Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html

ONE SENTENCE SUMMARY:

Attackers abused trusted Salesforce OAuth apps, vendor tokens, and guest misconfigurations to exfiltrate data, evading login detection via “legitimate” access.

MAIN POINTS:

  1. ShinyHunters-aligned actors accessed Salesforce tenants without exploiting platform vulnerabilities.
  2. OAuth trust relationships with connected apps enabled entry and persistence.
  3. Microsoft documented campaigns spanning mid-2025 through mid-2026 across industries.
  4. Authentication logs often missed abuse because activity looked like normal approved usage.
  5. Vishing convinced employees to authorize attacker-controlled “Data Loader” connected apps.
  6. Authorized apps performed API enumeration, data export, and credential hunting across SaaS.
  7. Vendor compromises stole OAuth/refresh tokens, enabling multi-customer downstream access.
  8. Drift, Gainsight, and Klue incidents show secrets theft, token harvesting, and extortion overlap.
  9. Misconfigured Experience Cloud guest permissions allowed unauthenticated Aura/GraphQL data scraping.
  10. Microsoft and Salesforce enhanced Defender telemetry, attribution, and governance for connected apps.

TAKEAWAYS:

  1. Prioritize monitoring post-authentication behavior: app identity, scopes, query volume, and anomalies.
  2. Treat OAuth integrations as high-risk identities; enforce least-privilege scopes and token hygiene.
  3. Reduce third-party blast radius by auditing vendors and rapidly revoking/rotating compromised tokens.
  4. Lock down Experience Cloud guest roles and test Aura endpoint exposure regularly.
  5. Use governance to find privileged or inactive apps, then remove or re-scope them proactively.