ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations

ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against (TL-2026-1275), also tracked as Scattered Lapsus$ Hunters OAuth Campaign, is a high-severity advanced persistent threat campaign, first published 2026-07-13. It is attributed to ShinyHunters with medium confidence, affects Salesforce Salesforce CRM / Connected Apps / Experience Cloud (Aura), maps to 30 MITRE ATT&CK techniques (T1005, T1020, T1056), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-1275

Threat ID
TL-2026-1275
Also known as
Scattered Lapsus$ Hunters OAuth Campaign, Salesforce Data Loader Impersonation Campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-07-13
Last reviewed
2026-07-13
Attribution
ShinyHunters
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
retail, education, manufacturing, technology, finance, luxury retail, telecoms, critical infrastructure, health, entertainment, government administration
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
21

Malware and tooling in ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against

Malware and tooling: AuraInspector, Salesforce Data Loader (impersonated/modified), ToogleBox Recall, Tox messaging protocol, TruffleHog - S9009

ShinyHunters, a financially motivated data extortion group operating under Google/Mandiant designations UNC6040 (intrusion), UNC6240 (extortion), and overlapping with UNC6395 (Salesloft Drift OAuth theft), has run a sustained campaign from mid-2025 through mid-2026 abusing OAuth trust relationships to compromise Salesforce environments and connected SaaS integrations (Salesloft/Drift, Gainsight, Klue).

How ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against works

ShinyHunters' Salesforce-focused campaign combines voice phishing (vishing), OAuth/connected-app abuse, and SaaS supply-chain compromise to achieve mass data exfiltration for extortion. In the vishing vector (tracked by Google Threat Intelligence Group as UNC6040), operators impersonate corporate IT support over the phone and walk victim employees through Salesforce's 'Connect an App' flow, guiding them to enter a connection code that authorizes an attacker-controlled OAuth application impersonating Salesforce's legitimate Data Loader (sometimes rebranded, e.g. 'My Ticket Portal'). This grants the actor a durable OAuth/refresh token that survives password resets and, in many cases, MFA, enabling bulk querying and export of CRM data via the Salesforce REST/Bulk/GraphQL APIs without triggering traditional interactive-login anomaly detections. Once inside, operators pivot to Okta and Microsoft 365 using harvested credentials, and delay extortion demands (branded 'ShinyHunters', operationally handled by UNC6240) by weeks to months after the initial breach, suggesting a data-stockpiling strategy before a 72-hour Bitcoin-ransom ultimatum is issued via phone and email, backed by a Tor-hosted data leak site. A parallel and overlapping supply-chain vector (tracked as UNC6395) compromised OAuth/refresh tokens for the Salesloft Drift third-party integration between August 8 and August 18, 2025, giving attackers programmatic access to ~760 downstream Salesforce customer orgs; the actors specifically harvested secondary credentials (AWS AKIA access keys, Snowflake tokens, passwords) staged inside CRM case/support records, indicating credential-harvesting-for-further-compromise as a core objective, not merely CRM data theft. Google's Threat Intelligence Group has stated it has not found compelling evidence directly linking UNC6395 to ShinyHunters despite the group's public claims. A third, related vector abused misconfigured Salesforce Experience Cloud 'Aura' guest-user API endpoints with GraphQL-based requests to bulk-retrieve data beyond intended guest-access limits (observed June 19-22, 2026, and more broadly since March 2026, ~400 victims). Additional supply-chain compromises hit Gainsight's published Salesforce connected app (November 2025, 200+ instances) and Klue (June 2026, credential theft enabling direct Salesforce API queries, e.g. from IP 138.226.246.94 on June 11, 2026). Microsoft explicitly states none of this stems from a Salesforce platform vulnerability — it is entirely OAuth-trust and configuration abuse. ShinyHunters operates as part of a broader, fluid criminal collaboration ecosystem alongside Scattered Spider (UNC3944) and Lapsus$ remnants, publicly referred to as 'Scattered Lapsus$ Hunters' / 'Sp1d3rHunters', and has claimed 40+ breaches in 2026 alone across retail, education, manufacturing, technology, finance, luxury retail, telecom, healthcare, and critical infrastructure sectors.

