Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Defending SaaS-based applications against ShinyHunters OAuth abuse

0
Medium
Published: 07/14/2026 (07/14/2026, 02:38:48 UTC)
Source: AlienVault OTX General

Description

Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into authorizing malicious OAuth applications. Supply chain compromises leveraged trusted integrations including Salesloft, Gainsight, and Klue to obtain OAuth tokens for downstream customer access. Misconfigured guest access enabled exploitation of Aura framework functionality for unauthorized data queries. These techniques abused legitimate OAuth relationships to inherit user and application privileges, enabling enumeration and exfiltration of CRM data while evading authentication detections. The campaigns targeted multiple industries including retail, education, and manufacturing, highlighting risks in OAuth-connected applications and third-party integrations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 12:41:39 UTC

Technical Analysis

This campaign involved ShinyHunters-linked threat actors abusing OAuth authorization mechanisms in SaaS applications, primarily Salesforce. The attackers used three main intrusion vectors: (1) voice phishing (vishing) to deceive employees into approving malicious OAuth applications, (2) supply chain compromises of trusted integrations such as Salesloft, Gainsight, and Klue to acquire OAuth tokens for downstream access, and (3) exploitation of misconfigured guest access in the Aura framework to perform unauthorized data queries. By abusing legitimate OAuth relationships, attackers inherited user and application privileges, enabling enumeration and exfiltration of CRM data while bypassing authentication detection controls. The campaign targeted multiple industries, emphasizing the security challenges posed by OAuth abuse and third-party integration vulnerabilities in SaaS environments.

Potential Impact

The abuse of OAuth tokens and legitimate application privileges enabled unauthorized access to sensitive CRM data, including enumeration and data exfiltration. The use of voice phishing and supply chain compromises increased the attack surface and complexity of detection. Multiple industries were affected, potentially resulting in data breaches and loss of customer trust. There were no known exploits in the wild reported at the time of publication.

Defensive Guidance

No official patch or fix is available because this is an abuse of legitimate OAuth mechanisms and misconfigurations rather than a software vulnerability. Organizations should strengthen OAuth app authorization processes, enhance employee awareness to prevent voice phishing attacks, audit and secure third-party integrations, and review guest access configurations in frameworks like Aura. Monitoring OAuth app approvals and enforcing strict least-privilege access controls are recommended to mitigate such abuse.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/"]
Adversary
ShinyHunters
Pulse Id
6a55a1380d4e12c0ea409b6e
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip103.75.11.78
CC=AU ASN=AS136557 host universal pty ltd
ip138.226.246.94
ip212.86.125.24
ip94.154.32.160
ip213.111.148.90
CC=UA ASN=AS35804 pp sks-lugan
ip103.75.11.110
CC=AU ASN=AS136557 host universal pty ltd

Threat ID: 6a55f7a868715ace4323278a

Added to database: 07/14/2026, 08:47:36 UTC

Last enriched: 08/13/2026, 12:41:39 UTC

Last updated: 08/27/2026, 16:35:07 UTC

Views: 156

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses