---
title: Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
metaTitle: MS Maps Shinyhunters' Salesforce Attack Paths
description: ShinyHunters affiliates spent a year raiding Salesforce orgs via vishing, stolen OAuth tokens, and misconfigured guest access — no exploits required.
slug: ms-maps-shinyhunters-sales-force-attack-paths
date: "2026-07-14T12:00:00-05:00"
featured: true
image:
  src: https://cdn.securelogix.dev/slx/images/three-salesforce-attack-paths.webp
  alt: A key left in the lock that it opens.
sourcePublisher:
  name: The Hacker News
  url: "https://thehackernews.com/"
sourceArticle:
  url: "https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html"
tags: [Vishing, MFA, Data Breach, Call Center Fraud]
status: published
---

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.

The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.

In research published July 13, Microsoft mapped the campaigns, which ran from mid-2025 into mid-2026, to three distinct techniques. It also worked with Salesforce to roll out new detection and governance tooling aimed at addressing the activity authentication logs miss.

That is what makes this hard to catch. When the access comes from a real user who approved a connected app, or from an integration the company already trusts, the traffic reads as ordinary use, and sign-in and authentication monitoring barely registers it.

What matters is what the app or account does once it is in, and that is exactly what most Salesforce logging was not built to show...
