ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations
ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against (TL-2026-1275), also tracked as Scattered Lapsus$ Hunters OAuth Campaign, is a high-severity advanced persistent threat campaign, first published 2026-07-13. It is attributed to ShinyHunters with medium confidence, affects Salesforce Salesforce CRM / Connected Apps / Experience Cloud (Aura), maps to 30 MITRE ATT&CK techniques (T1005, T1020, T1056), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1275
- Threat ID
- TL-2026-1275
- Also known as
- Scattered Lapsus$ Hunters OAuth Campaign, Salesforce Data Loader Impersonation Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-07-13
- Last reviewed
- 2026-07-13
- Attribution
- ShinyHunters
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- retail, education, manufacturing, technology, finance, luxury retail, telecoms, critical infrastructure, health, entertainment, government administration
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against
Malware and tooling: AuraInspector, Salesforce Data Loader (impersonated/modified), ToogleBox Recall, Tox messaging protocol, TruffleHog - S9009
ShinyHunters, a financially motivated data extortion group operating under Google/Mandiant designations UNC6040 (intrusion), UNC6240 (extortion), and overlapping with UNC6395 (Salesloft Drift OAuth theft), has run a sustained campaign from mid-2025 through mid-2026 abusing OAuth trust relationships to compromise Salesforce environments and connected SaaS integrations (Salesloft/Drift, Gainsight, Klue).
How ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against works
ShinyHunters' Salesforce-focused campaign combines voice phishing (vishing), OAuth/connected-app abuse, and SaaS supply-chain compromise to achieve mass data exfiltration for extortion. In the vishing vector (tracked by Google Threat Intelligence Group as UNC6040), operators impersonate corporate IT support over the phone and walk victim employees through Salesforce's 'Connect an App' flow, guiding them to enter a connection code that authorizes an attacker-controlled OAuth application impersonating Salesforce's legitimate Data Loader (sometimes rebranded, e.g. 'My Ticket Portal'). This grants the actor a durable OAuth/refresh token that survives password resets and, in many cases, MFA, enabling bulk querying and export of CRM data via the Salesforce REST/Bulk/GraphQL APIs without triggering traditional interactive-login anomaly detections. Once inside, operators pivot to Okta and Microsoft 365 using harvested credentials, and delay extortion demands (branded 'ShinyHunters', operationally handled by UNC6240) by weeks to months after the initial breach, suggesting a data-stockpiling strategy before a 72-hour Bitcoin-ransom ultimatum is issued via phone and email, backed by a Tor-hosted data leak site. A parallel and overlapping supply-chain vector (tracked as UNC6395) compromised OAuth/refresh tokens for the Salesloft Drift third-party integration between August 8 and August 18, 2025, giving attackers programmatic access to ~760 downstream Salesforce customer orgs; the actors specifically harvested secondary credentials (AWS AKIA access keys, Snowflake tokens, passwords) staged inside CRM case/support records, indicating credential-harvesting-for-further-compromise as a core objective, not merely CRM data theft. Google's Threat Intelligence Group has stated it has not found compelling evidence directly linking UNC6395 to ShinyHunters despite the group's public claims. A third, related vector abused misconfigured Salesforce Experience Cloud 'Aura' guest-user API endpoints with GraphQL-based requests to bulk-retrieve data beyond intended guest-access limits (observed June 19-22, 2026, and more broadly since March 2026, ~400 victims). Additional supply-chain compromises hit Gainsight's published Salesforce connected app (November 2025, 200+ instances) and Klue (June 2026, credential theft enabling direct Salesforce API queries, e.g. from IP 138.226.246.94 on June 11, 2026). Microsoft explicitly states none of this stems from a Salesforce platform vulnerability — it is entirely OAuth-trust and configuration abuse. ShinyHunters operates as part of a broader, fluid criminal collaboration ecosystem alongside Scattered Spider (UNC3944) and Lapsus$ remnants, publicly referred to as 'Scattered Lapsus$ Hunters' / 'Sp1d3rHunters', and has claimed 40+ breaches in 2026 alone across retail, education, manufacturing, technology, finance, luxury retail, telecom, healthcare, and critical infrastructure sectors.
