Tier-3 warns after Salesforce.com’s database is phished

1 min read

Manufacturers are being told they should install behavioural analysis software on their web security systems, following Salesforce.com’s exposure to a phishing scam.

“Salesforce.com is a successful business software provider that was recently the victim of a series of targeted phishing attacks,” explains behavioural analysis software firm Tier-3’s CTO, Geoff Sweeney. “Unfortunately, one of the company’s employees appears to have fallen for the phishing emails and inadvertently handed over access to the firm’s customer database.” Sweeney says that the incident resulted in Salesforce.com having to send an explanatory email to almost a million customers this week, asking them to be vigilant against bogus emailed invoices that appear to come from the company. “As if that wasn’t bad enough, Salesforce.com has reportedly tracked a second wave of forged emails that contain malware. The fact that the emails are addressed to specific customers and purport to come from Salesforce.com means that the chances of a customer’s PC being infected are quite high,” adds Sweeney. “This is a classic situation where popularly deployed security technologies can’t be relied upon to protect organisations against these types of threats. If the companies concerned have real-time behavioural analysis software installed on their systems, even if they open the bogus emails, any unauthorised interactions with their PC, including the installation of Trojans other malware and data leakage, could have been locked down,” he says.