Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
AI Summary
Microsoft has identified three attack paths used by threat actors associated with ShinyHunters to compromise Salesforce environments over a year-long campaign from mid-2025 to mid-2026. The attackers exploited trusted OAuth integrations through vishing attacks, stole OAuth tokens from compromised third-party vendors like Drift, Gainsight, and Klue, and abused misconfigured guest access in Salesforce Experience Cloud sites. These methods allowed persistent access to CRM data without exploiting platform vulnerabilities, blending malicious activity with legitimate traffic. The campaigns targeted organizations across retail, education, and manufacturing sectors, leveraging social engineering, supply chain compromises, and poor identity governance.
AI-extracted · verify before operational use
Extracted Entities 4 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub User | GRUB1 | Details → |