How trusted SaaS connections become a back door: lessons from the ShinyHunters OAuth campaign

Connecting a third-party application to Salesforce, Microsoft 365 or another SaaS platform can give that application continuing access to business data through OAuth permissions. Microsoft’s recent research shows why those trusted connections need the same scrutiny as user accounts.

In campaigns observed from mid-2025 to mid-2026, Microsoft identified activity using tradecraft commonly associated with ShinyHunters. Attackers abused approved OAuth relationships for data access, exfiltration and persistence. Importantly, Microsoft said the activity was not caused by an underlying Salesforce vulnerability. Microsoft’s analysis published in July 2026 describes affected organisations across sectors including retail, education and manufacturing.

How the attacks worked

Microsoft identified two primary intrusion paths: voice-phishing-driven OAuth consent abuse and compromise of trusted SaaS integrations.

In the first, attackers impersonated IT support and persuaded employees to approve attacker-controlled Salesforce applications, sometimes disguised as legitimate Data Loader tools. It is similar to the helpdesk impersonation scams aimed at London businesses, except the objective is application consent rather than simply obtaining a password.

The second path involved trusted suppliers. Compromised Salesloft Drift credentials in August 2025 enabled attackers to use OAuth tokens against customer Salesforce environments. A further campaign targeted Gainsight-published applications in November 2025. In June 2026, Microsoft also highlighted a Klue incident in which Salesforce credentials were used to discover, query and exfiltrate CRM data.

This is why the Marks and Spencer and Co-op attacks put supplier risk on the agenda.

Risk areaHow it can be abusedWhat to investigate
OAuth consentUser approves an attacker-controlled connected appNew apps, unusual publishers and excessive scopes
Supplier integrationCompromised vendor credentials or tokens inherit legitimate accessUnusual API queries and exports from trusted integrations
Guest accessOver-permissioned Salesforce guest access increases exposureGuest permissions and anomalous guest activity

Microsoft recommends securing Salesforce Experience Cloud guest-user access, but guest misconfiguration should be treated as a related security risk rather than one of the two primary ShinyHunters intrusion paths identified in the report.

Why normal sign-in monitoring is not enough

OAuth abuse can look legitimate because attackers operate through approved applications and inherited permissions. Microsoft observed bulk CRM queries and data exfiltration without traditional sign-in anomalies. This resembles the broader problem discussed in device code phishing in Microsoft 365: authentication controls alone do not provide complete visibility into what an authorised application subsequently does.

The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses experienced a cyber breach or attack in the previous 12 months, equivalent to approximately 612,000 UK businesses. Yet only 15% formally reviewed risks from immediate suppliers and just 6% reviewed their wider supply chain.

Our guide to what the breaches survey means for SMEs explains the wider implications.

What to check now

List every connected application and the permissions it holds. Remove applications that are unused, unrecognised or no longer required. Microsoft specifically recommends identifying highly privileged and inactive OAuth applications.

This also means revisiting the zombie tech audit and checking for shadow AI tools quietly sharing company data.

Restrict application consent where appropriate and use an administrator approval process for higher-risk requests. Microsoft Entra allows organisations to review and revoke permissions granted to enterprise applications.

Monitor API activity, report exports and connected-app behaviour as well as logins. Managed SOC services can support continuous cloud monitoring, while network penetration testing can identify what an attacker could reach after initial access.

Where suspicious activity has already occurred, cyber incident response becomes the priority. If exposed credentials surface elsewhere, knowing how to respond to a dark web alert can help teams act quickly.

Frequently asked questions

Does multi-factor authentication stop OAuth abuse?

Not by itself. MFA helps protect authentication, but a valid OAuth token or previously approved application can continue to access permitted resources without presenting a fresh MFA challenge for every API request. OAuth permissions, tokens and application activity therefore need separate monitoring.

How often should connected applications be reviewed?

There is no universal statutory interval. Quarterly reviews can be a practical starting point, alongside immediate checks when employees leave, suppliers change or applications are retired.

Is this only a Salesforce problem?

No. OAuth is widely used across SaaS platforms. Microsoft’s Defender documentation supports reviewing third-party OAuth applications across Microsoft 365, Google Workspace and Salesforce.

Where to start

If your business cannot currently identify every application with access to company data, begin with an inventory of applications, permissions, owners and last-use dates.

Northern Star can support this through IT consulting services in London and extend governance across overseas operations with global IT support for international projects.

Call +44 (0) 800 319 6032 or book a callback with our London team. You can also see how Northern Star works as a managed service provider in London.