, sharing distinct tactics, techniques, and procedures (TTPs).
These include the familiar IT support impersonation via vishing, a consistent focus on targeting Okta credentials, and a preference for English-speaking users within multinational corporations.
Google has dubbed this loose collective “The Com,” acknowledging that these shared methodologies could either signify direct collaboration or simply a common playbook adopted by various actors operating within the same shadowy communities.
The fact remains, the playbook is effective.
It bears repeating: the success of these attacks is not a failing of Salesforce’s technology.
As a spokesperson for Salesforce affirmed, “Salesforce has enterprise-grade security built into every part of our platform, and there’s no indication the issue described stems from any vulnerability inherent to our services.”
The vulnerability lies elsewhere – in the human element, in the inherent trust we place in a voice claiming authority, especially when that voice purports to solve a technical problem.
Despite countless warnings, company-wide training sessions, and endless reminders about the perils of phishing and vishing, scammers consistently find individuals who will take the bait.
It’s a sobering reminder that the most sophisticated firewalls and encryption protocols are only as strong as the human at the keyboard.
The psychological manipulation employed by groups like UNC6040 bypasses technical defenses, directly targeting our willingness to help, to comply, to resolve an issue quickly.
The ripple effect of such a breach extends far beyond Salesforce.
Armed with harvested credentials from a successful vishing attack, these criminals can move laterally through a network, pilfering data from other cloud-based platforms like Microsoft 365 and Okta, turning a single compromised employee into a gateway to an entire corporate ecosystem.
So, what’s the defense against such cunning?
Both Google and Salesforce offer critical guidance.
It begins with the principle of least privilege, ensuring users only have permissions essential for their roles.
Vigilant management of access to connected applications is paramount.
Enforcing multi-factor authentication (MFA) across the board, even for seemingly minor actions, adds a crucial layer of defense.
Limiting login access to a specific range of trusted IP addresses can act as a geographic fence.
Leveraging security tools available through Salesforce Shield and designating a specific security contact within the organization are also vital steps.
Ultimately, this ongoing battle against cybercriminals is a testament to their adaptability and our enduring human fallibility.
The latest Salesforce vishing scam serves as a stark, timely reminder that the most potent cybersecurity measure isn’t always a new piece of software; it’s a well-informed, perpetually skeptical employee.
In the digital age, vigilance isn’t just a best practice; it’s the first line of defense.
A new strategic partnership aims to overhaul space-based encryption hardware to support the high-speed data demands of modern military satellite networks.
Commercial data networks have become a critical vulnerability for military personnel as foreign adversaries exploit real-time bidding for intelligence.
Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.