The breach pattern of 2026 gets your own staff to authorize the attacker

ShinyHunters' vishing-plus-OAuth playbook has breached 40+ organizations this year without breaking MFA. The controls that stop it are governance settings, not products, deployable by a mid-market Salesforce shop in a week.

VISHING CALL YOUR EMPLOYEE FAKE "DATA LOADER" OAUTH APP CONNECTED-APP ALLOWLIST AUTHORIZATION DENIED AT THE GATE GOVERNANCE, NOT PRODUCTS · ONE ADMIN-WEEK

The most productive breach pattern of 2026 does not break multifactor authentication. It convinces your own employees to hand the attacker an authorized session. Through June and July, the ShinyHunters extortion group, tracked by Google's Mandiant as UNC6240, has breached more than 40 organizations this year using a three-part playbook, and on July 13 Microsoft published an analysis mapping roughly a year of it (Microsoft Security Blog, Jul 13, 2026; The Hacker News, Jul 2026). The victims are not small: Charter Communications had about 4.9 million customer records exfiltrated from Salesforce after a single voice-phished employee's Microsoft Entra account was compromised, and Carnival saw roughly 6 million customers exposed through similar social engineering (TechCrunch, Jul 7, 2026).

The playbook, in three moves

Microsoft's write-up maps three attack paths into Salesforce environments (Microsoft Security Blog, Jul 13, 2026):

Notice what is absent: no zero-day, no malware on the endpoint, no cracked hash. Every step rides authorized functionality. That is why this pattern defeats security stacks that were purchased specifically to stop intrusions. There is no intrusion in the classic sense. The system worked as configured. The configuration was the vulnerability.

Why the defense is governance, not a product

The controls that break this playbook are administrative settings and procedures, which is both the good news and the reason they are neglected: nobody's budget line item says "OAuth governance."

For a mid-market Salesforce shop, the core set is deployable in roughly a week:

None of these requires a purchase order. All of them require someone senior deciding the inconvenience is worth it, which is why the pattern keeps working at companies with eight-figure security budgets and no OAuth allowlist.

The honest caveats

Two things we cannot tell you. First, whether your particular SaaS estate has equivalent consent-phishing paths outside Salesforce. The same OAuth logic applies to Microsoft 365 and Google Workspace, and Microsoft's guidance gestures the same direction, but each platform's controls differ in the details. Second, whether ShinyHunters' victim count is complete; extortion groups publicize selectively, and the 40+ figure is what has surfaced, not necessarily what exists.

What we can tell you: this is the rare threat where the complete, vendor-documented defense costs approximately one admin-week. If your CRM holds millions of customer records and end users can still authorize arbitrary connected apps, that gap is now the best-documented open door in your company. Close it before the next campaign cycle finds it.