URL PROTECTION | SALESFORCE ANTI-PHISHING | URL SCANNING
Stop phishing attacks on Salesforce
Links shared in Salesforce aren’t always what they seem – and are not scanned by Salesforce for threats. You can’t expect every user to know the difference. WithSecure Cloud Protection for Salesforce scans URLs for threats in real time.
Scans URLs at post and click
From short links to new domains

Salesforce is an entry point for phishing attacks
1
A phishing email with a malicious link enters Salesforce.
2
A user opens the message and clicks the link.
3
The site captures their login and MFA token.
4
Attackers use the credentials to access connected systems.
5
Attackers move laterally, exfiltrating data and disrupting services.

Why phishing links thrive inside Salesforce
Phishing is still the number one attack method, but it’s no longer limited to email. Attackers now use Salesforce as a trusted delivery channel.
Users assume links in Salesforce are safe.
Malicious URLs hide inside files, fields, case comments, or agentic AI chats.
Shortened and newly registered domains mask their real destinations.
AI tools create convincing phishing pages in seconds.
Our detection telemetry shows around 1% of all URLs in enterprise Salesforce orgs are malicious.
Native anti-phishing for Salesforce
WithSecure™ Cloud Protection for Salesforce scans URLs the moment they’re posted, and again when clicked. Your users never reach a phishing site, even if the link was safe at upload but weaponized later.
Coverage includes:
URLs in records, files, cases, emails, and custom objects.
Shortened links that disguise their true destinations.
Newly registered domains, often used for phishing.
Filtering unwanted content categories such as gambling or inappropriate sites.

Advanced URL-based threat protection for your Salesforce
Real-time scanning
URLs are scanned the moment they’re posted or clicked, blocking phishing sites before users can reach them.
Short link unmasking
Detects and blocks phishing links hidden behind shortened URLs — even inside QR codes.
New domain detection
Blocks access to suspicious domains based on age, filtering out newly registered sites often used in phishing.
Standard + custom object coverage
Scans URLs across both Salesforce standard and custom objects – and even Agentforce workflows.
Native anti-phishing for Salesforce
WithSecure™ Cloud Protection for Salesforce scans URLs the moment they’re posted, and again when clicked. Your users never reach a phishing site, even if the link was safe at upload but weaponized later.
Coverage includes:
URLs in records, files, cases, emails, and custom objects.
Shortened links that disguise their true destinations.
Newly registered domains, often used for phishing.
Filtering unwanted content categories such as gambling or inappropriate sites.

