Motivation: Financial
Began as a database theft and resale actor and evolved toward SaaS-focused extortion, using vishing, credential harvesting, and SSO compromise to steal customer data from cloud and SaaS environments. Prolific and currently active.
Targeting: SaaS, Salesforce, customer databases. Related clusters include UNC6040, UNC6240, and UNC6661 in some reporting. Monetization: extortion and sale/resale of stolen data.
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.