Identity and Access Management · Third-Party Risk Management · Data Security and Protection · Incident Detection and Response
The Salesforce Fabric Is 2026's Single Attack Surface
Medtronic and McGraw-Hill confirm breaches inside the same ShinyHunters Salesforce campaign. The fabric stitching SaaS to OAuth is the real attack surface.
By Tal Eliyahu · · 9 min read
Medtronic confirmed a cybersecurity incident on April 27, 2026. McGraw-Hill confirmed one eleven days earlier, on April 16. The two announcements look like separate breaches at unrelated companies. They are part of the same campaign — and the campaign exposes a structural failure mode the cybersecurity industry has been pretending was a configuration error rather than a category-defining problem.
The campaign is ShinyHunters' coordinated targeting of Salesforce environments, running through 2025 and accelerating in 2026. The technique is consistent: vishing-driven Data Loader installs, OAuth token abuse, lateral access into Salesforce-hosted data, exfiltration. The victim list reads like a Fortune 500 directory — Workday, TransUnion, Allianz Life, Google, Cisco, LVMH brands, Adidas, Qantas, McGraw-Hill, and now Medtronic.
The fabric stitching SaaS to identity is the real attack surface. The cybersecurity industry has been treating it as plumbing.
What happened
Medtronic disclosed on April 27 that an unauthorized third party had access to certain corporate IT systems. The company stated no impact to products, patient safety, manufacturing, or hospital networks. ShinyHunters claimed 9 million records and terabytes of data; Medtronic has not confirmed those numbers, and the threat actor reportedly delisted Medtronic from its leak site shortly after — which raises a separate set of questions the trade press has not yet resolved.
McGraw-Hill disclosed on April 16 that 13.5 million accounts had been compromised through a misconfigured Salesforce-hosted webpage. The data exposed included names, addresses, phone numbers, and email addresses. The number is verified through Have I Been Pwned. The framing the company gave to regulators and press is the more important part: *this activity appears to be part of a broader issue involving a misconfiguration within Salesforce's environment that has impacted multiple organizations*.
That sentence is the giveaway. McGraw-Hill is not blaming Salesforce. It is naming the pattern.
The campaign and the pattern
ShinyHunters has been running variants of the same playbook against Salesforce customers for at least eighteen months. The technique chain is documented across multiple Fortune 500 victims through 2025 and 2026.
The chain typically runs: vishing call to a help-desk or admin user; social-engineered installation of a Salesforce Data Loader application or comparable connected app; OAuth token issued by the Salesforce instance to the malicious app; bulk export of CRM data via the Data Loader's legitimate API access; exfiltration to attacker infrastructure; extortion or leak-site posting.
What makes the chain hard to defend against is that none of the individual steps are exotic. Vishing has been a standard intrusion vector for years. Salesforce Data Loader is a legitimate tool. OAuth tokens are how every modern SaaS application grants third-party access. The misconfigurations the campaign exploits are the default behaviors of the SaaS-to-identity fabric most enterprises have been quietly accumulating since they adopted CRM.
This is not a Salesforce vulnerability. It is a Salesforce-customer governance problem at scale. And because Salesforce is the CRM of record for a meaningful share of the Fortune 500, the customer-side governance problem is functionally a single attack surface.
The opposite failure mode from Itron
This site analyzed the Itron breach two weeks ago — a critical-infrastructure vendor compromise that exposed the OT category's blind spot. The Salesforce wave is the inverse failure mode.
Itron's lesson was that the cybersecurity industry could not see what it did not own. OT vendor risk fell outside the asset map of most CISOs because the OT vendor sat upstream of the utility, not inside it. The category was sold downstream and the breach happened upstream.
The Salesforce wave's lesson is the inverse. Cybersecurity owns the SaaS perimeter on paper. Every CISO with a CRM in their environment can name the SaaS, the identity provider, the connected applications inventory, the DLP suite, and the CASB. They have governance documents. They have compliance attestations. They have controls.
What they do not have is operational control of the OAuth fabric stitching all of that together. The connected app inventory is rarely audited per scope. The Data Loader installs are rarely tracked per user. The OAuth token issuance is rarely instrumented for behavioral anomaly. The vishing-resistant authentication required to break the front door of the chain is rarely deployed at the help-desk and admin-user level.
The cybersecurity team owns the SaaS. The team does not control the fabric.
The category-defining moment
For three categories of cybersecurity vendors, the Salesforce wave is the demand catalyst they have been waiting for.
