Salesforce recently patched a vulnerability in its email services that was exploited by cyber attackers in targeted phishing attacks against high-value Facebook accounts. The attack was discovered by Guardio Labs, who found a zero-day vulnerability in Salesforce that allowed the attackers to send phishing emails using the company’s domain and infrastructure. This tactic granted the attackers the use of a trusted domain as the origin of their messages, providing them with an additional layer of credibility.
The vulnerability, dubbed “PhishForce” by the researchers, was present in Salesforce’s “email-to-case” feature. This feature allows users to create automatic processes to generate new case tickets based on incoming customer emails. The attackers utilized this feature to gain control of a Salesforce-generated email address and then created an inbound email address on salesforce.com. By setting this email address as an “organisation-wide” address, they were able to use it for outbound phishing emails.
The phishing emails, resembling messages from Meta Platforms (previously known as Facebook), were sent via the case.salesforce.com domain. The emails notified recipients of an account compromise and provided a link to a fake “support” page, where the attackers harvested user credentials.
Guardio alerted Salesforce about the vulnerability on June 28, prompting the company to quickly deploy a fix on July 28 to all Salesforce services and instances, closing the security loophole.
In response to the phishing attacks, Meta stated that it is investigating why their detections and mitigations for such attacks didn’t work. It’s worth noting that swift action was taken by Salesforce to address the issue and protect its users from further exploitation.


