Cyber criminals are currently trying to gain access to sensitive company data via sophisticated phone calls - this time focusing on users of the well-known sales platform Salesforce. The fraudsters are disguising themselves as support staff and feigning technical problems or security incidents in order to obtain access data or persuade them to install manipulated software.
Companies in the retail, catering and education sectors are at the centre of these attempts to deceive. According to security experts from Google, the perpetrators use tactics from so-called voice phishing - or vishing for short. The trick: the callers pretend to be IT staff and claim to be acting on behalf of a well-known hacker collective. Whether this is true is questionable - it is more likely that it is just intended to stir up fear.
Those affected report that either login data was stolen or modified applications were infiltrated after the conversations, which attackers use to extract data and sell it on later. According to Google, the scam has been running since March - dozens of companies may already be affected.
Salesforce has responded and is urgently advising users to secure their own infrastructure: only allow access to known IP addresses, manage authorisations consistently, activate multi-factor authentication and use the company's own security tools consistently. This is the only way to effectively contain the danger posed by this type of social engineering.
Source: https://www.onlinehaendler-news.de