ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access — Threadlinqs Intelligence
As of 2026-07-14, ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access is a high-severity phishing threat attributed to ShinyHunters, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1311 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: ShinyHunters · FINANCIAL
Threat actors linked to ShinyHunters (tracked by Google as UNC6040, with follow-on extortion activity as UNC6240) run voice-phishing campaigns impersonating IT support to trick employees into
Microsoft and Google Threat Intelligence have mapped a year-long (mid-2025 to mid-2026) campaign of Salesforce compromises tied to the ShinyHunters extortion brand and the financially motivated cluster UNC6040. The campaign relies on abusing legitimate OAuth trust relationships rather than exploiting a software vulnerability, and manifests across three distinct attack paths.
The first and primary path is voice-phishing (vishing) driven OAuth consent abuse: attackers cold-call employees, impersonate internal IT support, and talk the victim through Salesforce's OAuth App Manager / connected-app authorization screen, guiding them to approve an attacker-controlled connected application disguised as the legitimate Salesforce Data Loader data-migration tool. Because Salesforce's connected-app OAuth flow inherits the authorizing user's existing privileges once consent is granted, the attacker receives full API-level access under that user's identity without needing a password or a second MFA prompt going forward. This access is durable — it persists via refresh tokens (grant type refresh_token/offline_access) until explicitly revoked — and produces API traffic that is largely indistinguishable from normal integration or user activity to conventional sign-in and authentication monitoring, since the requests originate from a real, previously-authenticated identity.
Once authorized, the connected app is used to enumerate Salesforce org metadata and objects, run SOQL queries (Query/QueryMore/QueryAll) and Bulk API jobs against high-value objects (Accounts, Contacts, Cases, Opportunities), and export records in bulk. Analysts observed the attackers specifically combing exfiltrated case/support text and account records for secondary secrets — plaintext AWS access keys, VPN credentials, Snowflake tokens, and other credentials — that enable lateral movement into adjacent SaaS and cloud environments (Okta, Microsoft 365/Entra ID), extending the blast radius well beyond the Salesforce tenant itself. Extortion demands, when made, are issued weeks to months after the initial data theft, consistent with a broker/monetization relationship between the initial-access cluster (UNC6040) and the ShinyHunters extortion brand (also associated with the UNC6240 designation for the extortion/leak-site operations).
The second attack path is supply-chain compromise of trusted third-party OAuth-integrated vendors whose connected apps hold standing, broadly-scoped access to customer Salesforce orgs. In August 2025, the cluster tracked as UNC6395 stole OAuth access and refresh tokens for the Salesloft Drift AI chatbot integration and used them, over roughly a ten-day window (Aug 9-17, 2025), to run automated SOQL queries and bulk exports against more than 700 downstream Salesforce customer environments (including named victims such as Cloudflare, Google, PagerDuty, Palo Alto Networks, Proofpoint, SpyCloud, Tanium, and Zscaler), again hunting for embedded secrets in support-case text. Salesloft and Salesforce jointly revoked all active Drift access/refresh tokens on August 20, 2025 and engaged Mandiant to investigate. The same abuse-of-trusted-integration pattern recurred with the Gainsight published Salesforce application in November 2025 and with the Klue competitive-intelligence integration in June 2026, in both cases using compromised or abused OAuth credentials belonging to the vendor application to reach many downstream customer orgs simultaneously, giving the actor's activity the outward appearance of legitimate vendor integration traffic.
The third attack path targets Salesforce Experience Cloud sites with misconfigured/over-permissioned Guest User (unauthenticated) access. Between June 19-22, 2026, actors chained requests against the Salesforce Aura framework's unauthenticated endpoints and layered GraphQL-based queries on top of them, which allowed them to bypass the normal per-request record-count limitations that guest-user API calls are subject t
Weaknesses (CWE)
CWE-287, CWE-863, CWE-284, CWE-306
Target sectors: retail, education, manufacturing, technology, finance
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1585, T1566.004, T1199, T1195.002, T1204.001, T1098.003, T1078.004, T1078.004, T1550.001