Microsoft’s mapping of year-long ShinyHunters-linked Salesforce attacks shows how SaaS compromise is increasingly about abusing trusted access rather than breaking the platform itself.
The campaigns used three main paths: voice phishing to trick employees into approving malicious OAuth apps, theft of OAuth tokens from compromised third-party vendors, and misconfigured guest access in Salesforce sites. In each case, attackers used legitimate-looking access paths to reach customer data.
This is especially dangerous because normal login monitoring may not show anything obviously suspicious. If the access comes from an approved connected app, a trusted vendor integration, or a guest role with excessive permissions, the activity can look like ordinary business traffic while data is quietly exported.
Organizations using Salesforce should review all connected apps, OAuth scopes, vendor integrations, guest-user permissions, and inactive applications. Unused integrations should be removed, over-permissioned apps should be restricted, and suspicious API activity should be investigated.
Security teams should monitor for unusual SOQL queries, large data exports, new connected apps, unexpected OAuth grants, abnormal access from integrations, and guest-user access to sensitive objects.
The key lesson is that SaaS security is no longer only about protecting user passwords. OAuth apps, service accounts, vendor tokens, and guest roles are now part of the identity perimeter. Naturally, attackers noticed the forgotten side door while everyone was still admiring the front door lock.

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In
Source: Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths via The Hacker News — published 14 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.