Skip to content

Salesforce: Three Attack Vectors via Third Parties and Misconfiguration

Key takeaway: ShinyHunters-linked attackers gain Salesforce access through legitimate OAuth channels: vishing calls, stolen tokens from third-party vendors (Salesloft, Gainsight, Klue), and exposed Aura endpoints—not via product vulnerabilities.

Microsoft documents attack campaigns against Salesforce systems from mid-2025 through June 2026, in which attackers penetrate without exploiting technical platform vulnerabilities—instead leveraging voice phishing, compromised integrations, and misconfigured guest user access.

Microsoft published an analysis on July 13, 2026, of campaigns attributed to the extortion group ShinyHunters. The attackers targeted Salesforce environments without exploiting technical vulnerabilities in the platform itself. Instead, they exploited trust-based integration mechanisms and human operational errors.

The first documented attack vector employs voice phishing (vishing): attackers posed as IT support on the telephone and manipulated employees into authorizing a malicious application called Data Loader through OAuth consent screens. This granted the attackers API access to CRM data. Affected organizations in June 2025 included Google, Chanel, Pandora, and Adidas. The second vector bypasses direct employee contact: attackers compromised external software vendors that already held OAuth approvals for their customers’ Salesforce environments. In August 2025, they stole OAuth and refresh tokens from Salesloft that potentially endangered approximately 700 organizations—including Cloudflare, Zscaler, and Palo Alto Networks. In November 2025, a breach at Gainsight compromised roughly 200 Salesforce instances. In June 2026, attackers exploited a dormant test credential at Klue to harvest customer tokens via a manipulated code update; Huntress and Recorded Future were affected.

Share on: