ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access
ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for (TL-2026-1311), also tracked as Salesforce OAuth Connected-App Vishing Campaign, is a high-severity phishing campaign, first published 2026-07-14. It is attributed to ShinyHunters with medium confidence, affects Salesforce Salesforce CRM (Connected Apps / OAuth), maps to 21 MITRE ATT&CK techniques (T1048, T1078.004, T1087.004), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-1311
- Threat ID
- TL-2026-1311
- Also known as
- Salesforce OAuth Connected-App Vishing Campaign, Data Loader Impersonation Attack, Salesloft Drift OAuth Breach, UNC6040 Salesforce Vishing
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- ShinyHunters
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- retail, education, manufacturing, technology, finance
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for
Malware and tooling: Fake Salesforce Data Loader connected app, Salesforce Data Loader (impersonated)
Threat actors linked to ShinyHunters (tracked by Google as UNC6040, with follow-on extortion activity as UNC6240) run voice-phishing campaigns impersonating IT support to trick employees into authorizing malicious OAuth connected apps disguised as Salesforce's own Data Loader tool. A single OAuth approval grants the attacker the authorizing user's full Salesforce privileges without further password prompts, enabling persistent API-level access to enumerate instances, exfiltrate CRM data, and pivot into Okta/Microsoft 365, while evading standard sign-in monitoring.
How ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for works
Microsoft and Google Threat Intelligence have mapped a year-long (mid-2025 to mid-2026) campaign of Salesforce compromises tied to the ShinyHunters extortion brand and the financially motivated cluster UNC6040. The campaign relies on abusing legitimate OAuth trust relationships rather than exploiting a software vulnerability, and manifests across three distinct attack paths.
The first and primary path is voice-phishing (vishing) driven OAuth consent abuse: attackers cold-call employees, impersonate internal IT support, and talk the victim through Salesforce's OAuth App Manager / connected-app authorization screen, guiding them to approve an attacker-controlled connected application disguised as the legitimate Salesforce Data Loader data-migration tool. Because Salesforce's connected-app OAuth flow inherits the authorizing user's existing privileges once consent is granted, the attacker receives full API-level access under that user's identity without needing a password or a second MFA prompt going forward. This access is durable — it persists via refresh tokens (grant type refresh_token/offline_access) until explicitly revoked — and produces API traffic that is largely indistinguishable from normal integration or user activity to conventional sign-in and authentication monitoring, since the requests originate from a real, previously-authenticated identity.
Once authorized, the connected app is used to enumerate Salesforce org metadata and objects, run SOQL queries (Query/QueryMore/QueryAll) and Bulk API jobs against high-value objects (Accounts, Contacts, Cases, Opportunities), and export records in bulk. Analysts observed the attackers specifically combing exfiltrated case/support text and account records for secondary secrets — plaintext AWS access keys, VPN credentials, Snowflake tokens, and other credentials — that enable lateral movement into adjacent SaaS and cloud environments (Okta, Microsoft 365/Entra ID), extending the blast radius well beyond the Salesforce tenant itself. Extortion demands, when made, are issued weeks to months after the initial data theft, consistent with a broker/monetization relationship between the initial-access cluster (UNC6040) and the ShinyHunters extortion brand (also associated with the UNC6240 designation for the extortion/leak-site operations).
The second attack path is supply-chain compromise of trusted third-party OAuth-integrated vendors whose connected apps hold standing, broadly-scoped access to customer Salesforce orgs. In August 2025, the cluster tracked as UNC6395 stole OAuth access and refresh tokens for the Salesloft Drift AI chatbot integration and used them, over roughly a ten-day window (Aug 9-17, 2025), to run automated SOQL queries and bulk exports against more than 700 downstream Salesforce customer environments (including named victims such as Cloudflare, Google, PagerDuty, Palo Alto Networks, Proofpoint, SpyCloud, Tanium, and Zscaler), again hunting for embedded secrets in support-case text. Salesloft and Salesforce jointly revoked all active Drift access/refresh tokens on August 20, 2025 and engaged Mandiant to investigate. The same abuse-of-trusted-integration pattern recurred with the Gainsight published Salesforce application in November 2025 and with the Klue competitive-intelligence integration in June 2026, in both cases using compromised or abused OAuth credentials belonging to the vendor application to reach many downstream customer orgs simultaneously, giving the actor's activity the outward appearance of legitimate vendor integration traffic.
The third attack path targets Salesforce Experience Cloud sites with misconfigured/over-permissioned Guest User (unauthenticated) access. Between June 19-22, 2026, actors chained requests against the Salesforce Aura framework's unauthenticated endpoints and layered GraphQL-based queries on top of them, which allowed them to bypass the normal per-request record-count limitations that guest-user API calls are subject to and extract far larger volumes of org data than the guest-access design was intended to permit.
