CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

July 14, 2026

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths Swati KhandelwalJul 14, 2026SaaS Security / Identity Security Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In research published July 13, Microsoft mapped the campaigns, which ran from mid-2025 into mid-2026, to three distinct techniques. It also worked with Salesforce to roll out new detection and governance tooling aimed at addressing the activity authentication logs miss. That is what makes this hard…