Safeguarding Against ShinyHunters

Customer Town Hall | Wednesday, September 23 at 9:00 a.m. PDT

ShinyHunters has spent the past year turningOAuth approvals into a way in. Someone gets a call, approves what looks like aroutine app connection, and the stolen token gives the attacker persistentaccess to Salesforce and every connected app downstream. It's how they got intoenvironments through Drift and Gainsight, and it's still active. McKesson,Kimberly-Clark, and Neogen are this month's confirmed targets.

In this live webinar, our executive team andthreat research leaders will walk you through the mechanics of this campaignand what to check in your own environment before it reaches you.

How the OAuth path works:
The exact sequence from vishing call to approved app to persistent Salesforce token, and why it bypasses MFA

What to check in your environment this week: - The specific OAuth grants, connected apps, and service accounts most likely to be affected

Live Q&A with our threat research team: Direct access to thepeople tracking this campaign

Personalized threat report (to follow the webinar): - Which of your OAuth grants and service accounts you need to review first, in order, with mitigation steps you can put in place immediately

Speakers:
Ofer Klein, Co-Founder and CEO
Tal Shapira, Co-Founder and CTO
Gal Nakash, Co-Founder and CPO
Zoe Hillenmeyer, COO
Ophir Kelman, Head of Security Research

We’ve seen a recent uptick in ShinyHunter attacks against our customers. In this session, we’ll discuss what’s happening, why the attacks were successful, and what you can do to protect your environment.

Register Now for the Recording: Salesforce Under Attack

Thanks for submitting the form.
Securing AI inside Microsoft 365, Google Workspace, Salesforce, Zoom, Jira and more.

Govern the AI Inside the Apps You Already Use

Reco gives you visibility and control over embedded AI features in your existing SaaS platforms. From Microsoft Copilot to Salesforce GPT, and new tools like Cursor, Lovable, Agentforce, and n8n, we show you where AI is enabled, what data it can access, and who's using it.

Your SaaS Just Got Smarter. We Make Sure It's Safe

Detect SaaS AI Apps

Know which copilots, assistants, and AI add-ons are active across tools like Slack, M365, Google Workspace, Notion, Cursor, Lovable, n8n, Agentforce, and more.

Policy-Based Access & Risk Scoring

Auto-classify AI tools based on vendor risk, permissions, and usage context. Stop high-risk AI before it sees anything sensitive.

Map Data Exposure to AI Models

We show you which documents, conversations, and records are flowing through embedded AI engines.

Continuous Governance

AI in SaaS is always changing. Reco adapts in real time—no manual audits, no falling behind.

How Reco Brings SaaS AI Governance to Life

1. Discover

We scan across your SaaS environment to uncover embedded AI tools and features instantly.

2. Analyze

Understand what these AI systems can access—and what they're doing with your data.

3. Control

Enforce governance with automated controls.

4. Audit

Get audit trails and usage history. Prove governance. Show control.