The Human Layer Under Attack: How ShinyHunters Turned SaaS Trust Into a Cyberattack Weapon

When a Login Portal Becomes an Extortion Message

As thousands of students and faculty attempted to log into their university learning portals, familiar Canvas login pages suddenly displayed a chilling ransom message threatening the public release of stolen academic data.

Source: BleepingComputer

What first appeared to be a temporary platform outage quickly turned into one of the most disruptive cyberattacks on the education sector in recent years, affecting hundreds of institutions and exposing the growing risks associated with interconnected SaaS environments. The attackers defaced login portals, issued extortion demands, and allegedly stole millions of student and staff records across schools and universities. At the center of the campaign stood ShinyHunters, one of the most persistent and aggressive cybercriminal groups operating today.

Who Is ShinyHunters?

ShinyHunters first showed up in the spotlight through a string of high-profile breaches and data trading on underground forums. In 2025, they were back again, this time going after Salesforce environments at scale, which really pushed SaaS security back into the conversation.

What stood out in this campaign was not sophistication in the traditional sense, but the entry point. There was no classic “breaking in.” Instead, attackers leaned heavily on voice phishing and social engineering, posing as IT support and getting employees to approve malicious connected apps. And that’s really the turning point. Once that approval happens, you are not forcing your way in anymore, you are operating through trusted doors.

From there, it became a chain reaction. Stolen tokens and abused third-party integrations allowed them to move across SaaS environments quietly, pulling data from CRM systems and other enterprise applications without tripping obvious alarms. It was less about hacking a system and more about exploiting how everything is interconnected once trust is granted.

The impact spread across aviation, insurance, retail, tech, and more, largely through coordinated extortion campaigns built on that same access.

Major Incidents Linked to ShinyHunters
  1. Salesforce Experience Cloud Data Theft Campaign

Between 300–400 organizations impacted, including multiple cybersecurity firms. CRM and customer data exposed through misconfigured public-facing Experience Cloud environments.”

A large-scale data theft campaign targeted Salesforce Experience Cloud environments via the Aura API endpoint (/s/sfsites/aura). The attackers focused on instances where guest-user profiles were misconfigured, allowing unauthenticated users to access CRM objects that were intended to remain private.

The campaign involved systematic scanning of exposed Experience Cloud sites, identification of over-permissive guest access, and automated extraction of CRM data. Attackers also modified existing auditing tools and developed custom scripts to scale reconnaissance and data collection across exposed Salesforce instances.

  1. Instructure Canvas Breach (Student Data Exposure)

“According to attacker claims, Up to 275 million individuals impacted across ~9,000 schools were impacted. Exposure includes student identifiers and private communications from Canvas environments.”

Instructure confirmed unauthorized access to systems supporting its Canvas learning management platform, resulting in data exfiltration affecting multiple educational institutions. The compromised data includes names, email addresses, student ID numbers, and internal messages exchanged between students, teachers, and staff.

The company stated there is no evidence of exposure of passwords, financial data, or government-issued identifiers. While investigations remain ongoing, ShinyHunters separately claimed significantly larger impact figures, including data from thousands of schools and hundreds of millions of users, though these claims have not been independently verified.

  1. Carnival Supply Chain Data Breach

The incident affected nearly 6 million individuals after a social engineering intrusion compromised third-party access and SaaS systems, exposing passenger identity and travel data.

Carnival Corporation confirmed a breach originating from a third-party supply chain compromise enabled through social engineering. Attackers used phishing and voice-based impersonation techniques to compromise an employee account, gaining access to internal systems connected to Carnival’s environment.

The access was leveraged to move laterally into SaaS platforms and extract large volumes of customer data. Exposed information includes names, contact details, dates of birth, loyalty program data, and in some cases passport and driving licence information, with the majority of impact tied to Carnival’s Holland America Line customers.

  1. ADT Cloud Data Breach (Vishing-Based SSO Compromise)

“By impersonating trusted personnel over the phone, attackers obtained the access needed to defeat SSO protections. The identity-focused intrusion ultimately exposed customer and prospect records, affecting approximately 5.5 million individuals.

ADT Inc. experienced a cloud data breach following compromise of an employee account via voice phishing (vishing), which allowed attackers to obtain SSO credentials. These credentials were then used to access connected cloud environments and exfiltrate sensitive customer and prospect data.

The exposed data includes names, email addresses, phone numbers, physical addresses, partial dates of birth, and limited government-issued identification data in some cases. The incident reflects a broader identity-centric attack model involving social engineering, abuse of authentication systems, and lateral movement across SaaS infrastructure.

