Desk live·
ForensicPost
Breaches/Identity/File 26-0619

The Company That Named the Technique Was Also Hit by It

Google confirmed one of its own corporate Salesforce instances was accessed, with largely public business contact data taken before the access was cut. The disclosure is more useful than the incident.

Constructed geometry · not a chart of case data
TargetGoogle (corporate CRM)
ActorUNC6040
D. Kennedy8 min readConfidence: high2 sources reviewed

Google confirmed that one of its own corporate Salesforce instances was accessed in the campaign its threat intelligence team tracks as UNC6040, with the attackers taking largely public business contact data before access was terminated.

By the numbers this is a minor incident. It is in our database because of what the company did with it.

Publishing Your Own Compromise Is Rare And Useful

An organisation that both researches a campaign and is caught by it has an obvious incentive to keep those facts apart. Disclosing the second alongside the first invites the easy commentary, and Google published anyway.

The value to everyone else is specific. A defender reading the research now knows the technique works against an organisation with excellent detection, mature identity controls and the team that named the cluster. That removes the most common dismissal — that a technique only lands on the unsophisticated.

Two Things Went Right

The data reached was largely public business contact information, and access was terminated rather than persisting for months. The first is a data-minimisation outcome; the second is a detection outcome.

Both are worth stating because coverage of this campaign is dominated by eight-figure record counts. The same technique, against an organisation that limited what the platform held and noticed quickly, produced a footnote.

How we reported this

Compiled from public reporting and the company’s own threat intelligence publications, listed below. Corrections: corrections@forensicpost.com.

Sources
  1. How Google, Adidas, and more were breached in a Salesforce scamMalwarebytes
  2. Salesforce data theft roundup: everything you need to knowSalesforce Ben
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary