BeyondMachines :verified:<p>Hackers breach Salesforce instances of major corporations through voice phishing</p><p>ShinyHunters gang is conducting a sophisticated voice phishing campaign targeting Salesforce CRM instances and has breached major corporations including Cisco, Google, Chanel, Pandora, KLM, and Air France. The attack is tricking employees into authorizing malicious OAuth applications.</p><p>**Always verify any urgent call from "IT" or anyone representing authority. The urgent call technique paired with pressure tactics and abuse of the ability of most users to grant access to apps is extremely dangerous.**<br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/attack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>attack</span></a> <a href="https://infosec.exchange/tags/activeattack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>activeattack</span></a><br><a href="https://beyondmachines.net/event_details/hackers-breach-salesforce-instances-of-major-corporations-through-voice-phishing-x-5-x-3-m/gD2P6Ple2L" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">beyondmachines.net/event_detai</span><span class="invisible">ls/hackers-breach-salesforce-instances-of-major-corporations-through-voice-phishing-x-5-x-3-m/gD2P6Ple2L</span></a></p>