CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Defending SaaS-based applications against ShinyHunters OAuth abuse

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2451

As cited

Copy frozen at (site build).

cloud saas

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft identified ShinyHunters-associated threat actors conducting campaigns from mid-2025 to mid-2026 that abused OAuth relationships to compromise Salesforce and other SaaS applications across retail, education, and manufacturing sectors. The attackers used voice phishing to trick users into authorizing malicious apps, exploited supply chain compromises in third-party integrations like Salesloft, and leveraged misconfigured guest access to gain persistence and exfiltrate customer relationship management data. These intrusion paths operated within legitimate OAuth workflows, allowing the threat actors to inherit user privileges and evade conventional authentication detection without exploiting any Salesforce vulnerability.

Why it matters: Security teams managing Salesforce and integrated SaaS applications need to immediately review OAuth-connected applications, validate third-party integrations, audit guest access configurations, and implement advanced monitoring to detect unauthorized OAuth consent flows and suspicious API activity that could result in large-scale data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft identified threat actor activity associated with ShinyHunters targeting Salesforce and other SaaS applications between mid-2025 and mid-2026 through three primary attack vectors: voice phishing to trick users into authorizing malicious OAuth applications, supply chain compromise of trusted integrations like Salesloft and Gainsight, and exploitation of misconfigured guest access. The actors abused legitimate OAuth relationships to enumerate customer relationship management records, exfiltrate data at scale, and maintain persistent access across multiple industries including retail, education, and manufacturing.

Why it matters: Salesforce administrators and SaaS security teams need to immediately review OAuth-connected applications, validate third-party integrations, audit guest access configurations, and enable event monitoring to detect unauthorized application consent and data exfiltration attempts targeting sensitive CRM data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft identified threat actor activity associated with ShinyHunters targeting Salesforce and other SaaS applications between mid-2025 and mid-2026 through three primary attack vectors: voice phishing to trick users into authorizing malicious OAuth applications, supply chain compromise of trusted integrations like Salesloft and Gainsight, and exploitation of misconfigured guest access. The actors abused legitimate OAuth relationships to enumerate customer relationship management records, exfiltrate data at scale, and maintain persistent access across multiple industries including retail, education, and manufacturing.

Why it matters: Salesforce administrators and SaaS security teams need to immediately review OAuth-connected applications, validate third-party integrations, audit guest access configurations, and enable event monitoring to detect unauthorized application consent and data exfiltration attempts targeting sensitive CRM data.

VendorsMicrosoftSalesforce
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary