Microsoft has identified threat actors using ShinyHunters-linked tradecraft to compromise Salesforce customer environments by abusing OAuth trust relationships and social engineering employees through sophisticated voice phishing campaigns.
Key Points
- Threat actors utilized voice phishing to trick employees into granting malicious OAuth applications access to Salesforce tenants.
- Supply chain compromises involving trusted integrations like Salesloft and Gainsight allowed attackers to obtain connection secrets and maintain persistent access.
- Campaigns targeted various industries, including retail, education, and manufacturing, to perform bulk data exfiltration of CRM records.
- Microsoft upgraded Defender for Cloud Apps to provide near-real-time detection, connected application attribution, and enhanced visibility into OAuth scopes.
- New posture management tools allow security teams to identify and revoke unused or highly privileged applications to reduce the overall attack surface.
Why it Matters
- These campaigns demonstrate how attackers can bypass traditional authentication by operating through legitimate, pre-authorized SaaS workflows. Organizations must prioritize the governance of OAuth-connected applications to prevent unauthorized data access and maintain the integrity of their integrated software ecosystems.