What These Campaigns Have in Common
  • Trust is the real attack surface.
    Across these incidents, attackers were not relying on exotic exploits. They were leaning into what already works in most environments, trusted relationships, human behavior, and legitimate access paths. Once trust is in place, security controls tend to assume legitimacy.
  • Identity sits at the center of compromise.
    Whether it is voice phishing, credential theft, SSO abuse, or over-permissioned accounts, the common thread is identity misuse. Attackers are not breaking in as outsiders. They are showing up as valid users.
  • Exposure often comes from how systems are connected.
    It is rarely one weak system. It is the way SaaS platforms, OAuth apps, and integrations inherit trust from each other. A small misconfiguration or overly broad permission can quietly open doors that were never meant to be open.
  • Access is the multiplier.
    Once attackers get a foothold through a trusted identity or integration, everything accelerates. SaaS environments are highly connected by design, so lateral movement and data access tend to follow quickly.
  • The attack surface has shifted to trust and identity.
    The pattern is clear. Modern campaigns are less about “breaking infrastructure” and more about abusing identity, permissions, and the trust relationships between systems that were built to enable speed, not restrict misuse.
Three Strategic Shifts That Will Define Future Protection Against Identity-Led Threat Campaigns
  1. Security Convergence Is Now a Baseline Requirement

““A single MFA change, an OAuth approval, or a data export may look routine in isolation. But attackers rely on that. When correlated, these small signals often reveal a full attack unfolding step by step.”

Modern attacks do not respect organizational boundaries. Threat actors move across identities, applications, cloud environments, SaaS platforms, and third-party integrations, exploiting the gaps between security domains rather than targeting isolated systems. The challenge is that most security functions still operate in silos. Identity teams manage access, cloud teams manage infrastructure, application teams secure platforms, and security operations monitor alerts. Each function may be effective independently, but attackers succeed by connecting weak signals across them. Individually, events such as MFA changes, OAuth grants, API activity, or data exports may look normal. When correlated, they often reveal a complete attack path. This makes convergence essential, not as a tooling exercise, but as a way to understand how risk moves across identity, data, and systems in a connected environment.

  1. Human and Non-Human Identities Must Be Governed as One Ecosystem

“In many organizations, the balance of identity has shifted toward systems and automation, where service accounts, APIs, OAuth grants, machine credentials, application tokens, AI agents, and external integrations far outnumber human users.”

Recent intrusions often begin with human identities, but they increasingly extend through non-human identities. Service accounts, APIs, OAuth tokens, automation workflows, machine credentials, and third-party integrations now operate at a scale that often exceeds human users.

These identities frequently carry broad privileges but limited oversight. In many cases, they are not continuously governed or fully understood in terms of what they can access and how they interact with other systems.

From an attacker’s perspective, the distinction between human and non-human identities is irrelevant. Any identity that provides a path to valuable data becomes a target. Security programs therefore need unified visibility across all identity types, including their permissions, dependencies, and potential impact if compromised.

Without this, organizations end up securing individual identities while missing the interconnected pathways between them.

  1. Security Must Be Measured by Business Impact, Not Control Coverage

“Most threat actors prioritize access to customer data, intellectual property, financial systems, and key business platforms, typically with the aim of disruption, extortion, fraud, or reputational damage.”

Security programs still tend to measure success through control implementation, compliance alignment, and vulnerability counts. While these metrics are useful, they do not reflect how attackers operate.

Attackers focus on outcomes, not controls. Their goal is access to sensitive data, financial systems, intellectual property, or business-critical operations.

This makes context essential. A low-severity misconfiguration can become critical if it exposes a high-value SaaS system. A compromised service account may represent greater risk than multiple technical vulnerabilities if it enables direct access to sensitive data.

As a result, security programs are shifting toward impact-based prioritization. The focus is moving from tracking individual security findings to understanding attack paths, business dependencies, and the real-world consequences of compromise.

Conclusion

For security leaders, the significance of these attacks extends beyond the individual breaches themselves. They demonstrate how quickly risk can spread when identities, applications, integrations, and data are deeply interconnected, but security visibility remains fragmented. While the tactics varied, the outcome was often the same: a trusted identity, integration, or business process became the pathway to large-scale data exposure.

Key takeaways for security leaders:
  • Trust must be continuously validated, not assumed. Identities, SaaS integrations, third-party connections, and privileged access relationships have become prime targets for attackers because they often provide direct access to business-critical data and systems.
  • Security convergence is no longer optional. Identity security, cloud security, application security, governance, and security operations must work from a shared understanding of risk. Without that context, organizations struggle to see how seemingly isolated events connect into a broader attack path.
  • Resilience depends on limiting blast radius. Human error, compromised credentials, and misconfigurations will continue to occur. The goal is to ensure that a single trusted account, integration, or permission does not become a gateway to enterprise-wide exposure.

Table of Contents

Discover The Latest Blog Articles

Book A Demo

Fill out the form below!

How can we help?

How can we help?