Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of the ongoing international investigation into ShinyHunters — one of the most prolific data-theft and extortion crews operating today. While the arrest is a law-enforcement win, defenders should not mistake it for the end of the threat. ShinyHunters operates as a loosely affiliated brand and collective; arrests of individual members historically have not stopped the underlying campaigns, and the group's tradecraft is now well-documented and widely imitated.
The campaigns attributed to ShinyHunters and overlapping clusters (tracked by various vendors as UNC6040/UNC6240-style SaaS extortion activity, with overlaps into Scattered Spider ecosystems) have hit organizations running Salesforce, Snowflake, and other SaaS platforms — stealing customer records at massive scale and extorting victims under the ShinyHunters brand on BreachForums-style leak sites.
The critical defensive takeaway: this crew does not primarily exploit software vulnerabilities. They exploit trust, OAuth consent flows, help-desk processes, and unmonitored SaaS API access. Your patching cadence will not save you here — your identity governance, SaaS telemetry, and consent-policy hardening will.
Why Defenders Must Act Now
Every organization using Salesforce, Snowflake, Google Workspace, or Microsoft 365 should treat this news as a forcing function to audit three things today:
- Third-party OAuth applications and connected apps authorized in your SaaS tenants
- User consent settings — whether end users can self-authorize applications that read data
- Bulk API / data export activity — the loudest and most detectable phase of this attack chain
The group's operations follow a repeatable, detectable pattern. The arrest doesn't change the TTPs — it confirms they worked at scale.
Technical Analysis: The ShinyHunters SaaS Extortion Playbook
Threat Actor Profile
- Group: ShinyHunters (data-theft and extortion collective; overlapping membership and infrastructure with other English-speaking extortion crews)
- Status: Active despite arrests; historically resilient to member attrition
- Primary monetization: Data theft → extortion → leak-site sale
- Targets: Enterprises with large SaaS footprints — Salesforce CRM tenants, Snowflake data warehouses, cloud collaboration suites
Attack Chain (Defender's View)
Phase 1 — Vishing / Social Engineering (T1566.004 / T1656). Operators call help desks or end users, impersonating IT support. In the widely reported Salesforce campaign, victims were walked into authorizing a malicious OAuth "connected app" — often named to resemble Salesforce's legitimate Data Loader — via the OAuth device authorization or authorization-code flow. No malware. No exploit. Just a convincing phone call and a consent prompt.
Phase 2 — OAuth Token Abuse (T1550.001 / T1528). Once consent is granted, the attacker holds a refresh token with API scopes (often api, refresh_token, full). This token grants persistent, MFA-bypassing access: API calls authenticated with an OAuth token do not re-trigger MFA in most SaaS configurations. Conditional Access policies scoped only to interactive browser sign-ins frequently miss this entirely.
Phase 3 — Bulk Data Exfiltration (T1530 / T1119). The attacker uses the Salesforce Bulk API (the same API the legitimate Data Loader uses), SOQL queries, or mass export jobs to pull entire object tables — Accounts, Contacts, Leads, Opportunities — into CSV extracts. In Snowflake-focused intrusions, the equivalent is querying with stolen credentials lacking MFA and exporting result sets. Volumes are large: hundreds of thousands to millions of rows.
Phase 4 — Extortion (T1657). Victims receive extortion demands with data samples. Non-payers are listed on leak sites under the ShinyHunters brand.
Affected Platforms
| Platform | Abuse Vector | Key Telemetry |
|---|---|---|
| Salesforce | Malicious connected apps, Bulk API abuse | Event Monitoring / Event Log Files (API, BulkAPI, LoginEvent), Connected App OAuth usage |
| Microsoft Entra ID / M365 | Illicit consent grants, app impersonation | AuditLogs (Consent to application, Add service principal), SignInLogs |
| Google Workspace | OAuth grants to external apps | Admin audit log (authorize events), token audit |
| Snowflake | Stolen creds without MFA, bulk exports | LOGIN_HISTORY, QUERY_HISTORY, ACCESS_HISTORY |
Exploitation Status
Confirmed active, in-the-wild exploitation at scale throughout 2025 and continuing into 2026. Multiple named breach victims have been extorted under the ShinyHunters brand. This is not theoretical — the arrest itself stems from operational impact.
Detection & Response
The highest-fidelity detection points are (a) consent-grant events and (b) bulk export behavior. Endpoint rules are secondary, but useful if users were induced to run actual tooling locally.
Sigma Rules
The following rules target Entra ID consent abuse, OAuth-app impersonation of legitimate data tools, and local execution of bulk-export tooling. Tune the impersonation string list to your environment — the key signal is an app named like a legitimate tool that isn't the legitimate publisher's app.
---
title: OAuth Consent Grant to Application Impersonating Data Loader or Export Tool
id: 3b8f2a71-5c4e-4d9a-b6f1-9a2c7e5d1034
status: experimental
description: Detects OAuth consent grants where the application display name impersonates legitimate data export tooling (e.g., Salesforce Data Loader), consistent with ShinyHunters-style vishing-driven connected app abuse.
references:
- https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/
- https://attack.mitre.org/techniques/T1550/001/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.credential_access
- attack.t1550.001
- attack.t1656
logsource:
product: azure
service: auditlogs
detection:
selection_operation:
operationName|contains: 'Consent to application'
selection_impersonation:
TargetResources|contains:
- 'Data Loader'
- 'DataLoader'
- 'Dataloader'
- 'Data Export'
- 'Bulk Export'
- 'CRM Sync'
- 'Salesforce Sync'
filter_known_good:
InitiatedBy|contains: 'admin@yourdomain.com'
condition: selection_operation and selection_impersonation and not filter_known_good
falsepositives:
- Legitimate admin consent to sanctioned integration tools
level: high
---
title: Suspicious First-Time OAuth Consent by End User to External Application
id: 7c1d9e42-2a6f-4b83-9d5e-4f8a1b6c0927
status: experimental
description: Detects end users (non-admin) granting OAuth consent to applications, a common result of vishing-driven consent phishing used by SaaS extortion crews.
references:
- https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/
- https://attack.mitre.org/techniques/T1566/004/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.initial_access
- attack.t1566.004
- attack.persistence
logsource:
product: azure
service: auditlogs
detection:
selection:
operationName|contains:
- 'Consent to application'
- 'Add service principal'
- 'Add OAuth2PermissionGrant'
filter_admin_roles:
InitiatedBy|contains:
- 'Global Administrator'
- 'Cloud Application Administrator'
condition: selection and not filter_admin_roles
falsepositives:
- Environments where user consent is intentionally enabled (remediate — see below)
level: medium
---
title: Bulk Data Export Tooling Execution on Endpoint
id: 9e4a5c18-7b3d-4f62-a1c8-2d7e9b3f4065
status: experimental
description: Detects execution of data loader / bulk export tooling and scripted SOQL exports from endpoints, potentially indicating attacker-driven SaaS data theft staging.
references:
- https://attack.mitre.org/techniques/T1530/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.collection
- attack.t1530
- attack.exfiltration
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\dataloader.exe'
- '\data_loader.exe'
selection_cli:
CommandLine|contains:
- 'com.salesforce.dataloader'
- 'bulkapi'
- 'SOQL'
- 'salesforce_bulk'
condition: 1 of selection_*
falsepositives:
- Legitimate Salesforce administrators running sanctioned Data Loader jobs
level: medium
KQL Hunt — Microsoft Sentinel
This query hunts for consent grants and new service principals that could represent attacker-authorized applications, correlating the consent event with the initiating user and IP. Run it over at least 30 days and pivot on any application not in your sanctioned-app inventory.
let lookback = 30d;
AuditLogs
| where TimeGenerated > ago(lookback)
| where OperationName in ("Consent to application", "Add service principal", "Add OAuth2PermissionGrant")
| mv-expand TargetResources
| mv-expand TargetResources.modifiedProperties
| extend AppDisplayName = tostring(TargetResources.displayName),
InitiatedBy = tostring(parse_json(InitiatedBy).user.userPrincipalName),
InitiatingIP = tostring(parse_json(InitiatedBy).user.ipAddress)
| extend PropName = tostring(TargetResources_modifiedProperties.displayName),
PropValue = tostring(TargetResources_modifiedProperties.newValue)
| where PropName has "Permission" or PropValue has_any ("Mail.Read", "Sites.Read.All", "Files.Read.All", "full_access", "api", "refresh_token")
| project TimeGenerated, OperationName, AppDisplayName, InitiatedBy, InitiatingIP, PropValue, Result
| order by TimeGenerated desc
Complementary hunt for Salesforce bulk API activity ingested via Salesforce Event Log Files or a CSP connector into a custom table (adapt table name to your connector):
let lookback = 14d;
SalesforceEvent_CL
| where TimeGenerated > ago(lookback)
| where EVENT_TYPE_s in ("API", "BulkAPI", "ReportExport")
| summarize RowCount = sum(NUM_ROWS_d), Operations = count(),
Objects = make_set(OBJECT_TYPE_s), IPs = make_set(CLIENT_IP_s)
by USER_ID_s, bin(TimeGenerated, 1h)
| where RowCount > 50000 or Operations > 200
| order by RowCount desc
Velociraptor VQL — Endpoint Hunt
If users were vished into running local tooling or downloading staging utilities, hunt endpoints for bulk-export clients and recently written large CSV extracts in user directories:
-- Hunt for data export tooling execution and large CSV staging artifacts
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(dataloader|bulkapi|SOQL|salesforce|snowsql)'
OR Exe =~ '(?i)(dataloader|snowsql|export_tool)'
-- Hunt for large recently-modified CSV/JSON extracts in user profiles (potential staging)
SELECT FullPath, Size, Mtime, Btime
FROM glob(globs='C:/Users/*/{Downloads,Desktop,Documents,AppData/Local/Temp}/*.csv', accessor='ntfs')
WHERE Size > 10485760
AND Mtime > timestamp(epoch=now() - (14 * 86400))
ORDER BY Size DESC
Remediation Script — Audit and Lock Down Entra OAuth Consent
Run with an account holding Global Reader (audit) and Cloud Application Administrator (remediation). Requires the Microsoft.Graph PowerShell SDK.
