Defending SaaS-based applications against ShinyHunters OAuth abuse
Reported 14 Jul 2026 by otx · Severity: medium
Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into autho