Join RH-ISAC for a threat briefing about the latest intel on observed incidents and emerging threats relevant to the retail and hospitality community, as well as mitigation or response techniques. 

Sessions for this month’s briefing:

Defending Against Credential Stuffing and Account Takeover Fraud

Sophisticated credential stuffing attacks are increasingly leveraging residential proxy networks that closely mimic legitimate consumer traffic, making detection and mitigation more challenging than ever. In this session, Accertify will examine the attacker tactics, techniques, and procedures (TTPs) used to facilitate account takeover (ATO) fraud, along with the monetization pathways that enable these campaigns to generate significant criminal gains. Drawing on retail and hospitality-wide intelligence, Accertify will highlight the growing scale and impact of these attacks and explore how organizations can strengthen defenses by integrating fraud intelligence with cybersecurity visibility. Attendees will gain practical insights into how cross-functional collaboration between fraud and security teams can create measurable business value while improving protection against evolving threats.

Trusted Integrations, Untrusted Outcomes: Breaking Down the Klue-Enabled Salesforce Data Theft

Third-party SaaS integrations often hold broad, persistent access to critical business data, yet they frequently receive less scrutiny than employee accounts. This session examines the recent Klue-enabled Salesforce data theft campaign and places it within a broader trend of OAuth abuse observed across multiple Salesforce-related incidents involving integrations such as Salesloft Drift and Gainsight. ReliaQuest analysts will break down how attackers exploit trusted integrations to gain unauthorized access without deploying malware or triggering traditional security controls. Attendees will learn how compromised OAuth tokens can be used to execute large-scale, automated data exfiltration through legitimate APIs, why revoking refresh tokens is critical for containment, and how integration permissions directly impact the scope of compromise.
The session will also explore the challenges of attribution in these campaigns, including potential overlaps with activity associated with ShinyHunters and UNC6395. By understanding the techniques and tradecraft behind these attacks, defenders will be better equipped to identify, contain, and mitigate risks posed by third-party SaaS integrations and non-human identities.