Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

July 14, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Enterprises in retail, education, and manufacturing
Incident: Year-long campaign of data theft from Salesforce environments using OAuth abuse and vishing.
Impact: Unauthorized access to sensitive CRM records and corporate data across numerous high-profile global organizations.
Attacker: ShinyHunters (including linked actors UNC6040 and UNC6240)
Analysis: The campaign leverages trust relationships rather than software flaws, making detection difficult via standard sign-in logs. By using vishing to secure OAuth consent or stealing vendor tokens, attackers gained persistent API access to sensitive CRM data. This highlights a critical blind spot in SaaS governance where approved apps operate without sufficient behavioral monitoring.
Recommendations: Implement strict governance for OAuth app approvals and conduct regular audits of third-party integrations.; Train employees to recognize vishing attempts and mandate out-of-band verification for all IT support requests.; Review and harden Salesforce guest access configurations to prevent unauthorized data exposure.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *