Motivation: Financial extortion, data sale
A prolific data theft and extortion group that began as a database theft and resale actor and evolved toward SaaS-focused extortion. Recent activity involves vishing, credential harvesting, SSO compromise, and theft of customer data from cloud and SaaS environments.
Actor class: data theft/extortion. Targeting: SaaS, Salesforce, customer databases. Related clusters include UNC6040, UNC6240, and UNC6661 in some reporting.
Confirmed data theft/extortion actor.
Attribution and profile draw on public threat-intelligence reporting. Primary source →
Check your exposure privately, or get a tailored exposure audit.