Edition Introduction

Three of the largest SaaS security incidents of the past year share the same root cause: not a vulnerability in the core platform under attack, but a compromised OAuth token belonging to a trusted third-party integration. Salesloft-Drift, Gainsight, and Klue each hit hundreds of organizations, none of which were directly breached. All were reached through a connected app they had authorized, often years earlier, and largely forgotten. This edition of the Third-Party Exposure Monitor tracks that pattern across 2025 and 2026, explains why it keeps recurring, and sets out what security teams should do about the vendor integrations already sitting inside their environment.

This is a briefing, not a comprehensive audit of every SaaS incident this period; it focuses specifically on the OAuth-token pattern because of how consistently it recurs across otherwise unrelated platforms, vendors, and victim organizations, and because that consistency is itself the signal worth acting on.

Key Developments This Edition

Date

Incident

Organizations Affected

Mechanism

August 2025

Salesloft-Drift

700+, including Cloudflare, Palo Alto Networks, Zscaler

Stolen OAuth tokens used to exfiltrate Salesforce data and AWS keys, no exploit required [1]

November 2025

Gainsight

200+ Salesforce instances

Same threat actor group (ShinyHunters); same OAuth token abuse pattern [1]

Feb–Apr 2026

Vercel / Context.ai

1 primary victim chain, illustrative of the pattern

Compromised third-party AI tool's OAuth grant to Google Workspace exploited after employee malware infection [3]

June 2026

Klue

≈195–200, including Huntress, Recorded Future, Tanium, Jamf

Attackers used a legacy credential, some traced to a 2022 pilot integration, to harvest OAuth tokens and access downstream Salesforce environments [2][4]

 

Figure 1. Organizations affected by three major SaaS OAuth supply chain breaches, 2025–2026.

Incident Breakdown

Salesloft-Drift, August 2025

The Drift conversational marketing platform's OAuth integration with Salesforce was compromised, giving attackers valid tokens that let them query connected Salesforce instances directly, without needing a username, password, or MFA code for any individual target. Cyber Defense Magazine's tracking of the campaign found it eventually reached more than 700 organizations, including major security vendors Cloudflare, Palo Alto Networks, and Zscaler, with attackers systematically exfiltrating customer data, credentials, and in some cases AWS keys stored in Salesforce fields [1]. The campaign's scale illustrates the core mechanic of this entire incident category: compromising one widely integrated vendor grants simultaneous access to every downstream organization that trusted it.

Gainsight, November 2025

Three months later, a customer success platform called Gainsight became what Cyber Defense Magazine describes as the next domino, with reporting attributing the campaign to the same ShinyHunters threat actor group and the same underlying pattern: OAuth tokens tied to a trusted Salesforce integration, used to reach more than 200 additional Salesforce instances [1]. The repetition of both the technique and, reportedly, the attackers within a single quarter suggested this was not an isolated opportunistic attack but a repeatable playbook being run against the SaaS integration ecosystem specifically.

Vercel / Context.ai, February–April 2026

A narrower but instructive incident followed in early 2026. An employee at Context.ai, an AI analytics vendor, was infected with credential-stealing malware after downloading unrelated game-exploit software, and the resulting compromise extended to a Google Workspace OAuth application Context.ai's tool had been granted by Vercel employees. Trend Micro's analysis traced the full chain and characterized it as inherited access abuse: the attacker never touched Vercel's own infrastructure directly, only the third-party OAuth grant sitting between Vercel and a tool its employees had authorized [3].

Klue, June 2026

The most recent and most thoroughly documented incident in this pattern involved Klue, a competitive intelligence SaaS platform. Rescana's investigation found attackers gained access through a legacy credential associated with an integration that appears to date back to 2022, harvesting OAuth tokens used to access downstream Salesforce environments at close to 200 organizations, including cybersecurity vendors Huntress, Recorded Future, Tanium, and Jamf [2]. Salesforce responded by disabling the Klue Battlecards app integration platform-wide, and reporting from The Hacker News noted that a second, unrelated threat actor subsequently claimed access to the same stolen data and launched a separate extortion attempt, suggesting the original attackers' own infrastructure was itself compromised [4].

What makes this pattern significant is not any single incident's scale but its repeatability. In each case, the attacker did not need a password, a phishing success, or a software vulnerability in the platform ultimately accessed. They needed a valid OAuth token belonging to a third-party app the target organization had already authorized. Rescana's analysis of the Klue incident traced the compromised credential to an integration set up years before the breach, for a limited pilot that was apparently never time-boxed, rotated, or revisited [2]. Cyber Defense Magazine's tracking of this pattern across Salesloft-Drift and Gainsight found the same underlying condition: integrations granted broad permissions once, for convenience, and never audited again [1].

This is not an isolated SaaS ecosystem problem. It is a specific, high-profile instance of the broader third-party risk trend this campaign has documented from multiple angles. Verizon's 2026 Data Breach Investigations Report found third-party involvement now appears in 48% of breaches, up from 30% the year before, and that weak passwords and permission misconfigurations in third-party environments took a median of nearly eight months to resolve once identified [5]. Google Cloud's Cloud Threat Horizons Report H1 2026 found third-party software-based entry accounted for 44.5% of observed initial access activity in cloud environments, overtaking weak credentials as the leading vector [6].

