Desk live·
ForensicPost
Cloud/Method/File 26-0718

Vendor Analysis Maps Three ShinyHunters Attack Paths Into Salesforce Tenants

Vendor analysis published in July 2026 maps three distinct attack paths into Salesforce tied to a year of the same group’s activity. Publishing the map after the campaign is the recurring problem, not the exception.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetSalesforce tenants
ActorShinyHunters
D. Kennedy9 min readConfidence: high2 sources reviewed

Analysis published in July 2026 maps three distinct attack paths into Salesforce environments, tied to roughly a year of activity by the same group. Read together, the value is not any individual path but the convergence.

Vishing to a connected-app authorisation. Misconfigured public portals exposing records to guest users. Compromised credentials reaching integrations. Three routes, three sets of controls, one objective — the customer database — and an organisation that closed one may still be open on the others.

Defenders Inherit The Vendor’s Taxonomy

A practical difficulty for anyone trying to act on this is that each research vendor publishes its own cluster names and its own path taxonomy. The same campaign appears under several designations, and reconciling them is work most security teams do not have capacity for.

The consequence is that an organisation can read three accurate reports and come away believing it has three problems, or one, depending on which it read first.

The Map Arrives After The Territory

A comprehensive map published in July, covering activity that began the previous year, is genuinely useful for the organisations not yet hit. For those already compromised it is a description of what happened.

That is not a criticism of the researchers, who cannot map a campaign before observing it. It is an argument for weighting architectural controls over threat intelligence: the tenant that restricted connected-app authorisation in 2025 did not need to know any of this.

How we reported this

This is an analysis file built on published vendor research, listed below. Path taxonomy and cluster naming are the vendors’ own. Corrections: corrections@forensicpost.com.

Sources
  1. Microsoft maps three Salesforce attack paths tied to a year of ShinyHunters activityThe Hacker News
  2. How three techniques are behind ShinyHunters’ 2026 campaignsPush Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary