Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Fraudsters pretending to be IT professionals hacked the accounts of Adidas, Dior, and Google employees

Earlier this summer, Google announced that it had uncovered a hacking campaign that had compromised Salesforce customer accounts on a massive scale. It turned out that a number of well-known companies, including Google itself, were among the victims of the attackers. How the scammers' scheme worked.

Leave a comment
Fraudsters pretending to be IT professionals hacked the accounts of Adidas, Dior, and Google employees

Earlier this summer, Google announced that it had uncovered a hacking campaign that had compromised Salesforce customer accounts on a massive scale. It turned out that a number of well-known companies, including Google itself, were among the victims of the attackers. How the scammers' scheme worked.

As Ars Technica reports, the attackers operate in a very simple but effective way: They impersonate a customer’s IT department employee and simulate some kind of problem that requires immediate access to the account.

The series of hacking attacks is being carried out by attackers who are looking to steal data and sell it for extremely high prices. Instead of exploiting vulnerabilities in software or websites, they simply call the victim and ask for access. This tactic has proven to be extremely successful — among the companies whose Salesforce accounts were compromised in the attack are Adidas, Qantas, Allianz Life, Cisco and LVMH subsidiaries Louis Vuitton, Dior and Tiffany & Co.

How it works

Hackers are exploiting a Salesforce feature that allows customers to connect their accounts to third-party apps that integrate data with internal systems for blogging, mapping tools, and similar resources. The attackers contact employees and instruct them to connect an external app to their Salesforce account. When the employee follows the instructions, the attackers ask them to provide an eight-digit security code that the Salesforce interface requires before connecting. The attackers then use that number to gain access to the account and all the data stored in it.

Google said its Salesforce account was among those hacked. It happened back in June, but Google only announced it this week, likely because the company only recently learned about it.

«Analysis showed that the data was stolen by the attackers over a short period of time before access was interrupted,» the company said. The data stolen by the attackers was limited to business information such as company names and contact details, which Google said was already «largely publicly available.»

This attack is likely to have affected many companies that have not yet reported it. All Salesforce customers are advised to carefully review their instances to determine which external sources have access to them.

Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
Hackers are sending phishing emails disguised as subpoenas to Ukrainian government agencies and defense enterprises
Hackers are sending phishing emails disguised as subpoenas to Ukrainian government agencies and defense enterprises
On the topic
Hackers are sending phishing emails disguised as subpoenas to Ukrainian government agencies and defense enterprises
A well-known hacker group from Russia disguised itself as software from the Russian company Kaspersky to monitor foreign embassies in Moscow
A well-known hacker group from Russia disguised itself as software from the Russian company Kaspersky to monitor foreign embassies in Moscow
On the topic
A well-known hacker group from Russia disguised itself as software from the Russian company Kaspersky to monitor foreign embassies in Moscow
4chan hackers hacked Tea, a gossip app that was supposed to make dating safer for women. Over 100,000 images with personal information were leaked online
4chan hackers hacked Tea, a gossip app that was supposed to make dating safer for women. Over 100,000 images with personal information leaked online
On the topic
4chan hackers hacked Tea, a gossip app that was supposed to make dating safer for women. Over 100,000 images with personal information leaked online
Also Read
Головоломка киянина Quadline перемогла на фестивалі інді-ігор Google Play
Головоломка киянина Quadline перемогла на фестивалі інді-ігор Google Play
Головоломка киянина Quadline перемогла на фестивалі інді-ігор Google Play
Харківська художниця намалювала новий дудл для Google на День Незалежності України
Харківська художниця намалювала новий дудл для Google на День Незалежності України
Харківська художниця намалювала новий дудл для Google на День Незалежності України
Фахівців Google тепер годуватимуть роботи. Вони також уміють давати корисні (і не дуже) поради
Фахівців Google тепер годуватимуть роботи. Вони також уміють давати корисні (і не дуже) поради
Фахівців Google тепер годуватимуть роботи. Вони також уміють давати корисні (і не дуже) поради
Кінець епохи. Пошуковик Google більше не відповідатиме на безглузді запити
Кінець епохи. Пошуковик Google більше не відповідатиме на безглузді запити
Кінець епохи. Пошуковик Google більше не відповідатиме на безглузді запити

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.