MITRE ATT&CK techniques used in TL-2026-1275
Collection
T1005 Data from Local System; T1119 Automated Collection; T1213.004 Customer Relationship Management Software
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage
Credential Access
T1056 Input Capture; T1110.004 Credential Stuffing; T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation
Command and Control
T1071.001 Web Protocols; T1090.003 Multi-hop Proxy
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566.004 Spearphishing Voice
Discovery
T1087 Account Discovery; T1526 Cloud Service Discovery
Persistence
T1098 Account Manipulation; T1671 Cloud Application Integration
collection
T1185 Browser Session Hijacking
Execution
Impact
T1491.001 Internal Defacement; T1657 Financial Theft
Lateral Movement
T1550 Use Alternate Authentication Material
lateral-movement
Resource Development
T1583.001 Domains; T1585 Establish Accounts
Reconnaissance
reconnaissance
stealth
Affected products and versions in ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against
- Salesforce — Salesforce CRM / Connected Apps / Experience Cloud (Aura)
Vulnerable versions: all instances with permissive Connected App / guest-user configurations
Fixed in: N/A - configuration/process hardening, not a patch - Salesloft — Drift (Salesforce integration)
Vulnerable versions: all customer instances connected prior to Aug 20 2025 token revocation
Fixed in: Drift app removed from AppExchange; all OAuth tokens revoked Aug 20, 2025 - Gainsight — Gainsight Salesforce Connected App
Vulnerable versions: published app versions prior to Nov 2025 compromise disclosure
Fixed in: N/A - Klue — Klue Salesforce Integration
Vulnerable versions: credentials compromised June 2026
Fixed in: N/A
Remediation for ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against
Immediate actions
- Revoke and re-authorize all Salesforce Connected App OAuth/refresh tokens for Salesloft Drift, Gainsight, and Klue integrations
- Audit Salesforce Connected Apps list and remove any unrecognized or unused apps, especially those named 'Data Loader' variants
- Restrict the 'API Enabled' and 'Manage Connected Apps' / 'Customize Application' permission sets to a minimal set of admins
- Enforce IP login range restrictions on Salesforce; block known commercial VPN/Tor egress ranges from authenticating
- Lock down Experience Cloud / Aura guest-user profile permissions to prevent unauthenticated bulk GraphQL queries
- Rotate any secondary credentials (AWS keys, Snowflake tokens, passwords) that may have been stored in Salesforce case/support records
Workarounds
- Temporarily disable Data Loader API access for non-essential users
- Require manual admin approval for all new connected-app authorizations rather than self-service consent
Longer-term hardening
- Deploy Salesforce Shield Event Monitoring with Real-Time Event Monitoring and Transaction Security Policies
- Connect Salesforce instances to a CASB (e.g. Microsoft Defender for Cloud Apps) for OAuth scope visibility and unused-app detection (90+ day inactivity)
- Implement a formal connected-app approval and risk-scoring workflow (0-100 risk scale) before granting OAuth consent
- Train IT support and helpdesk staff on vishing recognition; implement out-of-band callback verification for any 'IT support' request to authorize an app or reset MFA
- Establish vendor/supply-chain security review requirements for any third-party app requesting Salesforce OAuth scopes
Weaknesses (CWE) in ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against
CWE-287, CWE-284, CWE-863
Timeline of ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against
- Google Threat Intelligence Group publishes initial report on UNC6040 vishing campaign targeting Salesforce via impersonated Data Loader connected apps; discloses impact to Google's own corporate Salesforce instance.
- UNC6395 begins mass exploitation of stolen Salesloft Drift OAuth/refresh tokens to access approximately 760 downstream Salesforce customer instances, harvesting AWS keys, Snowflake tokens, and passwords from case data.
- UNC6395 Salesloft Drift token-abuse campaign window closes (activity observed Aug 8-18, 2025).
- Salesloft, working with Mandiant and Salesforce, revokes all active Drift OAuth access and refresh tokens; Salesforce removes Drift from AppExchange pending investigation.
- Scattered Lapsus$ Hunters (ShinyHunters-branded extortion arm) opens a Tor-hosted data leak site to pressure victims of the Salesforce-linked breaches into paying ransoms.
- Gainsight's published Salesforce connected app is compromised, exposing over 200 downstream Salesforce instances to persistent unauthorized API access.
- Attackers begin exploiting misconfigured Salesforce Experience Cloud (Aura) guest-user permissions via GraphQL requests to bulk-retrieve data beyond intended guest-access scope; roughly 400 victim organizations affected over this period.
- Klue platform credentials are stolen and abused to make direct Salesforce API queries from IP 138.226.246.94, extending the SaaS supply-chain compromise pattern to a third integration vendor.
- Focused Aura-framework guest-access attacks observed against multiple organizations from IPs 103.75.11.78 and 103.75.11.110, running through June 22, 2026.
- Concentrated Aura framework attack window (June 19-22, 2026) concludes.
- Microsoft publishes 'Defending SaaS-based applications against ShinyHunters' OAuth abuse,' detailing Defender for Cloud Apps enhancements for Salesforce connected-app risk scoring and near-real-time event visibility.
Sources cited for ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against
- Defending SaaS-based applications against ShinyHunters' OAuth abuse
- Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
- The Cost of a Call: From Voice Phishing to Data Extortion
- ShinyHunters and UNC6395: Inside the Salesforce and Salesloft Breaches
- ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
- Reviewing the Salesforce-Salesloft Drift OAuth Supply Chain Breach
- Salesloft Drift Breach: Everything You Need to Know
- UNC6395 targets Salesloft in Drift OAuth token theft campaign
- Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
- Google: Salesforce Attacks Stemmed From Third-Party App
- Google Salesforce Breach: A Deep dive into the chain and extent of the compromise
- What Salesforce Organizations Need to Know About ShinyHunters and Vishing
- ShinyHunters Threat Actor Profile: TTPs, IoCs & Attacks
- Extortion gang opens data leak site to squeeze victims of its Salesforce attacks
- Chaotic Scattered Shiny Lapsus$ Spider: Information Warfare
Threats related to ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- Klue OAuth Supply-Chain Breach Enables 'Icarus' Salesforce CRM Data-Theft Extortion Campaign
- ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments
- LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
Detection coverage for TL-2026-1275
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1275 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.