Back
Outfaze Security Team

Outfaze Security Team

Salesforce Vishing: Defending Connected App Access

Salesforce Vishing: Defending Connected App Access

In June 2025, Google Threat Intelligence Group described UNC6040 campaigns that used voice phishing to compromise Salesforce customer environments. Attackers impersonated IT support and guided users into authorizing malicious connected applications.

The activity did not depend on a Salesforce product vulnerability. It depended on a trusted conversation, legitimate administrative screens, broad OAuth permissions, and insufficient detection of large data access.

How a support call became cloud data access

The caller directed a user to the connected-app setup flow and obtained authorization for an attacker-controlled application. That grant enabled API access and large-scale data extraction; later extortion could occur well after the initial theft.

This attack path can bypass controls focused only on passwords. The user may authenticate normally while granting a malicious application durable access to data.

Govern connected apps like privileged accounts

Restrict who can authorize applications, require admin approval for sensitive scopes, and review existing grants. Monitor new apps, permission changes, unusual API clients, high-volume queries, bulk exports, and access from anonymizing infrastructure.

Help-desk verification should use a known channel and ticket, never caller-provided contact details. A reported vishing event should trigger session, token, application, data-access, and lateral-movement review.

  • Inventory OAuth applications and owners.
  • Limit broad API and offline-access scopes.
  • Alert on unusual bulk data activity.
  • Give staff a safe way to end and independently verify support calls.

Put the lesson into practice

  1. Review who can create or authorize connected apps.
  2. Remove unused grants and narrow remaining scopes.
  3. Enable relevant Salesforce audit and event telemetry.
  4. Rehearse vishing verification with IT and high-risk users.
  5. Create a response path for malicious OAuth authorization.

Related Outfaze guidance

Authoritative sources