logo

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

ID: 04e4f740-1983-5d57-98c9-2f468d121acf

STIX ID: report--04e4f740-1983-5d57-98c9-2f468d121acf

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

...
...

Microsoft documents a year-long pattern of ShinyHunters-aligned data-extortion activity against Salesforce tenants, showing three main intrusion paths—phished/stolen credentials (including session-token phishing and infostealer logs), abuse of Connected Apps/OAuth tokens, and public Experience Cloud misconfigurations that expose data without credentials—and describes persistent, low-and-slow bulk data exfiltration and account persistence techniques, with concrete hardening and monitoring recommendations for Salesforce administrators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.