NEWS

OAuth Grants Pile Up Faster Than You Can Review Them — Here's How to Keep Up

OAuth grants are piling up faster than security teams can review them, and the Klue breach shows how one forgotten credential exposed data at dozens of firms.

Dylan H.

News Desk

October 8, 2026
8 min read
OAuth Grants Pile Up Faster Than You Can Review Them — Here's How to Keep Up

OAuth Grants Are Multiplying Faster Than Anyone Can Review Them

Every "Allow" click on an OAuth consent screen creates a standing trust relationship between two applications — an AI note-taker gets a standing line into a calendar, a task manager gets a line into Slack, a new developer tool gets a line into source code. A October 8, 2026 report from BleepingComputer, drawing on data from SaaS security vendor Nudge Security, puts a number on the scale of the problem: the average employee now accumulates 88 OAuth grants, and 31 of those carry data-level permissions — direct, standing access to corporate information that persists long after anyone remembers granting it. The report's warning is not theoretical. It points to the Klue breach disclosed in June 2026, in which a forgotten, four-year-old API credential let an extortion group harvest OAuth tokens and pull Salesforce CRM data out of more than a hundred companies, as the clearest illustration yet of what unreviewed grants can cost.


Details

AttributeValue
TrendOAuth grant sprawl across SaaS apps and AI integrations
Case StudyKlue (Battlecards) → customer Salesforce data exposure
Threat ActorIcarus, an extortion group active since approximately April 2026
Root CauseAn abandoned 2022 API credential left valid and unmonitored for four years
Attack WindowJune 11–12, 2026
Data ExposedSalesforce contacts, opportunities, quotes, and sales notes; searches for embedded secrets in ticket/case fields
Estimated Scope195+ Klue customers estimated impacted; 13+ confirmed publicly
Confirmed VictimsLastPass, Huntress, Recorded Future, Tanium, Jamf, HackerOne, OneTrust, Snyk, and others
Industry Projection50% of SaaS breaches will stem from overprivileged OAuth tokens by 2027 (Gartner)

How OAuth Grant Sprawl Outpaces Security Teams

The Math Doesn't Scale

According to the BleepingComputer/Nudge Security data, the average organization now has 40 apps with programmatic, non-human access to sensitive data — and a thorough manual review of a single OAuth grant takes roughly 45 minutes once an analyst accounts for the requesting app's permission scopes, the vendor's security posture, and the sensitivity of the data it can touch. Multiply that out: a 1,000-person company is sitting on roughly 88,000 total OAuth access paths, with an estimated 31,000 carrying direct access to sensitive data. No security team reviews tens of thousands of grants by hand, which means the overwhelming majority sit unexamined indefinitely.

Why OAuth Grants Evade Normal Access Controls

The report's core point is that OAuth is not a subset of identity and access management (IAM) — it is a separate protocol that most access-review processes were never built to cover. Single sign-on (SSO) governs how a user proves who they are at login; OAuth governs what an app can do with a user's data afterward, and the two don't automatically sync. Disabling a departing employee's account in Google Workspace or Microsoft 365 only suspends the grants that originated inside that platform — a grant issued by a third-party app continues operating uninterrupted, even after the person who approved it is long gone. Many grants also sit dormant for months, generating no log activity at all, yet remain fully valid and exploitable the moment an attacker finds them.

The Klue Breach: A Case Study in Forgotten Credentials

Klue, a Vancouver-based competitive-intelligence platform whose Battlecards product integrates with customer Salesforce instances, is the real-world example the report leans on. On June 11, 2026, the Icarus extortion group used a legacy GitHub personal access token — created in 2022 for a prototype integration that was never launched — to push unauthorized code into Klue's integration service. That credential had sat valid and unmonitored inside Klue's systems for four years. The injected code collected the OAuth access and refresh tokens Klue held on behalf of its customers to connect Battlecards to their Salesforce tenants. With those stolen tokens, Icarus queried customer Salesforce instances directly, posing as the trusted Klue integration, and exported contact records, opportunities, quotes, and sales notes — while also scanning ticket and case fields for embedded secrets such as API keys and passwords.

