ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations — Threadlinqs Intelligence
As of 2026-07-13, ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations is a high-severity apt threat attributed to ShinyHunters, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1275 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: ShinyHunters · FINANCIAL
ShinyHunters, a financially motivated data extortion group operating under Google/Mandiant designations UNC6040 (intrusion), UNC6240 (extortion), and overlapping with UNC6395 (Salesloft Drift OAuth
ShinyHunters' Salesforce-focused campaign combines voice phishing (vishing), OAuth/connected-app abuse, and SaaS supply-chain compromise to achieve mass data exfiltration for extortion. In the vishing vector (tracked by Google Threat Intelligence Group as UNC6040), operators impersonate corporate IT support over the phone and walk victim employees through Salesforce's 'Connect an App' flow, guiding them to enter a connection code that authorizes an attacker-controlled OAuth application impersonating Salesforce's legitimate Data Loader (sometimes rebranded, e.g. 'My Ticket Portal'). This grants the actor a durable OAuth/refresh token that survives password resets and, in many cases, MFA, enabling bulk querying and export of CRM data via the Salesforce REST/Bulk/GraphQL APIs without triggering traditional interactive-login anomaly detections. Once inside, operators pivot to Okta and Microsoft 365 using harvested credentials, and delay extortion demands (branded 'ShinyHunters', operationally handled by UNC6240) by weeks to months after the initial breach, suggesting a data-stockpiling strategy before a 72-hour Bitcoin-ransom ultimatum is issued via phone and email, backed by a Tor-hosted data leak site. A parallel and overlapping supply-chain vector (tracked as UNC6395) compromised OAuth/refresh tokens for the Salesloft Drift third-party integration between August 8 and August 18, 2025, giving attackers programmatic access to ~760 downstream Salesforce customer orgs; the actors specifically harvested secondary credentials (AWS AKIA access keys, Snowflake tokens, passwords) staged inside CRM case/support records, indicating credential-harvesting-for-further-compromise as a core objective, not merely CRM data theft. Google's Threat Intelligence Group has stated it has not found compelling evidence directly linking UNC6395 to ShinyHunters despite the group's public claims. A third, related vector abused misconfigured Salesforce Experience Cloud 'Aura' guest-user API endpoints with GraphQL-based requests to bulk-retrieve data beyond intended guest-access limits (observed June 19-22, 2026, and more broadly since March 2026, ~400 victims). Additional supply-chain compromises hit Gainsight's published Salesforce connected app (November 2025, 200+ instances) and Klue (June 2026, credential theft enabling direct Salesforce API queries, e.g. from IP 138.226.246.94 on June 11, 2026). Microsoft explicitly states none of this stems from a Salesforce platform vulnerability — it is entirely OAuth-trust and configuration abuse. ShinyHunters operates as part of a broader, fluid criminal collaboration ecosystem alongside Scattered Spider (UNC3944) and Lapsus$ remnants, publicly referred to as 'Scattered Lapsus$ Hunters' / 'Sp1d3rHunters', and has claimed 40+ breaches in 2026 alone across retail, education, manufacturing, technology, finance, luxury retail, telecom, healthcare, and critical infrastructure sectors.
Weaknesses (CWE)
CWE-287, CWE-284, CWE-863
Target sectors: retail, education, manufacturing, technology, finance, luxury retail, telecoms, critical infrastructure, health, entertainment, government administration
Target regions: North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1589.003, T1583.001, T1585, T1566.004, T1598.003, T1199, T1078, T1204.001, T1671, T1098