ShinyHunters Abuses OAuth Trust to Access Salesforce Tenants
Two intrusion paths (vishing-driven OAuth consent abuse and supply-chain compromise of integration vendors) both exploit legitimate authorization flows rather than platform vulnerabilities, evading conventional detections in the process.
TL;DR
Microsoft detailed two ShinyHunters campaigns (spanning mid-2025 to mid-2026) that abused OAuth trust relationships to access SaaS applications such as Salesforce instances. The first used voice phishing to trick employees into granting OAuth consent to a malicious app disguised as a Salesforce Data Loader. The second compromised integration vendors including Salesloft and Gainsight to pivot through trusted workflows into customer tenants. The activity, observed across retail, education, and manufacturing, evaded conventional authentication detections by operating inside legitimate authorization flows. Salesforce itself wasn't the vulnerability, the trust model was the target.
Microsoft published detailed threat intelligence on July 13 documenting ShinyHunters campaigns that abused OAuth trust relationships to access SaaS applications such as Salesforce instances across retail, education, and manufacturing. The activity, observed between mid-2025 and mid-2026, followed two distinct intrusion paths. Neither exploited a vulnerability in the SaaS platforms themselves, the threat actors operated inside legitimate authorization workflows.
The first path, beginning in mid-2025, used voice phishing. Threat actors impersonated IT support, socially engineered employees into authorizing attacker-controlled connected apps, and walked victims through the OAuth consent workflow. The malicious application was disguised as a legitimate Salesforce Data Loader tool. Once consent was granted, the privileged OAuth app made API calls on behalf of the victim user, enumerating Salesforce instances, persisting on CRM data, and potentially moving laterally into other SaaS platforms through discovered credentials.
The second path surfaced in August 2025 through supply-chain compromise. Compromised Salesloft Drift credentials let attackers obtain connection secrets underpinning OAuth integrations in multiple downstream customer Salesforce tenants. A follow-on campaign in November 2025 targeted Gainsight, another integration vendor, using similar techniques to pivot through trusted workflows into customer environments. In both paths, the abuse of legitimate OAuth relationships allowed the activity to evade conventional authentication detections.
Microsoft consulted with Salesforce to improve telemetry granularity in Defender for Cloud Apps, adding near-real-time detection, connected-application attribution, and expanded permission insights.
For practitioners, the immediate steps are concrete: monitor OAuth-connected applications, validate third-party integrations, review configurations, and enable Salesforce event monitoring. The campaigns underscore that OAuth trust isn't a vulnerability you patch, it's a surface you defend.
Published ·Deep Fathom