Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
ID: 04e4f740-1983-5d57-98c9-2f468d121acf
STIX ID: report--04e4f740-1983-5d57-98c9-2f468d121acf
Feed Name: CosmicBytez Labs
Microsoft documents a year-long pattern of ShinyHunters-aligned data-extortion activity against Salesforce tenants, showing three main intrusion paths—phished/stolen credentials (including session-token phishing and infostealer logs), abuse of Connected Apps/OAuth tokens, and public Experience Cloud misconfigurations that expose data without credentials—and describes persistent, low-and-slow bulk data exfiltration and account persistence techniques, with concrete hardening and monitoring recommendations for Salesforce administrators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
