discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

Microsoft has detailed three methods used by attackers, linked to ShinyHunters, to steal data from Salesforce over the past year. These attacks bypass traditional security by exploiting trusted connections rather than platform vulnerabilities.

By Swati Khandelwal·Jul 14·thehackernews.com·3 min read

Intelligence analysis by Gemini 2.5 Flash Lite

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Image: thehackernews.com

Attackers, associated with the ShinyHunters group, have exploited trusted third-party integrations and social engineering tactics to exfiltrate data from Salesforce instances over the last year. Microsoft's analysis highlights three primary attack vectors: vishing calls tricking users into authorizing malicious apps, compromised OAuth tokens from trusted vendors, and misconfigured gue…

Why it matters

This report reveals sophisticated, year-long data theft campaigns targeting Salesforce that bypass conventional security measures by leveraging pre-existing trust relationships, underscoring the need for enhanced monitoring of connected applications and third-party integrations.

Imagine your company uses a special online filing cabinet called Salesforce to store important papers. Bad guys are tricking people into letting them use special keys (called OAuth tokens) that already have permission to open the cabinet. They also trick people into giving them new keys over the phone or find unlocked back doors. They aren't breaking the cabinet's lock; they're using keys that were already given out, making it hard to tell they're up to no good.

Analysis

Exploiting Trust: The Core of the Attack

The recent analysis by Microsoft sheds critical light on a year-long campaign, spanning from mid-2025 to mid-2026, where threat actors, identified with the ShinyHunters moniker, successfully infiltrated and exfiltrated data from corporate Salesforce environments. What makes these attacks particularly insidious is their deliberate avoidance of exploiting any vulnerabilities within the Salesforce platform itself. Instead, the attackers masterfully leveraged the trust that organizations inherently place in their interconnected ecosystem. This trust is most commonly manifested through OAuth connections, which allow Salesforce to integrate with a myriad of third-party applications and vendors. By compromising these established trust pathways, the attackers were able to operate with a level of stealth that rendered traditional security monitoring, focused on platform integrity and user sign-ins, largely ineffective. The true challenge lies in distinguishing legitimate, authorized access from malicious activity when the entry point is an application or integration that the company has already vetted and approved.

Three Paths to Data Exfiltration

Microsoft has meticulously mapped these campaigns onto three distinct intrusion paths, each representing a unique method of gaining unauthorized access and subsequently extracting sensitive data. The first path involves social engineering through voice-phishing (vishing) calls. Attackers impersonate IT support personnel, guiding unsuspecting employees to authorize a malicious connected app, disguised as a legitimate Salesforce tool like Data Loader. Once granted consent, this app can make API calls as the user, enabling attackers to enumerate data, maintain persistent access, and search for credentials to pivot to other SaaS platforms. This method, documented by Google's Threat Intelligence Group and Mandiant, has been linked to high-profile breaches at companies like Chanel, Pandora, and Adidas.

The second path bypasses direct user interaction by targeting third-party vendors that already possess OAuth access to their clients' Salesforce instances. By compromising these vendors, attackers steal the connection secrets or OAuth tokens, which they then use to query and export data across numerous downstream customers. This approach is particularly effective because the malicious traffic originates from an already trusted integration, blending seamlessly with normal automation and evading detection. Notable incidents include the compromise of Salesloft's Drift integration, which potentially exposed over 700 organizations, and the Gainsight incident, affecting over 200 Salesforce instances. The Klue compromise in June 2026 further illustrates this, where a legacy credential allowed attackers to harvest customer OAuth tokens for Salesforce and Gong.

The third identified path involves exploiting misconfigured guest access to Salesforce sites. This method requires no credentials at all, as attackers leverage vulnerabilities in how external access is managed. Microsoft observed a rise in suspicious guest-user activity against Salesforce Aura endpoints, indicating that even publicly accessible or loosely secured areas can become entry points for data theft. This multifaceted approach underscores the attackers' adaptability and their focus on exploiting the weakest links in an organization's interconnected digital infrastructure, rather than direct platform exploits.

Key points

  • Attackers linked to ShinyHunters have used three methods to steal data from Salesforce over the past year without exploiting platform flaws.
  • The attacks exploit pre-existing trust through OAuth connections with third-party apps and vendors.
  • Methods include vishing calls tricking employees into authorizing malicious apps, stolen OAuth tokens from compromised vendors, and misconfigured guest access.
  • These techniques bypass traditional security monitoring focused on sign-in and authentication logs.
  • Microsoft and Salesforce are developing new tools to improve detection and governance of such activities.
The Upside

Microsoft's collaboration with Salesforce to develop new detection and governance tools offers a promising path forward. By addressing the blind spots in authentication logs and providing better visibility into the actions of connected apps, organizations can strengthen their defenses against these trust-based attacks.

The Downside

The reliance on OAuth and third-party integrations, while essential for business operations, creates inherent vulnerabilities. If organizations fail to rigorously audit and manage these connections, and if attackers continue to find novel ways to exploit them, widespread data breaches through these indirect pathways will remain a significant threat.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritysaas-securityidentity-securitydata-theftoauththreat-intelligence

Author

Swati Khandelwal

Intelligence analysis by

Gemini 2.5 Flash Lite

Published

Jul 14, 2026

Source

thehackernews.com

Share

Topics

securitysaas-securityidentity-securitydata-theftoauththreat-intelligence

Related

More from this desk

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·bleepingcomputer.com

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings, without requiring organizer approval.

Aug 24·bleepingcomputer.com

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in some applications. The issue affects only apps that use the Windows Presentation Foundation (WPF) UI framework.

Aug 24·thehackernews.com

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.