Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this through a combination of phishing for approval of malicious apps, stealing OAuth tokens from compromised vendors, and exploiting misconfigured guest access. Microsoft and Salesforce have collaborated to develop new detection and governance tools to address this growing threat, focusing on monitoring connected app activity and reducing the attack surface.
For a year, attackers associated with the ShinyHunters group have been walking into corporate Salesforce environments without exploiting any known vulnerabilities. Instead, they exploited the trust placed in connected apps and vendors to gain access. The attackers achieved this through a multi-pronged approach, starting with phishing calls to trick employees into approving malicious connected apps – specifically, a fake Data Loader tool.
These initial access points then led to several distinct intrusion paths. The first involved a phone call to get an employee to authorize a malicious connected app, allowing the attackers to enumerate the organization's Salesforce data and hunt for credentials. The second path bypassed the user entirely, stealing OAuth tokens from compromised third-party vendors like Salesloft and Gainsight, enabling them to access customer data across multiple Salesforce instances. Finally, attackers exploited misconfigured guest access to Salesforce Aura endpoints, exceeding the standard 2,000-record query limit and extracting far more data than a guest user should have been able to access.
Google's Threat Intelligence Group (GTIG) and Mandiant initially documented the initial access as UNC6040 and the follow-on extortion as UNC6240, both claiming to be ShinyHunters. The campaign impacted numerous organizations, including Cloudflare, Zscaler, Palo Alto Networks, and Huntress, with the group linked to incidents across over 200 Salesforce instances. Microsoft has since developed new detection and governance tools, including Defender for Cloud Apps, to surface activity related to connected apps and their granted OAuth scopes. These tools also include features for identifying unused apps and assigning risk scores to connected apps.
Microsoft and Salesforce recommend connecting Salesforce instances to Defender for Cloud Apps, enabling Salesforce event logs, and securing guest-user access. Beyond these product-specific steps, the long-term solution involves inventorying connected apps, removing unused integrations, and applying the principle of least privilege to all connected apps. The underlying issue is that existing identity controls were designed for human logins, not the complex ecosystem of connected apps and service accounts that now dominate Salesforce deployments.