# Connect with required scopes
Connect-MgGraph -Scopes "Application.Read.All","Directory.Read.All","Policy.ReadWrite.PermissionGrant","AuditLog.Read.All" -NoWelcome
# 1) Audit: list all OAuth2 permission grants (delegated consents) in the tenant
Write-Host "=== Delegated OAuth Grants ===" -ForegroundColor Cyan
$grants = Get-MgOauth2PermissionGrant -All
$grants | ForEach-Object {
$sp = Get-MgServicePrincipal -ServicePrincipalId $_.ClientId
[PSCustomObject]@{
AppName = $sp.DisplayName
AppId = $sp.AppId
ConsentType = $_.ConsentType
Scope = $_.Scope
}
} | Format-Table -AutoSize
# 2) Audit: flag apps with high-risk scopes (mail, files, full read)
Write-Host "=== High-Risk Scope Grants ===" -ForegroundColor Yellow
$grants | Where-Object { $_.Scope -match "Mail.Read|Files.Read|Sites.Read|full_access|offline_access" } |
ForEach-Object { (Get-MgServicePrincipal -ServicePrincipalId $_.ClientId).DisplayName + " :: " + $_.Scope }
# 3) Harden: disable user consent entirely (recommended) — forces admin consent workflow
Write-Host "=== Setting user consent policy to disabled ===" -ForegroundColor Cyan
$policy = Get-MgPolicyAuthorizationPolicy
Update-MgPolicyAuthorizationPolicy -AuthorizationPolicyId $policy.Id `
-DefaultUserRolePermissions @{ PermissionGrantPoliciesAssigned = @() }
# 4) Verify
$check = Get-MgPolicyAuthorizationPolicy
if ($check.DefaultUserRolePermissions.PermissionGrantPoliciesAssigned.Count -eq 0) {
Write-Host "User consent is now DISABLED. Admin consent workflow required." -ForegroundColor Green
} else {
Write-Host "Consent policies still assigned — review manually." -ForegroundColor Red
}
Remediation — Full Hardening Checklist
Identity and consent governance (do today):
- Disable end-user OAuth consent in Entra ID (script above) and Google Workspace (Admin console → Security → API controls → App access control → restrict third-party access). Route all consent through admin review.
- Inventory and purge unauthorized connected apps. In Salesforce: Setup → Manage Connected Apps → revoke any app not in your sanctioned inventory; check OAuth usage per user (Setup → Connected Apps OAuth Usage). Pay special attention to apps named like "Data Loader" that are not Salesforce-published.
- Enforce admin-approved app allowlists rather than blocklists — blocklists lose the cat-and-mouse game against renamed malicious apps.
- Extend Conditional Access / session controls to service principals and token flows, not just interactive sign-ins. Require compliant-device or trusted-IP conditions for API-token use where the platform supports it.
- Mandate MFA (phishing-resistant where possible) on Snowflake and all SaaS administrative interfaces — the Snowflake campaign succeeded almost exclusively against accounts without MFA.
Monitoring and telemetry:
- Enable Salesforce Event Monitoring / Event Log Files (API, BulkAPI, Login, ReportExport event types) and ship them to your SIEM. This is a paid Shield add-on — if you don't have it, this is your business case. Alert on row-volume thresholds and off-hours bulk exports.
- Baseline normal bulk-export behavior per user (your legitimate integration service accounts, ETL jobs) and alert on deviation — new source IPs, new OAuth client IDs, first-time bulk exports by interactive users.
- Alert on help-desk-adjacent vishing precursors: password resets followed within hours by MFA changes, new device enrollments, or OAuth consents from the same user.
Process hardening:
- Out-of-band verification for help-desk identity changes. ShinyHunters-style callers sound credible; require a callback to a number on file or a manager approval before password resets or MFA resets for privileged or finance users.
- Prepare an extortion playbook now: decide in advance how you'll validate claimed data theft (canary records in CRM are excellent tripwires), who engages legal/comms, and what your position is on negotiation. You will not make good decisions at 2 a.m. under deadline pressure.
If you suspect you're already hit:
- Revoke all tokens for the suspect connected app immediately (Salesforce: revoke OAuth tokens; Entra: disable the service principal and revoke refresh tokens).
- Pull login and API event logs before revoking if you can preserve forensic value — but do not delay revocation more than minutes; the data is leaving while you deliberate.
- Determine scope via
QUERY_HISTORY/ACCESS_HISTORY(Snowflake) or Bulk API job logs (Salesforce) to identify exactly which objects and rows were read. - Engage IR counsel and consider law-enforcement notification; the Dutch arrest demonstrates these investigations are active and victim cooperation matters.
The Bottom Line
One 24-year-old in Amsterdam is in custody, but the ShinyHunters playbook — vishing, consent phishing, OAuth token abuse, bulk API exfiltration — is documented, proven, and already being copied. The defensive work above is days, not months, of effort, and it closes the exact doors this crew walks through. Audit your consent grants today. Your CRM is the crown jewels they keep walking out with.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.