← Back to list

SaaS Data Theft: How UNC3944, UNC6040, and UNC6395 Quietly Redefined Cloud Risk

SaaS “trust” is the new perimeter — and the spiders know it. 🕷️

Wes Young in AlphaHunt Converge · 2025-09-04 14:47 · 0 claps · 0.6 min read
#threat-intelligence #crm #ecrime #threat-actor #salesforce
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 CRM · Email & CRM 🔧 · Data Engineering

SaaS Data Theft: How UNC3944, UNC6040, and UNC6395 Quietly Redefined Cloud Risk

Just need your refresh token and a minute alone with your CRM..

Just need your refresh token and a minute alone with your CRM..

SaaS “trust” is the new perimeter — and the spiders know it. 🕷️

UNC6395 is siphoning CRM data via hijacked OAuth tokens (think Salesloft/Drift integrations), while Scattered Spider (#UNC3944) speed-runs help-desk vishing → hypervisor ransomware. Retail, aviation, insurance — on the menu. 🍽️

Do this now: inventory every connected app, tighten OAuth scopes/consent, and lock resets behind phishing-resistant MFA. What’s your biggest blind spot — OAuth sprawl, password resets, or neglected hypervisors?

Read the breakdown & subscribe:

https://blog.alphahunt.io/saas-data-theft-how-unc3944-unc6040-and-unc6395-quietly-redefined-cloud-risk

AlphaHunt #CyberSecurity #SaaS #OAuth #Ransomware


메타데이터
post_id
7ffa691638ef
slug
saas-data-theft-how-unc3944-unc6040-and-unc6395-quietly-redefined-cloud-risk-7ffa691638ef
url
https://medium.com/alphahunt-intelligence/saas-data-theft-how-unc3944-unc6040-and-unc6395-quietly-redefined-cloud-risk-7ffa691638ef
canonical_url
https://medium.com/alphahunt-intelligence/saas-data-theft-how-unc3944-unc6040-and-unc6395-quietly-redefined-cloud-risk-7ffa691638ef
author_url
https://medium.com/@barely3am
status
ok
fetched_at
2026-07-17 18:22:04