ShinyHunters
A financially motivated data-theft and extortion collective, active since 2020, now running the largest OAuth and vishing campaign against Salesforce environments on record.
Actor Profile
Origin & structure
ShinyHunters surfaced in May 2020 with a two-week breach spree, hitting Tokopedia, Microsoft's GitHub repos, and Wattpad first. It's led by a persona known as ShinyCorp, took over BreachForums after its founder's 2023 arrest, and kept operating after the FBI seized the forum in October 2025.
Targeting philosophy
Early breaches (2020–21) were opportunistic database theft; by 2024 the group had pivoted to supply-chain access brokering (Snowflake/EPAM), and since mid-2025 to Salesforce specifically. One vendor-integration compromise (Drift, Gainsight, Anodot) now routinely nets hundreds of downstream victims in a single move.
Extortion model
Pay-or-leak: a private ransom demand first, then public auction, leak-site posting, DDoS, and harassment if refused. Reporting also points to an emerging ransomware-as-a-service-style structure.
Timeline of Activity
Public debut
Breach spree hits Tokopedia, Microsoft's GitHub repos, and Wattpad within two weeks.
Raoult arrest & sentencing
French national Sébastien Raoult is arrested, then sentenced in 2024, the group's biggest legal setback.
Snowflake supply-chain campaign
A compromised EPAM endpoint cascades into ~160 orgs, including AT&T, Ticketmaster, and Santander.
Salesforce vishing begins; French arrests
Google tracks the campaign as UNC6040/UNC6240; four suspects are arrested in France.
Drift token theft & JLR breach
Stolen Drift tokens expose ~760 orgs; Jaguar Land Rover's shutdown is jointly claimed with Scattered Spider.
BreachForums seized; Gainsight abuse
The FBI seizes BreachForums; stolen Gainsight tokens expose 200+ more Salesforce instances.
Coinbase extortion attempt
An insider-enabled breach leads to a $20M ransom demand, which Coinbase refuses.
Experience Cloud campaign & Anodot breach
Automated scanning drives mass extortion; an Anodot breach reaches Rockstar Games and Zara.
Klue breach & campaign mapped
A forgotten Klue credential exposes more victims; Microsoft formally maps the year-long campaign.
Kill Chain & MITRE ATT&CK Mapping
ShinyHunters' kill chain barely touches malware. The group operates almost entirely inside legitimate SaaS trust relationships, which makes this a harder chain to signature and a more useful one to map behaviorally.
Initial Access
Operators vishing-call employees into authorizing a fraudulent OAuth app spoofing Salesforce's "Data Loader" tool.
Compromises a shared SaaS integration vendor (Drift, Gainsight, Anodot) to inherit access to all its downstream customers.
Execution & Persistence
Stolen OAuth refresh tokens are reused directly against Salesforce, BigQuery, and Snowflake APIs.
Operators delete MFA-enrollment alerts in some Okta-linked environments to hide new device registration.
Discovery & Defense Evasion
Automated tooling ("AuraInspector") scans for misconfigured, publicly exposed Salesforce portals at scale.
Legitimate OAuth grants and API tokens let activity blend into normal SaaS traffic by default.
Collection & Exfiltration
Bulk API pulls against Salesforce, SharePoint, and connected data stores extract records straight through sanctioned interfaces, with no separate exfil channel needed.
Impact
Standard pay-or-leak pressure: ransom demand, deadline threats, DDoS, and leak-site publication if refused.
Tooling & named artifacts
Indicators of Compromise
Almost no malware artifacts to hash, since the intrusion path is a phone call and an OAuth consent screen. What follows are the durable, publicly reported patterns instead.
Reported patterns & behavior
| Indicator / Behavior | Type | Notes |
|---|---|---|
| "Data Loader" (fraudulent) | OAuth app name | Spoofs Salesforce's own tool; requests broad, full-access scopes |
| Typosquat Salesforce domains | Domain pattern | Naming conventions flagged by ReliaQuest across 2025 phishing infra |
| New OAuth grant, broad scope | Behavior | Especially soon after a help-desk interaction |
| Anomalous Bulk API volume | Behavior | Atypical data pulls outside normal integration patterns |
| MFA-enrollment suppression | Behavior | Missing new-device alerts in Okta-linked environments |
Detection & Mitigation Priorities
Ordered by impact-to-effort ratio for a mid-sized enterprise.
- P1Require admin approval for new OAuth grants in Salesforce and verify any "Data Loader" integration is genuine.
- P1Harden help-desk identity verification against vishing.
- P1Enable Salesforce Shield / Real-Time Event Monitoring for anomalous Bulk API activity.
- P2Inventory and rotate tokens for every third-party SaaS integration; deprovision disused ones.
- P2Alert on suppressed MFA-enrollment notifications, especially in Okta-linked environments.
- P3Prepare an extortion response playbook in advance, including legal, comms, and law enforcement contacts.
References
- 01ShinyHunters Threat Actor Profile: TTPs, IoCs & AttacksHuntress
- 02ShinyHunters' OAuth Pivot: A Year of SaaS Supply-Chain BreachesCloud Security Alliance
- 03Microsoft Maps Three Salesforce Attack Paths Tied to ShinyHuntersThe Hacker News
- 04Defending SaaS-Based Applications Against ShinyHunters OAuth AbuseMicrosoft Security
- 05ShinyHunters Targets Salesforce Amid Scattered Spider CollaborationReliaQuest
- 06ShinyHunters Calling: Financially Motivated Data Extortion GroupEclecticIQ
- 07Cybersecurity Alert: Salesforce Experience Cloud Security IncidentFINRA