Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-13 and was added to the RWP archive on 2026-09-07.
ShinyHunters is a brand over OAuth — Salesforce connected apps, not a new VPN 0-day
Microsoft 13 July 2026 plus GTIG SaaS guidance — vishing to approve a malicious connected app, plus Salesloft/Gainsight-class integration tokens. UNC6040/UNC6240/UNC6661 sit under the same leak-site paint. MFA that is not phishing-resistant does not stop this.
Bottom line up front
CONFIRMED as Microsoft 13 July 2026 (mid-2025 to mid-2026 campaigns) and GTIG’s SaaS-defense post: clusters painted as ShinyHunters (UNC6040 initial Salesforce vishing, UNC6240 later extortion, UNC6661 and kin) steal SaaS data by abusing trusted OAuth. Two paths: (1) helpdesk vishing that walks an employee into approving a malicious Salesforce connected app / Data Loader; (2) supply-chain tokens from integrations (Salesloft, Gainsight, similar) reused against many customer orgs. Microsoft: not a Salesforce RCE — OAuth relationship abuse. Extortion on the leak site after the theft. Cato: the brand outlasts forum seizures and arrests.
Do not merge every vishing Daily Top into this. UNC3753 (RMM) and UNC6671 (SSO device enroll) are cousins. This ticket is connected-app / integration-token theft.
PeopleSoft 0-day extortion in June 2026 (CVE-2026-35273, GTIG, higher-ed) is a related brand, different door — do not collapse it into OAuth.
What happened
The user says yes to an OAuth prompt on a recorded call. The app then is the exfil.
Why it matters
Salesforce, Workspace, and M365 connected apps are the new VPN. Allow-all OAuth is an open VLAN.
What is confirmed vs not
CONFIRMED Microsoft/GTIG TTPs.
REPORTED $20M demands / swatting in briefing decks — treat as GTIG/RH-ISAC color, verify per victim.
UNKNOWN one human crew vs franchise.
What defenders should do
- Allow-list connected apps; alert on every new OAuth grant.
- Phishing-resistant MFA for anyone who can approve apps.
- Rotate integration tokens after any SaaS ISV incident.
RWP assessment
Confidence: High on the OAuth path. The brand name is marketing; the grant log is evidence.
Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-13 and was added to the RWP archive on 2026-09-07.