Skip to content
Key Points - Trusted Tools as Attack Vectors: Threat actors abused a trojanized version of the Salesforce Data Loader app, turning a legitimate tool into a channel for mass data theft. - Social Engineering Entry Point: The breach began with vishing, where an employee was tricked into approving a malicious connected app, granting OAuth API access. - Stealthy API Exfiltration: Attackers executed bur...
Salesforce Data Loader Exfiltration Attack Explained | Huntaegis