Securing the Orbital Frontier: Northrop Grumman and Aeronix Target Data Throughput
A new strategic partnership aims to overhaul space-based encryption hardware to support the high-speed data demands of modern military satellite networks.
A vishing campaign by UNC6040 is exploiting the human element to steal Salesforce data by impersonating IT support and tricking employees into installing malicious software. This sophisticated attack underscores the critical need for enhanced human-centric defenses and employee education to combat evolving social engineering threats.

In an era defined by impenetrable digital fortresses and sophisticated cyber defenses, the most enduring vulnerability often remains the simplest: the human element.
A new report from Google Threat Intelligence Group (GTIG) serves as a chilling reminder that no amount of technological wizardry can fully guard against the age-old art of deception, particularly when wielded by cunning adversaries who understand the power of a convincing voice and a fabricated sense of urgency.
For months now, a threat actor identified as UNC6040 has been orchestrating a pernicious vishing campaign across the West, targeting sectors as diverse as hospitality, retail, and education.
The modus operandi is disarmingly straightforward, yet devastatingly effective: a phone call, an impersonation of IT support, and a seemingly benign request.
Employees, often caught off guard and under pressure, are then coaxed into downloading a tainted version of Salesforce Data Loader, a critical client application used by administrators and developers to manage vast quantities of data within the Salesforce ecosystem.
It’s a masterful stroke of social engineering, preying on trust and the inherent desire to be helpful, especially to someone seemingly there to fix a problem.
The malicious software, once installed, acts as a digital Trojan horse, granting UNC6040 “significant capabilities” to access, query, and exfiltrate sensitive information directly from compromised Salesforce customer environments.
Imagine the sheer volume and sensitivity of data managed through Salesforce – customer records, sales figures, proprietary information.
Its compromise isn’t merely a data breach; it’s an organizational hemorrhage, potentially crippling operations and eroding trust with clients.
The insidious nature of this attack lies in its subtlety; there are no flashy ransomware demands upfront, no immediate system shutdowns.
Just a quiet, methodical siphoning of vital corporate intelligence.
Perhaps the most unsettling detail unearthed by Google’s researchers is the deliberate delay between the initial data theft and the subsequent extortion attempts.
Months, GTIG notes, can pass before the cybercriminals resurface, demanding payment for the safe return or non-publication of the stolen data.
This extended timeline fuels speculation that the operation might be segmented, with one group specializing in the clandestine art of data exfiltration and another handling the delicate, high-stakes negotiations.
It speaks to a level of organizational sophistication rarely attributed to lone wolf hackers, hinting instead at a burgeoning cybercrime-as-a-service model where specialized skills are outsourced and integrated into a larger, more complex criminal enterprise.
Indeed, UNC6040 has reportedly claimed affiliation with notorious groups like ShinyHunters and is believed to be part of “The Com,” a sprawling, loosely-connected collective of cybercriminals that counts infamous entities such as Scattered Spider among its ranks.
This ecosystem of interconnected digital outlaws represents a formidable challenge to corporate security.
They share tactics, tools, and potentially even stolen data, creating a hydra-headed threat that is difficult to track and even harder to dismantle.
The notion that a data theft operation might be executed by one cell, only for the spoils to be passed to a separate “negotiations” team, underscores the maturity and division of labor now present within these underground networks.
Crucially, Google’s analysis emphasizes a vital point that should resonate with every organization: no inherent vulnerabilities within Salesforce itself were exploited in this campaign.
This wasn’t a technical flaw in a software giant’s code; it was a human flaw, a momentary lapse in vigilance, a successful manipulation of an individual.
The attackers circumvented firewalls and intrusion detection systems not by hacking them, but by bypassing them entirely through the most direct route possible: the person answering the phone.
This distinction is paramount because it shifts the focus from purely technical solutions to human-centric defenses.
In a world where phishing, smishing, vishing, and even quishing (QR code phishing) are becoming increasingly sophisticated, the traditional concept of an IT perimeter is dissolving.
The new frontline is the individual employee, and their awareness is the ultimate firewall.
A well-trained employee, armed with skepticism and a clear understanding of social engineering tactics, is arguably more valuable than the most expensive cybersecurity software.
The power of vishing, as this campaign demonstrates, lies in its ability to circumvent automated defenses and exploit human psychology.
It leverages authority, creates urgency, and often catches individuals at moments when they are multitasking or simply not expecting a direct, personal attack.
This makes comprehensive employee education not merely a recommendation but an imperative.
Organizations must invest in continuous training that goes beyond generic cybersecurity awareness, delving into the nuances of these evolving social engineering threats, teaching employees to verify identities, question unusual requests, and understand the real-world implications of clicking a link or downloading an attachment, however innocuous it may seem.
Ultimately, the UNC6040 campaign serves as a stark, sobering lesson.
As technology advances, so too do the methods of those who seek to exploit it.
In this relentless digital arms race, the most potent weapon in a cybercriminal’s arsenal often isn’t a zero-day exploit or a sophisticated piece of malware, but the timeless art of persuasion.
Protecting our digital assets, it turns out, relies less on the strength of our code and more on the strength of our collective human vigilance.
A new strategic partnership aims to overhaul space-based encryption hardware to support the high-speed data demands of modern military satellite networks.
Commercial data networks have become a critical vulnerability for military personnel as foreign adversaries exploit real-time bidding for intelligence.
Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.