CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2455

As cited

Copy frozen at (site build).

breaches incidents

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

Microsoft researchers documented a year-long campaign in which attackers associated with ShinyHunters exploited trusted OAuth connections to Salesforce environments rather than targeting platform vulnerabilities. The attackers leveraged existing integrations between Salesforce and third-party applications to gain unauthorized access to corporate data across multiple attack paths.

Why it matters: Security teams managing Salesforce deployments need to audit OAuth permissions and third-party integrations immediately, as this technique bypasses traditional patch-based defenses and targets the trust relationships already in place.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

Microsoft researchers documented a year-long campaign in which attackers associated with ShinyHunters exploited trusted OAuth connections to Salesforce environments rather than targeting platform vulnerabilities. The attackers leveraged existing integrations between Salesforce and third-party applications to gain unauthorized access to corporate data across multiple attack paths.

Why it matters: Security teams managing Salesforce deployments need to audit OAuth permissions and third-party integrations immediately, as this technique bypasses traditional patch-based defenses and targets the trust relationships already in place.

VendorsMicrosoftSalesforce
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary