Google confirmed that one of its own corporate Salesforce instances was accessed in the campaign its threat intelligence team tracks as UNC6040, with the attackers taking largely public business contact data before access was terminated.
By the numbers this is a minor incident. It is in our database because of what the company did with it.
Publishing Your Own Compromise Is Rare And Useful
An organisation that both researches a campaign and is caught by it has an obvious incentive to keep those facts apart. Disclosing the second alongside the first invites the easy commentary, and Google published anyway.
The value to everyone else is specific. A defender reading the research now knows the technique works against an organisation with excellent detection, mature identity controls and the team that named the cluster. That removes the most common dismissal — that a technique only lands on the unsophisticated.
Two Things Went Right
The data reached was largely public business contact information, and access was terminated rather than persisting for months. The first is a data-minimisation outcome; the second is a detection outcome.
Both are worth stating because coverage of this campaign is dominated by eight-figure record counts. The same technique, against an organisation that limited what the platform held and noticed quickly, produced a footnote.
Compiled from public reporting and the company’s own threat intelligence publications, listed below. Corrections: corrections@forensicpost.com.