Google has disclosed a significant data breach involving one of its corporate Salesforce instances, compromising customer data tied to its Google Ads platform.
Google has not revealed the exact number of people impacted, but according to ShinyHunters, who spoke with Cyber Security News, the breach exposed around 2.5 million records (Approx). Whether some of these entries are duplicates is still unknown.
The incident, detected in June 2025, was perpetrated by a financially motivated threat group tracked as UNC6040, known for its advanced voice phishing (vishing) tactics.
Google notified GBHackers News that the completed email notifications to affected customers on August 8, 2025, following an initial announcement on August 5.
The breached Salesforce instance stored contact information and related notes for small and medium businesses using Google Ads. According to Google’s Threat Intelligence Group (GTIG), the stolen data included basic, largely publicly available business information, such as:
- Business names
- Contact details (e.g., email addresses, phone numbers)
- Related notes stored in the Salesforce instance
While Google has stated that the compromised data was limited in scope and primarily publicly accessible, the breach raises concerns due to the potential for this information to be used in subsequent extortion schemes.
The threat actor retrieved the data during a brief window before Google revoked access, though specific details on the volume of affected records were not disclosed.
According to a Cyber Security News report, ShinyHunters demanded 20 Bitcoins (approximately $2.3 million) from Google. However, the threat actor later claimed this was sent “for the lulz” rather than as a serious extortion attempt.
The Attack and Extortion Threats
The breach was executed by ShinyHunters, who also claim collaboration with threat actors associated with Scattered Spider, now referring to themselves collectively as “Sp1d3rHunters.”
This group is responsible for gaining initial access to targeted systems, enabling ShinyHunters to conduct data exfiltration from Salesforce environments.
The attackers used a modified version of Salesforce’s Data Loader application, authorized through sophisticated voice phishing (vishing) tactics where employees were deceived into approving a malicious connected app.
GTIG notes that the group has evolved its tactics, shifting to custom Python scripts and using Mullvad VPN IPs or TOR to mask their activities.
ShinyHunters has been linked to extortion efforts tracked as UNC6240, contacting victims via emails from addresses like shinycorp@tuta[.]com and shinygroup@tuta[.]com, demanding bitcoin payments within 72 hours.
GTIG warns that the group may escalate by launching a data leak site (DLS) to pressure victims, including those affected by the Google Ads breach.
Extortion attempts often occur months after the initial theft, suggesting collaboration with other actors to monetize stolen data.
The attack highlights UNC6040 refined methods, including the use of compromised accounts from unrelated organizations to register malicious apps and automated data collection via TOR.
GTIG also observed infrastructure overlaps with “The Com,” a loosely organized cybercrime collective, indicating potential shared tactics among associated actors targeting cloud platforms like Okta and Microsoft 365.
Google responded promptly, conducting an impact analysis and implementing mitigations to secure the affected Salesforce instance.
The company emphasizes that the breach stemmed from social engineering, not a vulnerability in Salesforce’s platform. To prevent similar incidents, GTIG recommends:
- Least Privilege Access: Restrict permissions for tools like Data Loader, particularly the “API Enabled” permission.
- Connected App Management: Implement allowlisting and restrict powerful permissions like “Customize Application” to trusted administrators.
- IP Restrictions: Define trusted IP ranges to block unauthorized access from VPNs or TOR.
- Salesforce Shield: Use transaction security policies and event monitoring to detect suspicious activities, such as large data downloads.
- Multi-Factor Authentication (MFA): Enforce MFA universally and educate users on social engineering tactics to prevent MFA bypass.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!