The first is SaaS Security Posture Management (SSPM). Obsidian Security, AppOmni, CrowdStrike's Adaptive Shield, Valence, Reco, DoControl, and a handful of other entrants have been pitching SaaS posture as a 2024-2025 category. The Salesforce wave is the moment the category goes from CISO budget *should-have* to *must-have*. SSPM products inventory connected applications, audit OAuth scopes, surface Data Loader installs, and detect the misconfigurations the campaign exploits. Every Medtronic-shaped customer board conversation is now an SSPM evaluation conversation.
The second is Identity Threat Detection and Response (ITDR). Push Security, Permiso, Mitiga, CrowdStrike Falcon Identity, and the broader ITDR cohort detect anomalous identity behavior across SaaS — the kind of OAuth token misuse and lateral access patterns the ShinyHunters chain produces. ITDR is structurally adjacent to the agentic-security identity layer we have been mapping.
The third is OAuth and non-human identity governance. Astrix (now Cisco), Oasis Security, Entro, and similar specialists govern the credentials, tokens, and connected applications that are the actual attack surface. The Salesforce wave is the most visible argument these companies have ever had for why their category exists.
The vendors with credible product in any of these three categories will see meaningfully shorter sales cycles for the rest of 2026.
What changes for cybersecurity buyers
For procurement teams and CISOs, the Salesforce wave makes three previously theoretical conversations urgent.
The first is the connected-applications audit. Most enterprises have hundreds of OAuth-connected applications across their major SaaS instances. Most have never been audited per scope. The audit is a project plan, not a procurement decision — but it requires SSPM tooling to run at scale. Buyers without an SSPM contract should expect that conversation in the next quarter.
The second is the help-desk and admin-user authentication question. Vishing-driven Data Loader installs work because the help desk and admin tier of the identity stack often has weaker authentication than the user population. Phishing-resistant MFA, vishing-aware verification flows, and admin-tier behavioral monitoring are the controls that break the chain. CISOs who have left these controls partially deployed should expect to be questioned by their boards specifically about Medtronic.
The third is the SaaS shared-responsibility conversation. Salesforce, like every major SaaS provider, ships a shared-responsibility model that puts customer-side configuration squarely in the customer's lane. The Salesforce wave is forcing the model into procurement language. Expect 2027 SaaS contracts to include explicit customer-side requirements around connected-app governance, OAuth-scope review cadence, and data-loader controls. Cyber-insurance underwriters will follow.
What changes for cybersecurity vendors and acquirers
For public security platforms and acquirers, the Salesforce wave is the M&A catalyst for the SSPM and ITDR categories.
The major XDR and SSE platforms — Palo Alto Networks, CrowdStrike, SentinelOne, Cisco, Zscaler — all need a credible answer to the SaaS-fabric question. CrowdStrike already has Adaptive Shield from a 2024 acquisition. The others have varying combinations of partial coverage. Expect at least one platform-vendor SSPM acquisition before Q4 2026.
The identity vendors — Okta, Microsoft, CyberArk (now PANW) — face a sharper version of the same question. The OAuth scope governance gap the campaign exploits sits inside their territory. Whether they extend their identity products into SaaS-fabric governance natively or acquire SSPM and ITDR specialists is the open question. Both paths are credible. Both will be priced.
Salesforce itself faces a separate strategic question. The shared-responsibility narrative held for Snowflake in 2024. It may hold for Salesforce in 2026. But the difference between the two events is volume — the Salesforce wave has compromised data at meaningfully more enterprises than Snowflake did. Expect Salesforce to ship more native posture tooling in the next two quarters than it has shipped in the prior two years.
The CASB incumbents — Netskope, Zscaler's part of the SSE stack, Palo Alto's Prisma — face the unspoken question of whether their SaaS coverage actually catches this attack chain. The honest answer for most CASB deployments is *no, not yet*. The dishonest answer is what the next round of marketing claims will say.
What to watch next
Three signals over the next two quarters will tell us how the Salesforce wave reshapes procurement and M&A.
The first is the next material SSPM or ITDR acquisition. CrowdStrike has Adaptive Shield. PANW has CyberArk. The next platform-vendor purchase in this layer sets pricing and signals which incumbents are filling the gap by acquisition versus by building.
The second is regulatory response. The SEC's cybersecurity disclosure rule has been played out at Itron; a Medtronic 8-K with material framing or a follow-on regulatory action would set the precedent for SaaS-supply-chain breaches specifically. The healthcare angle adds HIPAA exposure that Itron's industrial scope did not carry. State AGs and class-action firms are paying attention.
The third is whether ShinyHunters or a successor campaign expands to other major SaaS surfaces. Workday, ServiceNow, GitHub, and the major HR and finance SaaS instances are all OAuth-fabric environments with similar governance gaps. The campaign's economic incentive is clear. The defenders' clock is shorter than it looks.