Frequently asked questions
What is URL Protection?
URL Protection is a feature of WithSecure Cloud Protection for Salesforce. It scans links across Salesforce environments for threats — including Sales Cloud, Service Cloud, Experience Cloud, and Agentforce — as well as in both standard and custom objects.
It blocks access to malicious or disallowed websites in real time, whether links appear in records, cases, community portals, chats, or automations. Protection works both when a link is first posted and again at the moment a user clicks it, ensuring newly weaponized malicious sites are caught.
It blocks phishing links and detects even sophisticated threats like newly registered domains and malicious destinations hidden with link shortenern (e.g. bit.ly, tinyurl).
(Note: Links hidden inside files or QR codes are scanned under the File Protection feature.)
Isn’t email security enough to stop phishing?
No. Email filters only protect inboxes. Once a link enters Salesforce — through a record, case comment, file, or portal — email security no longer applies. Attackers know this and deliberately target Salesforce because those blind spots are often unprotected.
What kinds of malware risks can come from URLs in Salesforce?
A single click can launch credential stealer malware, ransomware, or other malicious software. Some threats don’t even require clicks — “drive-by” downloads can trigger just by visiting a compromised page. Inside Salesforce, every file or link interaction can become a potential infection point if URLs aren’t inspected. Blocking sophisticated threats like newly registered domains and masked malicious short links is critical in phishing prevention.
Where can attackers place malicious URLs inside Salesforce?
Almost anywhere users can post or upload content: custom fields, standard objects and fields, case comments, community forums, email-to-case, web-to-case forms – or even Agentforce chats and workflows. These open text areas are often visible to external users. That makes Salesforce attractive as a distribution channel — attackers can reach employees through the same workflows you use to serve customers and partners. Because Salesforce integrates with so many business-critical systems, attackers use it as a distribution hub — one malicious link can spread risk into Microsoft 365, ERP, or service platforms.
Why isn’t basic URL detection enough?
Because the status of a URL can change quickly. A legitimate site today could be hijacked tomorrow. Attackers also use tricks like shortened links, freshly registered domains, or even AI-generated phishing kits to evade filters. That’s why time-of-click protection is critical: it evaluates the link as users access it, not just when it first appears.
How common are phishing threats in Salesforce?
Phishing remains the top cyberattack vector. IBM reports that 41% of attacks involve phishing, and 26% of those target public-facing applications like Salesforce. WithSecure telemetry shows that about 1% of all URLs scanned in enterprise Salesforce orgs are malicious. That may sound small, but at scale it represents thousands of dangerous links entering business workflows in an average Salesforce org in a matter of weeks. Salesforce itself has issued advisories highlighting phishing as a cyber risk.
We already train our users to spot phishing. Isn’t that enough?
Training helps reduce risk, but even experienced and knowledgeable people can be fooled. Attackers design phishing campaigns to look convincing and catch users off guard. Awareness is important, but security must step in when human error happens. Protecting users before they click is the responsible step.
We’ve never had a phishing problem in Salesforce. Why act now?
Phishing inside Salesforce often goes unnoticed until it causes (visible) damage. Recent CRM and SaaS related incidents show how quickly attackers can steal credentials and pivot into connected systems. We’ve investigated breaches where a single phishing link in Salesforce led to stolen credentials, MFA tokens, and lateral movement into Microsoft 365. Waiting until after a breach is risky and expensive. These evergreen security mantras stay true: Prevention is always cheaper than response. You cannot protect what you do not see.
Does this add complexity for admins or security teams?
No. WithSecure™ Cloud Protection is Salesforce-native. It installs in minutes, covers standard and custom objects, and works across Sales, Service, Experience Cloud, and Agentforce. Threats are blocked automatically, with clear alerts and reporting for admins. There are ready-made dashboards and reports. You can create your custom reports, too.
How does URL Protection help security teams day-to-day?
It reduces noise for admins and SecOps by automatically blocking harmful links, filtering unwanted categories, and providing clear analytics. Instead of relying on users to spot every risk, security teams get real-time visibility and automated remediation. That means fewer incidents to investigate and faster response when something slips through. This is the first line of defence, acting right at the source without delay, or slowing down the business.
What’s new in WithSecure Cloud Protection for Salesforce
-
WithSecure unveils Identity Protection to close one of Salesforce’s biggest security blind spots
WithSecure has unveiled Identity Protection for Salesforce — the first solution to detect compromised partner and customer accounts before they can be used in attacks. Designed to close one of the platform’s biggest security blind spots, the new capability helps enterprises safeguard high-trust environments like partner portals from credential-based fraud.
-
What’s new in WithSecure Cloud Protection for Salesforce 3.0
The Apollo 3.0 release introduces Identity Protection – a new layer of protection that monitors internal and external user credential compromise.
-
What’s new in WithSecure Cloud Protection for Agentforce 1.0
The first Agentforce-native security layer. Real-time protection against phishing and malware for Agentforce workflows.
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.9.1
QR codes in Salesforce look harmless. Until they aren’t. Today’s phishing attacks hide behind layers: a QR code inside a file, a shortened link inside the code. WithSecure Cloud Protection for Salesforce now detects them all, before users ever scan.
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.6
Detect malware inside password protected archives and block newly registered – and often malicious – domains
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.5
Detect and block malicious URLs in your Salesforce environment across custom objects and fields and prevent QR code quishing attacks
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.4
Detect and block malicious URLs in your Salesforce environment, from custom objects and fields to file attachments and even shortened web links.
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.3
Detect and block disguised file types, and report detections straight from the app
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.2
Master your data: deep threat analysis meets controlled geographic processing
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.1
Understand your security status and configurations with a glance
-
What’s new in WithSecure™ Cloud Protection for Salesforce 2.0
Configurable Click-Time URL Protection, bolstered file scanning, future-proof solution architecture and more
Get a Free Demo
THE #1 SALESFORCE MALWARE PROTECTION SOLUTION
Fill the form and get:
Free 15-day trial – test the product without limitations
Real attack simulation and product demo
Free customized and actionable risk assessment










