// 1 CRITICAL · 4 ZERO-DAY · 6 CVE · 5 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-party vendor compromises.

On July 13, 2026, Microsoft published a technical report documenting threat-actor campaigns with tradecraft associated with ShinyHunters, active from mid-2025 through mid-2026, targeting SaaS ecosystems by abusing trusted OAuth relationships. The analysis reveals a troubling pattern: attackers exploit legitimate consent flows and third-party vendor compromises rather than software vulnerabilities, rendering the activity "indistinguishable from legitimate integration behavior," in the report's own words.

Key Takeaways
  • Microsoft identified two primary vectors: vishing for OAuth consent to apps disguised as Salesforce Data Loader, and supply-chain compromise of trusted third-party vendor integrations.
  • Vendors Salesloft, Gainsight, and Klue were compromised in sequence between August 2025 and June 2026, with access to OAuth tokens across multiple Salesforce tenants.
  • Activity was observed in multiple tenants across retail, education, and manufacturing sectors.
  • Microsoft released new posture capabilities in Defender for Cloud Apps, including visibility into OAuth scopes and a 0–100 risk scoring model for connected applications.

The Invisible Mechanism: When Legitimate Consent Becomes a Weapon

The vishing campaign began in mid-2025. Threat actors impersonated IT support to trick employees into authorizing malicious apps disguised as legitimate Salesforce Data Loader tools. Once OAuth consent was obtained, attackers gained programmatic access that generated no traditional authentication anomalies.

The second vector materialized through the compromise of third-party vendors whose integrations were already trusted. In August 2025, compromised Salesloft Drift credentials allowed attackers to obtain connection secrets and use OAuth tokens across multiple customer Salesforce instances. In November 2025, the campaign targeted Gainsight applications integrated with Salesforce to maintain persistent API access. In June 2026, the Klue incident saw threat actor Storm-3138 obtain credentials used for Salesforce customer instances.

The Confirmation Ecosystem: Vendors and Independent Investigations

Microsoft's reconstruction aligns with independent statements from the affected vendors. Salesloft, with Mandiant support, confirmed the Drift intrusion between March and September 2025, the exfiltration of secrets, and the rotation of OAuth tokens. Gainsight confirmed the temporary disabling of the Salesforce integration, an investigation conducted with Mandiant and CrowdStrike, and reported that a "handful of customers" suffered data impact. Klue confirmed the June 2026 incident, the compromise of a legacy credential, and the use of OAuth tokens to access Salesforce, with the investigation assigned to CrowdStrike.

Notably, Klue does not name Storm-3138 in the extracted text of its own communication; attribution to this threat actor comes exclusively from the Microsoft report. Similarly, the connection to ShinyHunters is presented by Microsoft as "overlapping tradecraft commonly associated with," not as a definitive attribution.

The Telemetry Paradox: Seeing the Invisible Requires Co-Design

"This activity was not the result of a vulnerability inherent to Salesforce. Rather, the threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence." — Microsoft Security Blog

The core technical challenge emerges from the report's second key observation: "These activities often appeared indistinguishable from legitimate integration behavior." To address this, Microsoft collaborated with Salesforce to improve Real-Time Event Monitoring (RTEM) telemetry within Defender for Cloud Apps. Co-design was necessary because sanctioned OAuth flows generate no conventional compromise signals: authentication is valid, consent was granted, and the APIs are official.

The result is a set of posture capabilities that expand the visibility surface: visibility into granted OAuth scopes, insights into highly privileged apps, identification of unused apps with a 90-day inactivity threshold, and a 0–100 risk scoring model for connected applications. These tools do not eliminate the vector, but they reduce the information asymmetry between attackers and defenders.

Immediate Actions

  • Review OAuth scopes granted to connected applications in Salesforce and related SaaS environments, prioritizing apps with elevated privileges over sensitive data.
  • Enable the new posture capabilities in Defender for Cloud Apps, particularly the 0–100 risk scoring and unused app identification, to reduce the attack surface.
  • Evaluate RTEM telemetry integrated with Salesforce as a detection layer for activity that appears legitimate but exhibits anomalous data-access patterns.
  • Verify the trust chain of third-party SaaS integrations, demanding transparency on how vendors such as Salesloft, Gainsight, and Klue manage secrets and OAuth tokens.

A Replicable Model: The SaaS Supply Chain as a New Frontier

The pattern documented by Microsoft is not confined to a single ecosystem. The logic is transferable: any SaaS platform with an ecosystem of trusted integrations is potentially exposed to compromises that inherit privileges through third-party vendors. The novelty lies not in the OAuth technique, which is well known, but in the systematic way it has been operationalized and the inherent difficulty of detection.

The Microsoft report of July 13, 2026, does not conclude the investigation. There is no indication the activity has ceased, nor that all potentially affected tenants have been identified. The exact number of compromised organizations and the volume of exfiltrated data remain unquantified. Also unresolved is the question of a third vector, "misconfigured guest access," reported solely by Arrowwood Services and absent from the primary Microsoft post: the dossier does not establish whether this represents a separate campaign or an editorial extrapolation.

Sources


Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. microsoft.com
  2. arrowwoodservices.com
  3. trust.salesloft.com
  4. gainsight.com
  5. klue.com