Salesforce alerted Klue to the anomalous activity on June 12; Klue engaged CrowdStrike for incident response and revoked all outstanding OAuth tokens by June 13, according to RH-ISAC. Estimates of the blast radius vary by source, but 195 or more Klue customers are believed to have been affected, with 13 or more confirming impact publicly, including LastPass, Huntress, Recorded Future, Tanium, Jamf, HackerOne, OneTrust, and Snyk. LastPass confirmed it was affected but said customer vaults were not accessed. The breach never touched Salesforce's own infrastructure — it rode in entirely on OAuth tokens that a trusted third-party integration had legitimately held for years.

Impact Assessment

Impact AreaDescription
CRM Data ExposureContact names, emails, job titles, phone numbers, sales opportunities, quotes, and notes exported from customer Salesforce tenants
Supply-Chain Blast RadiusA single compromised vendor (Klue) exposed data at 195+ downstream customers through standing OAuth trust
Secondary Credential RiskAttackers searched case and ticket fields for embedded API keys, tokens, and passwords, risking further intrusions
ReputationalNamed security vendors (LastPass, Huntress, Recorded Future, Tanium, Jamf) had to publicly disclose third-party exposure
Detection GapDormant, unmonitored grants generate no telemetry, allowing a four-year-old credential to go unnoticed
Industry-Wide TrendGartner projects half of all SaaS breaches by 2027 will trace back to overprivileged OAuth tokens, not stolen passwords

Recommendations

For SaaS and IT Admins

  • Maintain a continuously updated inventory of every OAuth grant across Google Workspace, Microsoft 365, Salesforce, and other core SaaS platforms — not just the apps IT provisioned, but every integration an employee has personally authorized.
  • Set calendar-based expiry or mandatory re-approval on integration credentials, especially those tied to pilots, proofs-of-concept, or vendor integrations that were never fully launched.
  • Audit third-party API keys and personal access tokens for age; a credential with no owner check-in for years is a liability regardless of whether it was ever "used."

For Security Teams

  • Treat OAuth grants as a distinct risk category from user identity — a disabled account does not mean every grant tied to that account is dead.
  • Prioritize review of grants with data-level read/write scopes over login-only or metadata-only scopes; risk-score by vendor security posture, permission breadth, and data sensitivity rather than reviewing every grant equally.
  • Build revocation playbooks for third-party SaaS vendors specifically, since a compromised vendor can expose many downstream customers through tokens the vendor — not the customer — controls.

For End Users

  • Periodically review and revoke app connections in Google Workspace, Microsoft 365, and Salesforce "Connected Apps" settings, removing anything no longer in active use.
  • Be deliberate about what scopes are approved when connecting a new AI tool, note-taker, or productivity app — broader access requested up front means broader exposure later.
  • Report abandoned or "never actually launched" integrations to IT so associated credentials get decommissioned rather than left dormant.

Key Takeaways

  1. The average employee holds 88 OAuth grants, 31 of which carry data-level permissions — a scale no manual review process can keep up with.
  2. OAuth is a separate protocol from identity and authentication; disabling a user account does not automatically kill grants issued by third-party apps.
  3. The Klue breach shows how a single forgotten credential — a 2022 API token for an abandoned integration — can sit dormant for years before giving attackers a path into every customer that trusted the vendor.
  4. Icarus exploited stolen OAuth tokens to impersonate a trusted Salesforce integration, exporting CRM data from 195+ organizations including LastPass, Huntress, Recorded Future, Tanium, and Jamf.
  5. Gartner projects that 50% of SaaS breaches will stem from overprivileged OAuth tokens by 2027, making grant governance as critical as password hygiene.
  6. Organizations should inventory, risk-score, and periodically re-approve OAuth grants — with particular attention to abandoned vendor integrations and pilot credentials that outlive their original purpose.

Sources