Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Microsoft has detailed three methods used by attackers, linked to ShinyHunters, to steal data from Salesforce over the past year. These attacks bypass traditional security by exploiting trusted connections rather than platform vulnerabilities.
Intelligence analysis by Gemini 2.5 Flash Lite

Attackers, associated with the ShinyHunters group, have exploited trusted third-party integrations and social engineering tactics to exfiltrate data from Salesforce instances over the last year. Microsoft's analysis highlights three primary attack vectors: vishing calls tricking users into authorizing malicious apps, compromised OAuth tokens from trusted vendors, and misconfigured gue…
Imagine your company uses a special online filing cabinet called Salesforce to store important papers. Bad guys are tricking people into letting them use special keys (called OAuth tokens) that already have permission to open the cabinet. They also trick people into giving them new keys over the phone or find unlocked back doors. They aren't breaking the cabinet's lock; they're using keys that were already given out, making it hard to tell they're up to no good.
Analysis
Exploiting Trust: The Core of the Attack
The recent analysis by Microsoft sheds critical light on a year-long campaign, spanning from mid-2025 to mid-2026, where threat actors, identified with the ShinyHunters moniker, successfully infiltrated and exfiltrated data from corporate Salesforce environments. What makes these attacks particularly insidious is their deliberate avoidance of exploiting any vulnerabilities within the Salesforce platform itself. Instead, the attackers masterfully leveraged the trust that organizations inherently place in their interconnected ecosystem. This trust is most commonly manifested through OAuth connections, which allow Salesforce to integrate with a myriad of third-party applications and vendors. By compromising these established trust pathways, the attackers were able to operate with a level of stealth that rendered traditional security monitoring, focused on platform integrity and user sign-ins, largely ineffective. The true challenge lies in distinguishing legitimate, authorized access from malicious activity when the entry point is an application or integration that the company has already vetted and approved.
Three Paths to Data Exfiltration
Microsoft has meticulously mapped these campaigns onto three distinct intrusion paths, each representing a unique method of gaining unauthorized access and subsequently extracting sensitive data. The first path involves social engineering through voice-phishing (vishing) calls. Attackers impersonate IT support personnel, guiding unsuspecting employees to authorize a malicious connected app, disguised as a legitimate Salesforce tool like Data Loader. Once granted consent, this app can make API calls as the user, enabling attackers to enumerate data, maintain persistent access, and search for credentials to pivot to other SaaS platforms. This method, documented by Google's Threat Intelligence Group and Mandiant, has been linked to high-profile breaches at companies like Chanel, Pandora, and Adidas.
The second path bypasses direct user interaction by targeting third-party vendors that already possess OAuth access to their clients' Salesforce instances. By compromising these vendors, attackers steal the connection secrets or OAuth tokens, which they then use to query and export data across numerous downstream customers. This approach is particularly effective because the malicious traffic originates from an already trusted integration, blending seamlessly with normal automation and evading detection. Notable incidents include the compromise of Salesloft's Drift integration, which potentially exposed over 700 organizations, and the Gainsight incident, affecting over 200 Salesforce instances. The Klue compromise in June 2026 further illustrates this, where a legacy credential allowed attackers to harvest customer OAuth tokens for Salesforce and Gong.
The third identified path involves exploiting misconfigured guest access to Salesforce sites. This method requires no credentials at all, as attackers leverage vulnerabilities in how external access is managed. Microsoft observed a rise in suspicious guest-user activity against Salesforce Aura endpoints, indicating that even publicly accessible or loosely secured areas can become entry points for data theft. This multifaceted approach underscores the attackers' adaptability and their focus on exploiting the weakest links in an organization's interconnected digital infrastructure, rather than direct platform exploits.
Key points
- Attackers linked to ShinyHunters have used three methods to steal data from Salesforce over the past year without exploiting platform flaws.
- The attacks exploit pre-existing trust through OAuth connections with third-party apps and vendors.
- Methods include vishing calls tricking employees into authorizing malicious apps, stolen OAuth tokens from compromised vendors, and misconfigured guest access.
- These techniques bypass traditional security monitoring focused on sign-in and authentication logs.
- Microsoft and Salesforce are developing new tools to improve detection and governance of such activities.
Microsoft's collaboration with Salesforce to develop new detection and governance tools offers a promising path forward. By addressing the blind spots in authentication logs and providing better visibility into the actions of connected apps, organizations can strengthen their defenses against these trust-based attacks.
The reliance on OAuth and third-party integrations, while essential for business operations, creates inherent vulnerabilities. If organizations fail to rigorously audit and manage these connections, and if attackers continue to find novel ways to exploit them, widespread data breaches through these indirect pathways will remain a significant threat.



