[DEEP RESEARCH] The User Was Phished. The Token Moved the Data
The user may start the incident. OAuth apps, tokens, and integrations can turn it into quiet, scalable data theft.
The user may start the incident. OAuth apps, tokens, and integrations can turn it into quiet, scalable data theft.
Everyone loves a “trusted app” until it turns into a long-lived permission slip with better branding.
The platform can stay technically unbroken and you still get cleaned out. That gap is the problem.
No malware. Still owned. 🧾🔑💬
Device-code phishing + Teams as the “lobby” + stolen OAuth tokens = API-speed SaaS exfil. If you’re hunting binaries, you’re late.
Part 2: OAuth consent scams went from “one guy” to a token factory 🎅🏭🔑
Salesloft/Drift showed how stolen OAuth tokens → Salesforce tenant exfil at scale. Google Cloud+1
Deep dive + defenses (verified publisher, least scope, fast revoke MTTR).
2026’s nastiest SaaS breaches will ride valid tokens + “trusted” apps. We already got the trailer with the Salesloft/Drift OAuth blast radius. And the browser? Yeah, it’s part of the perimeter now. 😬🔑💬
UNC3944, UNC6040, and UNC6395 are executing targeted campaigns against SaaS, cloud, and virtualization environments, leveraging vishing, OAuth abuse, and supply-chain compromise. Their TTPs require precise, telemetry-driven controls and detection.