Defending SaaSbased applications against ShinyHunters OAuth abuse

From Microsoft Security Research and Microsoft Defender Security Research Team In a series of campaigns observed between mid2025 and mid2026 Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters including voice phishing vishing supply chain compromise and misconfigured guest access to target customer SaaSbased applications such as Salesforce instances The threat actors Source