Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-13 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity & Cloud

ShinyHunters is a brand over OAuth — Salesforce connected apps, not a new VPN 0-day

Microsoft 13 July 2026 plus GTIG SaaS guidance — vishing to approve a malicious connected app, plus Salesloft/Gainsight-class integration tokens. UNC6040/UNC6240/UNC6661 sit under the same leak-site paint. MFA that is not phishing-resistant does not stop this.

RWP Ventures · 2026-09-07 · event 2026-07-13 · 1 min read · priority 8.3

Bottom line up front

CONFIRMED as Microsoft 13 July 2026 (mid-2025 to mid-2026 campaigns) and GTIG’s SaaS-defense post: clusters painted as ShinyHunters (UNC6040 initial Salesforce vishing, UNC6240 later extortion, UNC6661 and kin) steal SaaS data by abusing trusted OAuth. Two paths: (1) helpdesk vishing that walks an employee into approving a malicious Salesforce connected app / Data Loader; (2) supply-chain tokens from integrations (Salesloft, Gainsight, similar) reused against many customer orgs. Microsoft: not a Salesforce RCE — OAuth relationship abuse. Extortion on the leak site after the theft. Cato: the brand outlasts forum seizures and arrests.

Do not merge every vishing Daily Top into this. UNC3753 (RMM) and UNC6671 (SSO device enroll) are cousins. This ticket is connected-app / integration-token theft.

PeopleSoft 0-day extortion in June 2026 (CVE-2026-35273, GTIG, higher-ed) is a related brand, different door — do not collapse it into OAuth.

What happened

The user says yes to an OAuth prompt on a recorded call. The app then is the exfil.

Why it matters

Salesforce, Workspace, and M365 connected apps are the new VPN. Allow-all OAuth is an open VLAN.

What is confirmed vs not

CONFIRMED Microsoft/GTIG TTPs.

REPORTED $20M demands / swatting in briefing decks — treat as GTIG/RH-ISAC color, verify per victim.

UNKNOWN one human crew vs franchise.

What defenders should do

  1. Allow-list connected apps; alert on every new OAuth grant.
  2. Phishing-resistant MFA for anyone who can approve apps.
  3. Rotate integration tokens after any SaaS ISV incident.

RWP assessment

Confidence: High on the OAuth path. The brand name is marketing; the grant log is evidence.

Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-13 and was added to the RWP archive on 2026-09-07.

Sources

  1. Microsoft — Defending SaaS against ShinyHunters OAuth abuse
  2. GTIG — Defending against ShinyHunters cybercrime targeting SaaS
  3. Cato CTRL — ShinyHunters brand that outlasts takedowns