
ShinyHunters-Style Vishing Tricks Staff Into OAuth Access
Microsoft reports attackers linked to ShinyHunters spent a year getting into corporate Salesforce data without exploiting Salesforce bugs. One key method was…
Microsoft reports multiple real-world campaigns (mid-2025 to mid-2026) where attackers used voice phishing and trusted SaaS integrations to gain access to customer Salesforce environments. The key pattern is abusing OAuth “connected apps” and trusted integrations so access looks legitimate, enabling quiet, large-scale CRM data theft and long-term persistence.
Microsoft documented a series of real-world campaigns, running from mid-2025 into mid-2026, sharing tradecraft linked to ShinyHunters. The core technique relied on vishing calls in which attackers impersonated internal IT support personnel and asked employees to authorize a connected app inside their Salesforce tenant. In several confirmed cases, the caller guided the victim step by step through the OAuth consent workflow, presenting the malicious application as a legitimate tool such as a Salesforce Data Loader.
Once a user approved the request, the attacker-controlled OAuth application inherited that user's permissions. This allowed threat actors to make API calls on behalf of the victim, enabling enumeration, persistence, and large-scale data exfiltration from the CRM environment.
The attack worked because it exploited trust rather than a technical flaw. A phone call from someone claiming to be IT support carries built-in credibility, and OAuth consent prompts are a normal, expected part of many workplace workflows. Because the resulting access came through an authorized integration rather than a suspicious login, the activity often appeared indistinguishable from legitimate integration behavior. This made it harder for standard sign-in monitoring to catch.
The pattern also escalated beyond direct vishing into supply-chain style compromise. Attackers targeted third-party SaaS vendors that integrate with Salesforce, using connection secrets and OAuth tokens to reach downstream customers without any direct contact.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They socially engineered employees into authorizing attacker-controlled connected apps through the OAuth consent workflow, which let them make API calls on behalf of the victim user without typical sign-in anomalies.
They impersonated internal IT support personnel and asked employees to approve a connected app, sometimes disguised as a legitimate Salesforce Data Loader tool.
Yes, the campaigns escalated into supply-chain style attacks targeting third-party SaaS vendors like Salesloft, Drift, and Gainsight that integrate with Salesforce, often using OAuth tokens.
Review newly authorized connected apps for excessive privileges, verify OAuth consent requests through known internal channels, and audit Salesforce guest-user permissions for unusual activity.
Imagine this: one phone call, you click OK once, and someone quietly siphons your entire Salesforce. ShinyHunters-linked campaigns are doing exactly this: vishing you, pretending to be IT, and walking you through an OAuth consent screen for a fake 'Salesforce Data Loader' connected app. The script sounds like this: 'Hi, this is IT support. We need you to authorize a Salesforce connected app so we can restore access.' If you click Allow, that OAuth app can quietly pull CRM data via API on your behalf, with no weird sign-ins. So if anyone calls saying, 'Approve this Salesforce connected app right now,' hang up and ping IT through Teams or the helpdesk portal before you touch that Allow button.

Microsoft reports attackers linked to ShinyHunters spent a year getting into corporate Salesforce data without exploiting Salesforce bugs. One key method was…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Sophos reports a real Microsoft Teams voice-phishing campaign where attackers pretended to be IT support to convince employees to start remote-access sessions.…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…