Victims span retail, education, and manufacturing sectors, and the campaign's scale (per ShinyHunters' own, unverified claims) reportedly reached close to 1,000 organizations across the Salesloft/Drift and Gainsight waves combined. No CVE applies: this is abuse of legitimate OAuth/connected-app and guest-access functionality, not a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1311
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Persistence
T1078.004 Cloud Accounts; T1098.003 Additional Cloud Roles
Privilege Escalation
Defense Evasion
Discovery
T1087.004 Cloud Account; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery
Command and Control
Collection
T1119 Automated Collection; T1530 Data from Cloud Storage
Initial Access
T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship; T1566.004 Spearphishing Voice
Execution
Impact
T1485 Data Destruction; T1657 Financial Theft
Credential Access
T1528 Steal Application Access Token; T1552.001 Credentials In Files
lateral-movement
T1550.001 Application Access Token
Lateral Movement
T1550.001 Application Access Token
Resource Development
Reconnaissance
Affected products and versions in ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for
- Salesforce — Salesforce CRM (Connected Apps / OAuth)
Vulnerable versions: all orgs with connected-app OAuth authorization enabled
Fixed in: N/A - mitigated via API Access Control policy, not a patch - Salesforce — Experience Cloud (Guest User / Aura framework)
Vulnerable versions: orgs with misconfigured Guest User object/field permissions
Fixed in: N/A - mitigated via configuration hardening - Salesloft — Drift AI chatbot Salesforce integration
Vulnerable versions: all customer integrations prior to Aug 20 2025 token revocation
Fixed in: tokens revoked 2025-08-20; re-issued under stricter scope - Gainsight — Salesforce published application
Vulnerable versions: customer orgs with Gainsight connected app installed, Nov 2025
Fixed in: N/A - remediation via credential rotation - Klue — Salesforce competitive-intelligence integration
Vulnerable versions: customer orgs with Klue integration active, June 2026
Fixed in: N/A - remediation via credential rotation
Remediation for ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for
Immediate actions
- Revoke unused and unrecognized Salesforce connected-app OAuth approvals org-wide
- Immediately revoke Salesloft Drift, Gainsight, and Klue OAuth tokens/API keys if still active and re-issue with scoped, monitored credentials
- Enable Salesforce API Access Control and switch to deny-by-default: 'For admin-approved users, limit API access to only allowed connected apps'
- Block/monitor the published IOC IP ranges at the network egress and SIEM layer
- End any inbound call requesting OAuth approval, Salesforce credential reset, or vendor access changes; verify independently via known-good contact channels before acting
Workarounds
- Restrict Salesforce login by IP range and enable 'Enforce login IP ranges on every request' in Session Settings
- Secure Experience Cloud Guest User profiles: remove 'View All'/'Modify All', disable unnecessary object/field access, and audit Aura/GraphQL endpoint exposure
- Run Salesforce Security Health Check and remediate all flagged misconfigurations
Longer-term hardening
- Implement live video / government-ID identity proofing for help-desk password and MFA reset requests
- Enforce phishing-resistant MFA (FIDO2/WebAuthn) via corporate SSO (Entra ID, Okta) for all Salesforce access
- Disable or time-box dormant connected apps and integrations after 90 days of inactivity
- Move OAuth client secrets and API keys to a centralized secrets manager with short-lived, rotated credentials and IP allow-listing
- Set Organization-Wide Defaults to Private for sensitive objects and use Restriction Rules for row-level security instead of relying on Role Hierarchy
Weaknesses (CWE) in ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for
CWE-287, CWE-863, CWE-284, CWE-306
Timeline of ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for
- UNC6395 begins using stolen Salesloft Drift OAuth access/refresh tokens to systematically query and export data from over 700 downstream Salesforce customer environments via automated SOQL queries and bulk exports.
- Salesloft, in collaboration with Salesforce, revokes all active access and refresh tokens associated with the Drift application and engages Mandiant to investigate.
- Actors abuse the Gainsight published Salesforce application, maintaining persistent API access across multiple customer Salesforce instances via the compromised connected app.
- Klue competitive-intelligence Salesforce integration is abused; observed API calls from IOC IP 138.226.246.94 against customer instances.
- Actors begin chaining unauthenticated Salesforce Aura framework requests with GraphQL queries to bypass guest-user record-retrieval limits, sourced from IOC IPs 103.75.11.78 and 103.75.11.110.
- Observed window of Aura/GraphQL guest-access abuse campaign activity concludes.
- The Hacker News reports on Microsoft's mapping of the year-long ShinyHunters Salesforce campaign.
- Microsoft Security publishes 'Defending SaaS-based applications against ShinyHunters OAuth abuse,' mapping three distinct Salesforce attack paths observed over the prior year and detailing new Defender for Cloud Apps detection coverage.
- Cyber Security News publishes 'One Malicious OAuth Approval Can Give Hackers Persistent Access to Salesforce Data,' summarizing the vishing/Data Loader-impersonation OAuth abuse TTP for a general audience.
Sources cited for ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for
- One Malicious OAuth Approval Can Give Hackers Persistent Access to Salesforce Data
- Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
- Defending SaaS-based applications against ShinyHunters OAuth abuse
- Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations
- Investigate how the ShinyHunters used vishing to compromise Salesforce instances
- Detecting ShinyHunters/UNC6040 Vishing Campaigns in Salesforce OAuth Attacks
- ShinyHunters and UNC6395: Inside the Salesforce and Salesloft Breaches
- ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data
- Active Exploitation Alert: ShinyHunters Abuse OAuth and Vendor Integrations to Breach Salesforce and SaaS Environments
- What Salesforce Organizations Need to Know About ShinyHunters and Vishing
- Reviewing the Salesforce–Salesloft Drift OAuth Supply Chain Breach
- Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
Threats related to ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- Klue OAuth Supply-Chain Breach Enables 'Icarus' Salesforce CRM Data-Theft Extortion Campaign
- LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)
- ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts
Detection coverage for TL-2026-1311
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1311 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.