Microsoft has mapped three attack paths ShinyHunters has been using over the past year to target Salesforce environments.
The three paths
Vishing calls that trick employees into approving a malicious connected app.
Stolen OAuth tokens from compromised software vendors.
Misconfigured guest access to Salesforce sites.
Microsoft has worked with Salesforce to release new detection and governance tooling to help companies identify this activity.
Why identity teams should care
The attackers did not exploit a flaw in Salesforce. That is the whole point. All three paths are delegated access left over-permissioned or no longer monitored, which makes this a third-party trust problem wearing a SaaS security costume.
Third-party trust is also the control surface with the least clear ownership in most organisations. The connected app was approved by an employee, the vendor token was issued by procurement's chosen supplier, and the guest access was configured by whoever built the site. None of those people are on the identity team, and the identity team is who gets the incident.
Delegated access does not decay on its own. It has to be reviewed by someone, and that someone is usually nobody.
Three questions worth answering this quarter
Who can approve a connected app, and does anyone review those approvals afterwards? If an employee can consent on their own, consent is your perimeter.
Which vendors hold live OAuth tokens into your tenant? And would you find out if one of them were breached before they told you?
What does guest access reach? Guest configurations are usually set once, during a project, by someone optimising for the site working rather than for least privilege.
Source
Microsoft maps year-long ShinyHunters campaign against Salesforce, The Hacker News