Figure 2. Third-party involvement in breaches, year-over-year (Verizon 2026 DBIR).

Signal Snapshot

Metric

Finding

Source

Third-party involvement in breaches

48% in 2026, up from 30% the prior year

Verizon 2026 DBIR [5]

Third-party remediation time

Median of nearly 8 months for known gaps once identified

Verizon 2026 DBIR [5]

Third-party initial access share (cloud)

44.5%, overtaking weak credentials as leading vector

Google Cloud Threat Horizons H1 2026 [6]

Excessive SaaS permissions

Majority of SaaS users hold more privileges than their role requires

Josys, Top SaaS Cybersecurity Risks 2026 [7]

 

Enterprise Implications

For enterprises, the practical exposure is not limited to the specific vendors named above. The pattern generalizes to any third-party application currently connected to a core system, CRM, identity provider, or cloud environment, via OAuth or an API key, particularly integrations set up for a trial, a pilot, or a specific short-term project that were never formally offboarded. Security teams that can answer, with confidence, which third-party applications currently hold API access to their core systems, and when each was last reviewed, are in a materially different position than those who cannot.

There is also a detection asymmetry worth noting across all four incidents. In each case, the affected organizations learned of the compromise through vendor notification or public reporting, not through internal detection of anomalous OAuth token usage. This is consistent with the broader pattern this campaign has documented: activity that originates from infrastructure already trusted by the organization, in this case a previously authorized integration, frequently does not trigger the alerting built around anomalous human login behavior. Third-party integration monitoring therefore needs to be treated as its own detection category, not assumed to be covered by existing identity and access monitoring built primarily around human users.

CyberTech Intelligence Perspective

CyberTech Intelligence views the Salesloft-Drift, Gainsight, and Klue incidents as the same finding from three separate angles rather than three unrelated events. Each confirms that OAuth-based third-party integrations have become a preferred initial access path precisely because they bypass the controls, MFA, password policies, endpoint detection, that organizations have already invested heavily in for direct user access. An integration audit is not a compliance formality in this context; it is closing the specific gap these incidents demonstrate attackers are actively exploiting.

The Klue incident's four-year-old credential is, in CyberTech Intelligence's assessment, the single most instructive detail across this edition. It confirms that the exposure window for a forgotten integration is not measured in weeks or months but can persist for years without detection, and that the eventual trigger for discovery is rarely internal review. Organizations should treat the presence of any long-lived, unreviewed third-party credential as an active liability rather than a dormant one, given how consistently this exact pattern has now been exploited across separate incidents and separate SaaS platforms.

Recommended Actions

The actions below are ordered by how directly they address the specific mechanism seen across all four incidents this edition tracked: a long-lived, unreviewed, over-permissioned third-party credential.

  • Inventory every third-party application with OAuth or API access to core systems, including integrations set up for pilots or trials that were never formally offboarded.
  • Review and time-box integration permissions, scoping OAuth grants to the minimum necessary access rather than accepting default broad scopes.
  • Establish a recurring review cadence for third-party token age and usage, rather than reviewing access only at initial vendor onboarding.
  • Monitor vendor security bulletins actively; both Salesloft-Drift and Klue affected organizations were notified by the vendor, not detected internally, in most reported cases.

Strengthen Third-Party API Exposure Visibility with CyberTech Intelligence

CyberTech Intelligence helps security teams inventory and govern third-party SaaS integrations, closing the OAuth token exposure gap the incidents in this edition demonstrate is being actively exploited.

To assess your organization's third-party integration exposure, connect with CyberTech Intelligence for a Third-Party API Exposure Review.

Connect With Us

References

  1. Cyber Defense Magazine. Why 2026 Will Be The Year Of SaaS Breaches. Cyber Defense Magazine, 2026. https://www.cyberdefensemagazine.com/why-2026-will-be-the-year-of-saas-breaches/ 
  2. Rescana. Klue Supply Chain Breach Exposes OAuth Tokens and Salesforce Data in Multi-Stage Cybersecurity Incident (June 2026). Rescana, 2026. https://www.rescana.com/post/klue-supply-chain-breach-exposes-oauth-tokens-and-salesforce-data-in-multi-stage-cybersecurity-incident-june-2026 
  3. Trend Micro. The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables. Trend Micro, 2026. https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html 
  4. The Hacker News. Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data. The Hacker News, 2026. https://thehackernews.com/2026/06/salesforce-disables-klue-app.html 
  5. Verizon. 2026 Data Breach Investigations Report. Verizon, 2026. https://www.verizon.com/business/resources/reports/dbir/ 
  6. Google Cloud. Cloud Threat Horizons Report H1 2026. Google Cloud, 2026. https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026 
  7. Josys. Top SaaS Cybersecurity Risks in 2026. Josys, 2026. https://www.josys.com/article/top-saas-cybersecurity-risks