Executive Summary
Between mid-2025 and mid-2026, the cybercriminal group ShinyHunters executed a series of sophisticated attacks targeting SaaS-based applications, notably Salesforce. Utilizing techniques such as voice phishing (vishing), supply chain compromises, and exploiting misconfigured guest access, they abused trusted OAuth relationships to gain unauthorized access, exfiltrate data, and establish persistent footholds within organizations. These methods allowed them to inherit user and application privileges, enabling extensive enumeration and querying of customer relationship management (CRM) records while evading traditional authentication detections. The campaigns impacted multiple industries, including retail, education, and manufacturing, underscoring the critical need for vigilant monitoring of OAuth-connected applications, thorough validation of third-party integrations, and stringent review of guest access configurations.
The relevance of this incident is heightened by the increasing prevalence of similar tactics employed by threat actors to exploit OAuth mechanisms and third-party integrations. Organizations must recognize the evolving threat landscape where attackers leverage trusted relationships and social engineering to bypass conventional security measures. This trend emphasizes the urgency for enhanced detection capabilities, improved visibility into connected applications, and the implementation of robust security practices to safeguard against such sophisticated attacks.
Why This Matters Now
The ShinyHunters' exploitation of OAuth mechanisms and third-party integrations highlights a critical vulnerability in SaaS applications. As these platforms become integral to business operations, the urgency to secure them against such sophisticated attacks has never been greater. Organizations must act promptly to implement enhanced monitoring, validate integrations, and review access configurations to prevent unauthorized data access and potential breaches.
Attack Path Analysis
The ShinyHunters group initiated their attack by conducting voice phishing (vishing) campaigns, impersonating IT support to deceive employees into granting OAuth consent to malicious applications. This allowed them to inherit user privileges and gain unauthorized access to Salesforce instances. Leveraging the granted OAuth tokens, they escalated their privileges to perform API calls on behalf of the victim users, enabling extensive data access. The attackers then moved laterally by exploiting trusted third-party integrations, such as Salesloft and Gainsight, to access multiple customer Salesforce instances. They established command and control by maintaining persistent access through these OAuth tokens and integrations, effectively evading traditional authentication detections. Subsequently, they exfiltrated large volumes of sensitive CRM data, including accounts, contacts, and service case information. The impact of these actions was significant, leading to data breaches across various industries and potential extortion attempts.
Kill Chain Progression
Initial Compromise
Description
ShinyHunters conducted vishing attacks, impersonating IT support to trick employees into authorizing malicious OAuth applications, thereby gaining initial access to Salesforce instances.
MITRE ATT&CK® Techniques
Phishing: Voice Phishing
Steal Application Access Token
Cloud Application Integration
Data from Information Repositories: Customer Relationship Management Software
Exfiltration Over Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure security of authentication factors
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Security Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
SaaS applications face OAuth abuse and supply chain compromise risks. Zero trust segmentation and egress security controls are critical for preventing data exfiltration.
Financial Services
CRM data exposure threatens customer financial information. Multicloud visibility and encrypted traffic controls essential for HIPAA/PCI compliance and preventing lateral movement.
Higher Education/Acadamia
Educational institutions using Salesforce for student records vulnerable to voice phishing OAuth consent abuse. Enhanced threat detection and anomaly response capabilities required.
Retail Industry
Customer relationship management systems targeted for bulk data queries and exfiltration. Cloud firewall and egress policy enforcement needed to protect sensitive retail data.
Sources
- Defending SaaS-based applications against ShinyHunters OAuth abusehttps://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/Verified
- Salesforce tracks possible ShinyHunters campaign targeting its usershttps://www.computerweekly.com/news/366639851/Salesforce-tracks-possible-ShinyHunters-campaign-targeting-its-usersVerified
- Salesforce investigating campaign targeting customer environments connected to Gainsight apphttps://www.cybersecuritydive.com/news/salesforce-investigating-customer-connected-Gainsight/806093/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained by enforcing strict identity-based policies, reducing the likelihood of unauthorized OAuth application approvals.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing strict segmentation policies, reducing unauthorized access to sensitive data.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been constrained by monitoring and controlling east-west traffic, reducing unauthorized access to other Salesforce instances.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain command and control could have been limited by providing comprehensive visibility and control over multicloud environments, reducing undetected access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been constrained by enforcing strict egress policies, reducing unauthorized data transfers.
The overall impact of the breach could have been limited by reducing the attacker's ability to access and exfiltrate sensitive data, thereby mitigating potential extortion and reputational damage.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management (CRM)
- Sales Operations
- Marketing Campaigns
- Customer Support Services
Estimated downtime: 7 days
Estimated loss: $5,000,000
Personal Identifiable Information (PII) of customers, including names, contact details, and service case data; sensitive business information such as sales opportunities and account details.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement within the network.
- • Enhance Multicloud Visibility & Control to monitor and manage OAuth applications and third-party integrations across all cloud environments.
- • Deploy Egress Security & Policy Enforcement to control and monitor outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities, such as unauthorized OAuth consent grants.
- • Regularly review and audit OAuth applications and third-party integrations to ensure they adhere to security policies and do not pose risks.



