UNC6040 Explained: The Voice-Phishing Crew That Tricked Google, Qantas — and Now McKesson

Hooded hacker holding a smartphone in a dark room, illustrating voice phishing attacks

Google’s own threat researchers were the first to name it. Now the name keeps popping up every time another big company admits its Salesforce data walked out the door. Here’s what UNC6040 actually is — and why a simple phone call has become one of the most effective hacking tools of 2025 and 2026.

The Call That Isn’t From IT

UNC6040’s playbook is embarrassingly simple, which is exactly why it works. It starts with a phone call. The caller claims to be IT support — professional, courteous, urgent — and walks the victim through Salesforce’s connected-app page to approve what looks like a routine data tool.

That tool is a modified version of Salesforce’s Data Loader, often disguised under innocent names like “My Ticket Portal.” One click of “approve,” and the attackers have OAuth tokens granting bulk query and export rights over the company’s CRM. Custom Python scripts then automate the exfiltration — quietly, through VPN and TOR infrastructure.

The sinister part: extortion often arrives months later. Google’s Threat Intelligence Group, which tracks the cluster as UNC6040, has said the group proved “particularly effective at tricking employees” — no Salesforce vulnerability required, just human trust.

The Name Soup: UNC6040, ShinyHunters, and The Com

Keeping the names straight matters, because they’re not the same thing. UNC6040 is the tracking designation Google assigned to the vishing cluster itself. Publicly, the activity is linked to ShinyHunters, the long-running financially motivated crew behind years of data-theft and extortion campaigns. The infrastructure overlaps with tactics from The Com, a loose collective of English-speaking cybercriminal groups — Reuters reported it “shares characteristics with suspected ties” to that broader ecosystem.

Google separately tracks the extortion phase as UNC6240, and a parallel campaign that hit Salesforce integrations via the Salesloft Drift OAuth compromise as UNC6395. Same neighborhood, different addresses — which is why Mandiant has stressed the clusters are tracked separately.

When Google Got Got

The story turned heads because the hunters hit the hunter’s own house. In June 2025, Google disclosed that one of its own corporate Salesforce instances — used for small and medium business contact data — was compromised by UNC6040 activity. The company said the data taken was confined to “basic and largely publicly available business information,” retrieved during a short window before access was cut off.

The victim list grew from there: Qantas, Allianz Life, Chanel, AT&T, Cisco, Pandora, Adidas, Santander, and others across retail, hospitality, and education. Salesforce’s response was consistent throughout: there’s “no indication” the campaign stems from any vulnerability in its platform — it’s social engineering, full stop.

Why McKesson Put It Back in the News

The latest headline belongs to McKesson, the U.S. pharmaceutical distribution giant. In late August 2026, the company confirmed hackers broke into several of its cloud-hosted accounts and exfiltrated data from its oncology, multispecialty, and medical-surgical units. TechCrunch reports that ShinyHunters took credit, saying it tricked several McKesson employees into granting access through phishing and social engineering — the same opening move UNC6040 is known for — and shared a data sample TechCrunch verified against public records.

The group’s headline claim of 284 million records remains an attacker claim, measured in database rows rather than unique people, which McKesson has not confirmed. But the pattern — a phone call, a Salesforce foothold, data pulled from cloud environments — is unmistakably the UNC6040 playbook.

Why This Matters

Here’s the angle the breach headlines miss: while the AI industry obsesses over securing frontier models, the most consequential Salesforce data-theft campaign of the last two years ran on a telephone. No zero-day, no AI agent — just a convincing voice, an OAuth consent screen, and helpful employees doing what helpful people do.

The fixes Google, the FBI, and Salesforce keep repeating aren’t exotic: restrict who can install connected apps, enforce phishing-resistant MFA (not SMS or voice codes), limit API privileges, and train help-desk staff to verify callers. UNC6040 proves that the cheapest exploit in the catalog — trust — still defeats the most expensive security stack money can buy.

Meanwhile in AI Tech: Anthropic’s $11.6B Akamai deal | OpenAI’s GPT-6 Sol and Luna price war

Written by
Ryan covers artificial intelligence and enterprise tech — from foundation models and AI chips to the business of machine intelligence. He tracks model releases, funding rounds, and the policy moves shaping the AI industry.