Microsoft mapped a year-long campaign tied to ShinyHunters-linked activity that appears to have moved through OAuth trust rather than a Salesforce platform flaw.
A Salesforce OAuth trust relationship can outlive the login that created it, letting attackers move through CRM data without repeatedly facing MFA.
A reported abuse of OAuth-linked SaaS trust shows how one third-party integration can become a quiet path to CRM data.