MITRE ATT&CK techniques used in TL-2026-1275

Collection

T1005 Data from Local System; T1119 Automated Collection; T1213.004 Customer Relationship Management Software

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage

Credential Access

T1056 Input Capture; T1110.004 Credential Stuffing; T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation

Command and Control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566.004 Spearphishing Voice

Discovery

T1087 Account Discovery; T1526 Cloud Service Discovery

Persistence

T1098 Account Manipulation; T1671 Cloud Application Integration

collection

T1185 Browser Session Hijacking

Execution

T1204.001 Malicious Link

Impact

T1491.001 Internal Defacement; T1657 Financial Theft

Lateral Movement

T1550 Use Alternate Authentication Material

lateral-movement

T1550.004 Web Session Cookie

Resource Development

T1583.001 Domains; T1585 Establish Accounts

Reconnaissance

T1589.003 Employee Names

reconnaissance

T1598.003 Spearphishing Link

stealth

T1684.001 Impersonation

Affected products and versions in ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against

  • Salesforce — Salesforce CRM / Connected Apps / Experience Cloud (Aura)
    Vulnerable versions: all instances with permissive Connected App / guest-user configurations
    Fixed in: N/A - configuration/process hardening, not a patch
  • Salesloft — Drift (Salesforce integration)
    Vulnerable versions: all customer instances connected prior to Aug 20 2025 token revocation
    Fixed in: Drift app removed from AppExchange; all OAuth tokens revoked Aug 20, 2025
  • Gainsight — Gainsight Salesforce Connected App
    Vulnerable versions: published app versions prior to Nov 2025 compromise disclosure
    Fixed in: N/A
  • Klue — Klue Salesforce Integration
    Vulnerable versions: credentials compromised June 2026
    Fixed in: N/A

Remediation for ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against

Immediate actions

  • Revoke and re-authorize all Salesforce Connected App OAuth/refresh tokens for Salesloft Drift, Gainsight, and Klue integrations
  • Audit Salesforce Connected Apps list and remove any unrecognized or unused apps, especially those named 'Data Loader' variants
  • Restrict the 'API Enabled' and 'Manage Connected Apps' / 'Customize Application' permission sets to a minimal set of admins
  • Enforce IP login range restrictions on Salesforce; block known commercial VPN/Tor egress ranges from authenticating
  • Lock down Experience Cloud / Aura guest-user profile permissions to prevent unauthenticated bulk GraphQL queries
  • Rotate any secondary credentials (AWS keys, Snowflake tokens, passwords) that may have been stored in Salesforce case/support records

Workarounds

  • Temporarily disable Data Loader API access for non-essential users
  • Require manual admin approval for all new connected-app authorizations rather than self-service consent

Longer-term hardening

  • Deploy Salesforce Shield Event Monitoring with Real-Time Event Monitoring and Transaction Security Policies
  • Connect Salesforce instances to a CASB (e.g. Microsoft Defender for Cloud Apps) for OAuth scope visibility and unused-app detection (90+ day inactivity)
  • Implement a formal connected-app approval and risk-scoring workflow (0-100 risk scale) before granting OAuth consent
  • Train IT support and helpdesk staff on vishing recognition; implement out-of-band callback verification for any 'IT support' request to authorize an app or reset MFA
  • Establish vendor/supply-chain security review requirements for any third-party app requesting Salesforce OAuth scopes

Weaknesses (CWE) in ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against

CWE-287, CWE-284, CWE-863

Timeline of ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against

  • Google Threat Intelligence Group publishes initial report on UNC6040 vishing campaign targeting Salesforce via impersonated Data Loader connected apps; discloses impact to Google's own corporate Salesforce instance.
  • UNC6395 begins mass exploitation of stolen Salesloft Drift OAuth/refresh tokens to access approximately 760 downstream Salesforce customer instances, harvesting AWS keys, Snowflake tokens, and passwords from case data.
  • UNC6395 Salesloft Drift token-abuse campaign window closes (activity observed Aug 8-18, 2025).
  • Salesloft, working with Mandiant and Salesforce, revokes all active Drift OAuth access and refresh tokens; Salesforce removes Drift from AppExchange pending investigation.
  • Scattered Lapsus$ Hunters (ShinyHunters-branded extortion arm) opens a Tor-hosted data leak site to pressure victims of the Salesforce-linked breaches into paying ransoms.
  • Gainsight's published Salesforce connected app is compromised, exposing over 200 downstream Salesforce instances to persistent unauthorized API access.
  • Attackers begin exploiting misconfigured Salesforce Experience Cloud (Aura) guest-user permissions via GraphQL requests to bulk-retrieve data beyond intended guest-access scope; roughly 400 victim organizations affected over this period.
  • Klue platform credentials are stolen and abused to make direct Salesforce API queries from IP 138.226.246.94, extending the SaaS supply-chain compromise pattern to a third integration vendor.
  • Focused Aura-framework guest-access attacks observed against multiple organizations from IPs 103.75.11.78 and 103.75.11.110, running through June 22, 2026.
  • Concentrated Aura framework attack window (June 19-22, 2026) concludes.
  • Microsoft publishes 'Defending SaaS-based applications against ShinyHunters' OAuth abuse,' detailing Defender for Cloud Apps enhancements for Salesforce connected-app risk scoring and near-real-time event visibility.

Sources cited for ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against

Threats related to ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against

Detection coverage for TL-2026-1275

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1275 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats