Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138) — Threadlinqs Intelligence
As of 2026-07-14, Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138) is a high-severity data breach threat attributed to ShinyHunters (UNC6040, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1288 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: ShinyHunters (UNC6040 · FINANCIAL
Microsoft, alongside Google GTIG/Mandiant, Cloudflare Cloudforce One, and Salesforce, mapped a year-long campaign (mid-2025 to mid-2026) by ShinyHunters-linked actor clusters targeting Salesforce
Between mid-2025 and mid-2026, ShinyHunters-affiliated actor clusters (tracked variously by Google GTIG as UNC6040 for initial access and UNC6240 for extortion, by Google as UNC6395 for the Drift OAuth-token theft, by Cloudflare Cloudforce One as GRUB1, and by Microsoft as Storm-3138 for the Klue incident) ran a sustained campaign against Salesforce customer environments that did not exploit any Salesforce platform vulnerability, but instead abused three distinct identity/OAuth trust paths.
Path 1 (vishing/malicious connected apps): English-speaking callers impersonating internal IT support socially engineered Salesforce end users into visiting Salesforce's legitimate 'connected app' authorization page and approving a rogue app (frequently disguised as a modified Salesforce Data Loader or generically named app such as 'My Ticket Portal'). Once a victim approved the OAuth consent screen, the attacker's application received a valid access/refresh token and could make Salesforce REST/Bulk API calls as that user indefinitely, enabling slow, low-noise, high-volume record exfiltration that produced no anomalous sign-in event because the underlying session belonged to a real, already-authenticated user.
Path 2 (stolen third-party OAuth tokens): Threat actors compromised the source-code repositories or CI pipelines of Salesforce ISV/integration vendors and harvested hardcoded or leaked OAuth client secrets and refresh tokens using tools such as TruffleHog. The Salesloft/Drift incident (root-caused to attacker access on Salesloft's GitHub organization as early as March 2025, with active token abuse identified August 8-18, 2025) exposed Drift's Salesforce, Slack, and Google Workspace integration tokens, giving attackers direct API access to an estimated 700+ downstream Salesforce customer orgs, including major security vendors (Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, Tenable, CyberArk, Elastic, BeyondTrust, JFrog, Rubrik, Cato Networks, Workiva). A near-identical follow-on compromise of Gainsight-published Salesforce apps in November 2025 affected 200-285 additional Salesforce instances (Atlassian, DocuSign, F5, GitLab, Malwarebytes, SonicWall, Thomson Reuters, Verizon among victims). A third vendor compromise, of Klue (tracked by Microsoft as Storm-3138, publicly claimed by an actor using the 'Icarus' handle) in June 2026, reused a legacy/abandoned test-integration credential to push a malicious code update that harvested customer OAuth tokens, affecting Klue's Salesforce-integrated customers including Huntress and Recorded Future.
Path 3 (Experience Cloud guest-access misconfiguration): In parallel, actors probed Salesforce Experience Cloud sites with overly permissive unauthenticated 'Guest User' profiles, using a reconnaissance/mass-scanning tool dubbed AuraInspector to enumerate exposed Aura/GraphQL API endpoints. Where guest-object permissions or sharing rules were misconfigured, attackers issued unauthenticated SOQL queries against the Aura controller and used cursor-based pagination to bypass Salesforce's standard 2,000-record query cap, bulk-extracting records (including support-case attachments containing AWS access keys, Snowflake tokens, and plaintext passwords) and deleting query-job history afterward to hinder forensic reconstruction.
All three paths converge on the same underlying detection gap Microsoft's report highlights: identity security programs (MFA, conditional access, session policies) are built around human logins, while OAuth connected apps, integration/service accounts, and API tokens sit largely outside those controls, are frequently over-permissioned, and in many orgs go unreviewed for months (Microsoft flagged connected apps inactive 90+ days that still retained live, unscoped permissions as a top risk indicator). Confirmed and reported victim organizations across the combined campaign include Google (June 2025), Chanel, Pandora, Adidas, Qantas, Allianz Life, multiple LVMH brands, Cloudflar
Weaknesses (CWE)
CWE-287, CWE-284, CWE-269, CWE-522
Target sectors: retail, education, manufacturing, technology, cybersecurity, financialservices, insurance, aviation, luxurygoods, healthcaretechnology
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1585.001, T1566.004, T1566.002, T1199, T1195.002, T1204.001, T1098.003, T1528