Salesforce is not the break point here. The break is the trust chain around it: a consent grant, a trusted integration, or guest access can hand an attacker legitimate privileges that keep working after the initial intrusion and slip past login-based monitoring.
Microsoft ties mid-2025 to mid-2026 campaigns to ShinyHunters-like tradecraft and says the actors used OAuth consent vishing, abused trusted workflows through integrations such as Salesloft and Gainsight, and exploited misconfigured guest access. Those paths let them enumerate and query CRM records, exfiltrate data at scale, and keep persistent access across many tenants in retail, education, and manufacturing.
The risk now sits in app consent and integration grants, not just passwords or MFA. If those grants are trusted as normal application traffic, the attacker can keep moving through CRM data and adjacent SaaS workflows under a legitimate identity.