The Containment Era is here. →Explore

Executive Summary

In mid-2025, cybercriminal threat clusters UNC6040 and UNC6395 launched coordinated attacks targeting the Salesforce environments of major global enterprises, leveraging supply chain compromises, OAuth token abuse, and social engineering tactics. Attackers tricked employees into authorizing malicious OAuth apps or exploited stolen access tokens, enabling mass data exfiltration from Salesforce—including sensitive 'Accounts', 'Contacts', and support case records containing credentials and cloud secrets. Stolen information was subsequently used by the ShinyHunters extortion group for ransom threats and further infiltrations, impacting organizations such as Google, Cisco, Adidas, and major cybersecurity firms.

This incident exemplifies a growing wave of attacks exploiting trusted third-party platforms and identity federation weaknesses to compromise cloud SaaS data at scale. The sophisticated multi-stage approach highlights urgent risks related to SaaS supply chains, the need for robust OAuth governance, and increased vigilance toward privilege escalation via indirect access vectors.

Why This Matters Now

The prevalence of SaaS, federated identity, and supply chain interdependencies has made token theft and OAuth exploitation a leading attack vector in 2025. Organizations face urgent pressure to address gaps in SaaS governance, token lifecycle management, and real-time anomaly detection to prevent cascading breaches across interconnected cloud platforms.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incidents revealed insufficient safeguards around OAuth token governance, lateral movement detection, and vendor access control, highlighting the need for broader alignment with ZTMM, PCI DSS, and NIST 800-53 requirements for access, monitoring, and data protection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Application of Zero Trust Network Segmentation, egress filtering, east-west visibility, and anomaly detection would have significantly hindered attackers’ lateral movement, API data harvesting, and mass exfiltration efforts across cloud SaaS and hybrid environments.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Centralized monitoring of OAuth app connections and anomalous access patterns detected suspicious third-party integrations.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based policy segmentation limited scope of OAuth app permissions and access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west microsegmentation and workload-to-workload traffic controls blocked unauthorized API/data flows.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Anomalous API consumption or unusual data transfer patterns were baselined and rapidly alerted.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Stringent egress controls detected and blocked abnormal outbound flows consistent with data exfiltration.

Impact (Mitigations)

Security fabric and inline enforcement reduces blast radius and increases detection of extortion follow-on tactics.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
  • Customer Support
Operational Disruption

Estimated downtime: 10 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to Salesforce instances led to the exfiltration of sensitive customer data, including contact information, support case details, and potentially credentials such as AWS keys and passwords. This exposure increases the risk of further targeted attacks and data misuse.

Recommended Actions

  • Enforce zero trust segmentation to restrict OAuth app and user permissions to least privilege by identity and namespace.
  • Deploy robust east-west and egress policy enforcement to block lateral API pivoting and unauthorized data exfiltration.
  • Centralize multicloud/SaaS visibility to rapidly surface unauthorized token usage, unusual third-party app integrations, and mass data access events.
  • Continuously monitor for credential leakage and anomalous data flows with automated threat and anomaly response across hybrid and SaaS environments.
  • Audit and limit sensitive data and secrets stored in cloud SaaS support cases, ensuring strong workload and application isolation.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image