Saturday, September 19, 2026

ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data

A series of high-impact campaigns linked by overlapping tradecraft to ShinyHunters, in which attackers abused trusted Salesforce OAuth relationships to bypass conventional MFA protections, establish persistence, and exfiltrate CRM data at scale.

The activity, observed from mid-202520252025 through mid-202620262026, affected organizations in retail, education, and manufacturing.

Microsoft emphasized that the campaigns did not exploit an inherent Salesforce vulnerability. Instead, the operators manipulated legitimate OAuth workflows, compromised trusted SaaS integrations, and abused overly permissive guest access configurations.

The most prominent intrusion route involved voice phishing, or vishing. Attackers impersonated IT support staff and persuaded employees to authorize attacker-controlled connected applications in Salesforce.

In confirmed cases, the malicious application was presented as a legitimate Salesforce Data Loader utility.

Once a user approved the OAuth consent request, the application inherited that user’s permissions and could issue Salesforce API calls without requiring the attacker to authenticate repeatedly.

This effectively neutralized MFA as a meaningful barrier, as the malicious activity occurred through a valid, authorized OAuth session rather than via a stolen password or an anomalous login.

Microsoft said the access enabled attackers to enumerate Salesforce environments, query CRM data, maintain persistent access, and potentially discover credentials that could facilitate movement into other SaaS services.


Commonly observed attack paths for SaaS applications (Source : Microsoft).
Commonly observed attack paths for SaaS applications (Source : Microsoft).

In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing).

Because the calls originated from approved applications and operated with legitimate user privileges, they could evade detections focused on suspicious sign-ins.

Salesforce OAuth Abused

The threat actors also targeted Salesforce-connected vendors and integrations. In August 202520252025, compromised credentials associated with Salesloft Drift reportedly exposed connection secrets used by downstream SaaS applications, enabling attackers to use OAuth tokens across multiple customer Salesforce tenants.


Complete permission visibility for Salesforce connected apps and external client apps  (Source : Microsoft).
Complete permission visibility for Salesforce connected apps and external client apps (Source : Microsoft).

A later campaign in November 202520252025 affected Gainsight-published applications integrated with Salesforce. According to Gainsight’s advisory, attackers abused trusted external connections to preserve API access across customer environments.

Microsoft further linked similar methods to the June 202620262026 Klue incident, where Storm-3138 accessed credentials used to reach Salesforce customer instances. Klue said the actor used those credentials to discover, query, and extract customer data.

In each case, the use of legitimate integration tokens made bulk discovery and export activity resemble normal application behavior.

Attackers could access accounts, contacts, and service-case records without generating the login anomalies commonly associated with account compromise.

Microsoft additionally observed suspicious activity against Salesforce Aura endpoints. Attackers exploited misconfigured Experience Cloud guest-user permissions and sent GraphQL access based Aura requests to enumerate and retrieve exposed data.

The activity did not rely on a software flaw. Instead, it exploited guest access granted beyond what was necessary. By chaining Aura requests, attackers could bypass normal record retrieval constraints and extract substantially more information than guest users should ordinarily access.

Salesforce administrators should review Experience Cloud guest-user security guidance and remove unnecessary object, field, and record permissions.

Microsoft expanded its Defender for Cloud Apps Salesforce connector to support near-real-time Salesforce telemetry through Salesforce Shield Event Monitoring.

The enhanced integration provides connected-app attribution, OAuth scope visibility, API context, and risk-based insights for privileged or inactive applications.

Organizations should inventory every connected and external client application, validate OAuth scopes, revoke unused integrations, and investigate applications holding broad administrative or data-access permissions.

They should also monitor Salesforce event logs for bulk API queries, unusual export patterns, newly authorized connected apps, and unexpected activity from non-human identities.

The campaigns demonstrate that MFA alone cannot stop attacks that exploit trusted authorization. In SaaS environments, OAuth consent, third-party integrations, and guest permissions must be treated as critical identity security controls rather than operational conveniences.

Indicators of compromise (IOC)

Indicator  Type  Description  
138.226.246.94 IP address Used by the Klue integration to call Salesforce API to perform CRM queries on June 11. Previously disclosed by Klue in their notification about the breach.
212.86.125.24 IP address 
213.111.148.90 IP address 
94.154.32.160 IP address 
103.75.11.78IP addressUsed to target the Aura framework with guest access from June 19 to 22. These IP addresses were not previously published and were discovered by Microsoft as part of a novel campaign.
103.75.11.110IP address

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains

China-aligned threat actors are using low-quality Chinese-language casino and...

Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware

Feral Wolf has expanded its ransomware tradecraft by abusing...

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems

A newly observed ransomware operation dubbed SETTRA is abusing...

JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data

JADEPUFFER, the agentic threat actor first linked to an...

ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

Threat actors are increasingly impersonating OpenAI’s ChatGPT service in...

Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell

Linux administrators are being urged to patch four newly...

Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability

More than 100,000 WordPress sites using the Tutor LMS...

Related Articles

Recent News