top of page

Salesforce Customers Fall Victim as ShinyHunters and Scattered Spider Join Forces

  • Writer: Joseph K
    Joseph K
  • Aug 15, 2025
  • 1 min read

A coordinated social engineering campaign targeting Salesforce customers has exposed critical vulnerabilities in how enterprises secure their SaaS environments, demonstrating that authenticated users can become the most effective attack vector when manipulated by sophisticated threat actors.


The campaign, executed through an apparent collaboration between the established data extortion group ShinyHunters and social engineering specialists Scattered Spider (also known as UNC3944), has compromised dozens of high-profile organizations including Google, Cisco, LVMH brands, and Qantas. The attackers gained access to customer relationship management data by exploiting OAuth-based authorization for Salesforce Connected Apps through meticulously planned voice phishing attacks.






Comments


Recent Posts

Get In Touch

Want to learn more about our past work or

explore how we can support your current initiatives?

Reach out today and let Fiduciary Tech be your trusted partner.

Headquarters

1100 106th Avenue NE, Suite 101F
Bellevue, WA 98004
425-998-8505

info@fiduciarytech.com

Seoul Office

Address: Geunshin Building 506-1, 20 Samgae-ro, Mapo-gu, Seoul, 04173, Republic of Korea
02-71
2-2227

info@fiduciarytech.com

fiduciary technology consulting

© 2026 by Fiduciary Technology Solutions 

bottom of page