Microsoft identified three distinct methods used by the data-extortion group ShinyHunters to infiltrate corporate Salesforce environments.

These attacks bypass core platform flaws by abusing trusted relationships and configurations to evade authentication monitoring.

Intrusion methods include voice-phishing for malicious app authorization and stealing OAuth tokens from compromised third-party vendors.

Hackers also exploit misconfigured guest user access on Salesforce sites.

The campaigns targeted organizations in the retail, education, and manufacturing sectors.

Microsoft and Salesforce are collaborating to enhance detection and security tools against these specific threats.