Defending SaaS-based applications against ShinyHunters OAuth abuse
ID: 7837e0d9-e842-55e7-8062-3443aa841e01
STIX ID: report--7837e0d9-e842-55e7-8062-3443aa841e01
Feed Name: Microsoft Security
Date Published: 2026-07-13
Date Updated: 2026-07-15
Author: Microsoft Security Research and Microsoft Defender Security Research Team
Microsoft observed campaigns between mid-2025 and mid-2026 in which threat actors linked to ShinyHunters used voice‑phishing (vishing) to trick users into approving malicious OAuth-connected apps and compromised third‑party SaaS integrations (e.g., Salesloft, Gainsight, Klue) to obtain tokens and connection secrets, enabling persistent API access and large‑scale exfiltration of Salesforce CRM data; the report outlines attack paths, MITRE techniques, detection/hunting queries for Microsoft Defender for Cloud Apps, and recommendations for governance and preventive controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
