At OBT, we keep a close eye on global cybersecurity incidents to help our clients in the not-for-profit and business sectors understand emerging risks. One recent case that grabbed headlines was Google’s confirmation of a Salesforce breach in June 2025.
While Google was quick to clarify the scope and impact, this event offers important lessons for all organisations, regardless of size or industry.
What Happened
In June 2025, threat group UNC6040 accessed one of Google’s corporate Salesforce instances.
Exposed data included business contact information (names, email addresses, phone numbers, and internal notes) related to Google Ads customers, primarily small and medium businesses.
No passwords, payment details, or Gmail accounts were compromised.
By August 8, Google had notified all affected customers and contained the breach.
Despite these facts, media reports exaggerated the scale, with some outlets incorrectly claiming 2.5 billion Gmail users were at risk. Google strongly refuted this, confirming Gmail services remain secure.
Key Lessons for Australian NFPs & SMEs
1. “Non-Critical” Data Still Poses Risk
Even seemingly harmless contact details can fuel phishing, business scams, or extortion campaigns. Cybercriminals don’t always need passwords; sometimes an email and a phone number are enough.
2. Cloud Platforms Are Attractive Targets
Tools like Salesforce, Microsoft 365, and CRMs are gateways into critical data and workflows. Securing them requires:
Strict access controls
Regular monitoring and logging
Multi-factor authentication (MFA)
Governance policies for staff access
3. Incident Response and Transparency Builds Trust
Google’s quick customer notifications demonstrate best practice. In the NFP and SME sector, where trust is core to mission, rapid and clear communication is equally critical when incidents occur.
4. Don’t Rely on Headlines, Rely on Facts
Exaggerated media coverage around “mass Gmail breaches” shows how misinformation spreads quickly. Leaders should ensure they get updates directly from trusted security sources, not clickbait articles.
The OBT Perspective
This breach reminds us that cybersecurity resilience isn’t just about protecting the perimeter; it’s about recognising how attackers exploit even the smallest data points. For NFPs and purpose-driven organisations, the risks are heightened:
Many lack dedicated IT teams.
Donor and client data is highly sensitive.
Reputational damage from a breach can erode trust overnight.
At OBT, we work with organisations to strengthen identity, secure cloud platforms, and build incident response readiness. From Secure365® solutions to cyber awareness training, our goal is to help you avoid becoming the next headline.
Takeaways for Your Organisation
Review CRM and cloud access policies.
Train staff to spot and report phishing attempts.
Ensure MFA is enforced across all accounts.
Have an incident response plan, don’t wait until after an attack.
Summary Table
| Aspect | Insight |
|---|---|
| Breach Type | Salesforce data leak (June 2025) |
| Threat Actor | UNC6040 (voice-phishing group) |
| Data Exposed | Business contact info (emails, phone numbers, notes) |
| Myth Busted | No Gmail accounts breached, media misreports |
| Lesson for NFPs & SMEs | Secure CRM/cloud, treat all data as valuable, train staff |
At OBT, we help purpose-driven organisations build cybersecurity resilience so they can focus on impact, not incident response. If this case study has raised questions about your own organisation’s security posture, reach out; our team is here to help.



