Leadership1 distinct publisher3 min readUpdated
Mandiant's teardown of UNC3944 and UNC6040 puts one weak boundary at the center of both playbooks: a remote service desk that resets credentials for whoever sounds convincing.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
Mandiant has published a technical analysis of voice-based social engineering, written by Nick Guttilla, that treats the remote IT support channel as the attack surface rather than a footnote [1]. It matters because two separate financially motivated actors, with different end goals, both walk in through the same door [1].
The setup is structural, not accidental. The report argues that in-person interaction has diminished and that remote IT structures such as an outsourced service desk have normalized employees dealing with external or less familiar personnel, which expands the attack surface [2]. Mandiant says financially motivated actors have increasingly adopted vishing as a primary vector for initial access [3], and that the tactic works because it preys on trust and the desire to be helpful [13].
The two case studies diverge after entry. The cluster tracked as UNC3944, which overlaps with Scattered Spider, calls corporate service desks and impersonates employees to have credentials and multi-factor authentication methods reset [4]. That access is then used for SIM swapping, ransomware deployment, and data theft extortion [5]. UNC6040 runs a narrower play: its operators also impersonate IT support, but the objective is to get an employee to Salesforce's connected app page and authorize a malicious, actor-controlled version of the Data Loader application [6]. That single authorization enables large-scale exfiltration from the victim's Salesforce environment, followed by extortion [7]. Mandiant frames the difference as account takeover for broad network access versus targeted theft of CRM data [8].
The part that should concern operators is Mandiant's own red team record. Using these techniques against clients of varying sizes, the firm reports achieving administrative-level user impersonation, corporate network perimeter breaches, and sensitive data access [9], and says it has convinced multiple service desks to reset credentials and alter several forms of MFA [10]. A technique that reproduces across organizations of different sizes is not one badly run vendor; it is a defect in how identity is verified on a phone call [2].
No product purchase closes this. Mandiant's reconnaissance section notes that the volume of information an attacker can gather about culture, employees, policies, procedures, and technology directly shapes how mature a scenario can be made [12], and the listed inputs include network ranges and IP space, domains and subdomains, cloud and email infrastructure, internet-accessible and internal web applications, code repositories, and corporate phone number and email address formats [11]. Most of that cannot be un-published. The only durable control sits at the moment a caller asks for something.
Three checks are available without a budget cycle. First, whether the outsourced desk's contract and runbook specify what proof is required before a credential or MFA reset, given that Mandiant obtained both by phone [10]. Second, whether an MFA method can be changed at all on a single inbound voice call, which is the specific step UNC3944 asks for [4]. Third, whether an ordinary Salesforce user can authorize a connected app, because UNC6040's entire campaign depends on that permission existing [3]. Each is a policy decision an executive can make this quarter, and each is testable by calling your own service desk and seeing what it gives up.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Google Cloud's threat intelligence blog published a technical analysis of vishing threats attributed to Mandiant and written by Nick Guttilla.
The report states that the prevalence of in-person social interactions has diminished and that remote IT structures, such as an outsourced service desk, have normalized employees' engagement with external or less familiar personnel, introducing an expanded attack surface.
Mandiant states that financially motivated threat actors have increasingly adopted voice-based social engineering, or vishing, as a primary vector for initial access.
The cluster tracked as UNC3944, which overlaps with Scattered Spider, has operators who frequently call corporate service desks and impersonate employees to have credentials and multi-factor authentication methods reset.
Mandiant says UNC3944's access is then used for broader attacks including SIM swapping, ransomware deployment, and data theft extortion.
UNC6040 operators impersonate IT support with the specific goal of deceiving employees into navigating to Salesforce's connected app page and authorizing a malicious, actor-controlled version of the Data Loader application.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party analysis, single interested source
The cluster rests on one named-author vendor post with specific, internally consistent tradecraft detail (actor clusters, the Salesforce Data Loader consent abuse, an OSINT target inventory) and a first-party account of reproducing the attack in client engagements. Against that: no independent corroboration, no telemetry, no dated incidents, no indicators, and no counts behind the 'multiple service desks' claim, so most load-bearing statements are assertions by the party that also sells the remediation.
Active technique, unquantified scale
Adoption here is adoption of the attack technique. Two named financially motivated clusters are described as actively using vishing for initial access, and Mandiant reports reproducing the same service-desk and consent-abuse paths across multiple client engagements — real usage, not a lab concept. But nothing is quantified: no victim counts, no engagement counts, no dates, no success rates, and no evidence about how widely defenders have adopted countermeasures.
Slightly overstated breadth
The writing is technical and restrained rather than alarmist, and the described mechanisms are concrete. The mild positive gap comes from breadth asserted without numbers — 'clients of varying sizes', 'multiple service desks', 'increasingly adopted' — inside a post that also advertises the author's red team practice, plus the cluster framing that the help desk 'breaks cheaply' resting on that same unquantified self-report.
Vendor sells the detection and the remediation
The publisher is the commercial owner of the analysis: Mandiant/Google Cloud sells threat intelligence and red team assessments, and the post explicitly foregrounds Mandiant's own successful vishing engagements and how such simulations 'empowered organizations to proactively identify and resolve deficiencies'. That is a direct commercial pull toward emphasizing severity and breadth. It is disclosed rather than hidden, and the tradecraft content is useful independent of the pitch, which keeps this short of maximal.
Credible mechanism, thin corroboration
High confidence that the described techniques exist and work as described — the mechanics are specific, consistent with the named clusters' known tradecraft, and reproducible in principle. Lower confidence in scope and severity claims, which are single-source, self-reported, undated, and unquantified, and in the derived Salesforce configuration prerequisite, which the source does not address.
invest
Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea1 distinct publisher
build
Notion's agent stack is live, not slideware, and it only changes one of your decisions1 distinct publisher
build
A green build only proves your agent was consistent with itself1 distinct publisher
invest
Spark's $22M bet that the agent framework layer can stay independent1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026