Analysis published in July 2026 maps three distinct attack paths into Salesforce environments, tied to roughly a year of activity by the same group. Read together, the value is not any individual path but the convergence.
Vishing to a connected-app authorisation. Misconfigured public portals exposing records to guest users. Compromised credentials reaching integrations. Three routes, three sets of controls, one objective — the customer database — and an organisation that closed one may still be open on the others.
Defenders Inherit The Vendor’s Taxonomy
A practical difficulty for anyone trying to act on this is that each research vendor publishes its own cluster names and its own path taxonomy. The same campaign appears under several designations, and reconciling them is work most security teams do not have capacity for.
The consequence is that an organisation can read three accurate reports and come away believing it has three problems, or one, depending on which it read first.
The Map Arrives After The Territory
A comprehensive map published in July, covering activity that began the previous year, is genuinely useful for the organisations not yet hit. For those already compromised it is a description of what happened.
That is not a criticism of the researchers, who cannot map a campaign before observing it. It is an argument for weighting architectural controls over threat intelligence: the tenant that restricted connected-app authorisation in 2025 did not need to know any of this.
This is an analysis file built on published vendor research, listed below. Path taxonomy and cluster naming are the vendors’ own. Corrections: corrections@forensicpost.com.