Threats · 62 days ago
Salesforce is not the break point here. The break is the trust chain around it: a consent grant, a trusted integration, or guest access can hand an attacker legitimate privileges that keep working after the initial intrusion and slip past login-based monitoring.
Microsoft ties mid-2025 to mid-2026 campaigns to ShinyHunters-like tradecraft and says the actors used OAuth consent vishing, abused trusted workflows through integrations such as Salesloft and Gainsight, and exploited misconfigured guest access. Those paths let them enumerate and query CRM records, exfiltrate data at scale, and keep persistent access across many tenants in retail, education, and manufacturing.
The risk now sits in app consent and integration grants, not just passwords or MFA. If those grants are trusted as normal application traffic, the attacker can keep moving through CRM data and adjacent SaaS workflows under a legitimate identity.
2 sources covering this story
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Microsoft maps three Salesforce intrusion paths that abuse OAuth apps, vendor tokens, and guest access while ordinary sign-in monitoring stays quiet.
Defending SaaS-based applications against ShinyHunters OAuth abuse | Microsoft Security Blog
Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications.
Part of the PlainSec briefing for 2026-07-14