UNC6395 is a threat group that has been attributed a widespread data theft campaign targeting Salesforce instances in August 2025 by exploiting compromised OAuth tokens for the Salesloft Drift application. "We are focused on the ongoing hardening of the Drift Application environment," the company said. "This process includes rotating credentials, temporarily disabling certain parts of the Drift application and strengthening security configurations. "UNC6040 threat actors have utilized phishing panels, directing victims to visit from their mobile phones or work computers during the social engineering calls," the FBI said. "After obtaining access, UNC6040 threat actors have then used API queries to exfiltrate large volumes of data in bulk."