Key Points
- Trusted Tools as Attack Vectors: Threat actors abused a trojanized version of the Salesforce Data Loader app, turning a legitimate tool into a channel for mass data theft.
- Social Engineering Entry Point: The breach began with vishing, where an employee was tricked into approving a malicious connected app, granting OAuth API access.
- Stealthy API Exfiltration: Attackers executed bur...
