ShinyHunters abused trusted Salesforce connections to steal company data, prompting Microsoft security upgrades. Here’s how the attack worked, why it matters, and how you can protect your online accounts today.
Table of Contents
What Happened?
Microsoft published the changes on July 13, 2026, after observing attacks from mid-2025 through mid-2026.
The upgrades add faster detection, clearer details about connected apps, and stronger controls over the permissions those apps receive.
Microsoft said the activity came from abused trusted connections, not a security flaw inside Salesforce.
The ShinyHunters attacks show how criminals can reach large amounts of data through one trusted business connection. That information may later help them create convincing phishing emails, fake support calls, or account alerts.
Your information may also have been leaked in another breach or data leak without you knowing.
Automatic monitoring for data leaks can help you find problems before suspicious messages or account activity appear.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Stolen?
Microsoft observed related activity across retail, education, and manufacturing organizations.
TechRadar reported that Google knew of more than 700 potentially affected organizations. However, the exact number of confirmed victims remains unknown.
Attackers searched and copied Salesforce customer relationship management records, which companies use to organize customer and business information.
Microsoft did not publish a full list of stolen fields, so the exact information taken remains unclear.
Because these systems organize customer and business information, stolen records can help criminals create more believable messages.
How ShinyHunters Abused Trusted Salesforce Connections
First, attackers called workers and pretended to be IT support.
They convinced some targets to approve a fake Salesforce Data Loader app.
OAuth is a permission system that lets one app access information in another service without receiving your password.
Once approved, the attackers’ app could use official Salesforce tools to search and copy data.
Later, ShinyHunters targeted software providers connected to Salesforce, including Salesloft and Gainsight.
Attackers stole OAuth tokens or integration secrets, which work like digital passes between connected services.
That allowed one stolen connection to reach many customer environments.
Because the activity used normal sign-ins and official APIs, which let apps exchange data, it could look legitimate.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