The cybersecurity industry has spent two years debating whether AI agents are the new attack surface. The Salesforce wave is the reminder that the SaaS fabric is already the largest attack surface most enterprises have. The agents are coming. The fabric is here.
Itron showed cybersecurity could not see what it did not own. The Salesforce wave shows cybersecurity does not control what it does own. Both lessons compound.
Frequently asked questions
- What is the ShinyHunters Salesforce campaign?
- ShinyHunters is a financially motivated threat actor running a coordinated campaign against Salesforce environments. The technique chain is consistent across victims: vishing calls to help-desk or admin users, social-engineered installation of malicious connected applications (often disguised as Salesforce Data Loader), OAuth token issuance from the Salesforce instance to the attacker app, bulk export of CRM data using the Data Loader's legitimate API access, exfiltration, and extortion or leak-site posting. The victim list through 2025 and 2026 includes Workday, TransUnion, Allianz Life, Google, Cisco, LVMH brands, Adidas, Qantas, McGraw-Hill, and Medtronic.
- Why is the Salesforce wave structurally different from a typical SaaS breach?
- The wave exposes a category-level governance failure rather than a single-vendor vulnerability. Salesforce itself is not breached; its customers' OAuth scope governance, connected-applications audits, and admin-tier authentication are. Because Salesforce is the CRM of record for a meaningful share of the Fortune 500, the customer-side governance problem is functionally a single attack surface across hundreds of major enterprises. That is a different threat model than a single SaaS vendor having a vulnerability — and it is what makes the campaign category-defining rather than incident-specific.
- Which cybersecurity vendor categories see the strongest demand catalyst from the Salesforce wave?
- Three categories. SaaS Security Posture Management (SSPM) — Obsidian Security, AppOmni, CrowdStrike's Adaptive Shield, Valence, Reco, DoControl — inventories connected applications and surfaces misconfigurations. Identity Threat Detection and Response (ITDR) — Push Security, Permiso, Mitiga, CrowdStrike Falcon Identity — detects the OAuth abuse patterns the campaign produces. OAuth and non-human identity governance — Astrix (now Cisco), Oasis Security, Entro — governs the credentials and connected applications that are the actual attack surface. Vendors with credible products in any of these three categories will see meaningfully shorter sales cycles through the rest of 2026.
- How does the Salesforce wave compare to the 2024 Snowflake breaches?
- Both are SaaS supply-chain multipliers — single attack surfaces propagating to dozens of customer environments. Snowflake's 2024 wave hit roughly 165 customer environments through stolen credentials lacking MFA. The Salesforce campaign uses a different chain (vishing-to-Data-Loader-to-OAuth-token instead of pure credential theft) and has hit more major enterprises by name. The structural lesson is identical: the SaaS-to-identity fabric is the actual attack surface, and customer-side governance is what determines exposure. The defenders' takeaway should also be identical, but the volume and visibility of the Salesforce wave is forcing the conversation in a way Snowflake's mostly did not.
Related on CyberBiz
- Cybersecurity market map — Where SSPM, ITDR, and OAuth/NHI governance vendors sit in the broader cybersecurity vendor landscape.
- Public cybersecurity companies — The platforms (PANW, CrowdStrike, Cisco, Zscaler, Okta) facing M&A pressure in the SSPM and ITDR categories.
- CrowdStrike stock profile — Adaptive Shield (acquired 2024) gives CrowdStrike a head start in SSPM. The competitive distance is real.
- Okta stock profile — The OAuth scope governance gap the Salesforce wave exploits sits inside Okta's territory. Open question: extend natively or acquire.
- Itron breach analysis — Companion piece — the inverse failure mode (cybersecurity can't see what it doesn't own; Salesforce wave shows cybersecurity doesn't control what it does own).
- Cisco's Astrix acquisition analysis — Non-human identity primitive — directly relevant to the OAuth governance gap the campaign exploits.
- Agentic security category map — Where ITDR sits in the agentic-stack identity layer, and why the SaaS fabric and the agent fabric are the same architectural problem.
- Newsroom — Live cybersecurity market feed: breaches, M&A, funding rounds.
Sources
- Data breach at edtech giant McGraw Hill affects 13.5 million accounts — BleepingComputer
- Educational company McGraw Hill says Salesforce misconfiguration led to data leak — The Record (Recorded Future News)
- Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak — SecurityWeek
- Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records — Security Affairs
- ShinyHunters strike again: Workday breach tied to Salesforce-targeted social engineering wave — CSO Online