Year-long attack on Salesforce: three data-theft paths that bypass standard checks

Colleagues, I’d like to draw your attention to a cybersecurity topic.
Microsoft has described a year-long data-theft campaign targeting Salesforce, linked to ShinyHunters.
The attackers did not breach the platform directly; instead, they abused trusted integrations and access misconfigurations.
Key scenarios:
• vishing and consent to a malicious OAuth app;
• theft of OAuth tokens from vendors;
• access via incorrectly configured guest permissions.
Why it matters: MFA does not eliminate risk when access is granted through OAuth, integrations, or guest accounts.
I would review connected apps, unused tokens, and guest access. Have you already revisited these controls?

