OAuth Grants Are Multiplying Faster Than Anyone Can Review Them
Every "Allow" click on an OAuth consent screen creates a standing trust relationship between two applications — an AI note-taker gets a standing line into a calendar, a task manager gets a line into Slack, a new developer tool gets a line into source code. A October 8, 2026 report from BleepingComputer, drawing on data from SaaS security vendor Nudge Security, puts a number on the scale of the problem: the average employee now accumulates 88 OAuth grants, and 31 of those carry data-level permissions — direct, standing access to corporate information that persists long after anyone remembers granting it. The report's warning is not theoretical. It points to the Klue breach disclosed in June 2026, in which a forgotten, four-year-old API credential let an extortion group harvest OAuth tokens and pull Salesforce CRM data out of more than a hundred companies, as the clearest illustration yet of what unreviewed grants can cost.
Details
| Attribute | Value |
|---|---|
| Trend | OAuth grant sprawl across SaaS apps and AI integrations |
| Case Study | Klue (Battlecards) → customer Salesforce data exposure |
| Threat Actor | Icarus, an extortion group active since approximately April 2026 |
| Root Cause | An abandoned 2022 API credential left valid and unmonitored for four years |
| Attack Window | June 11–12, 2026 |
| Data Exposed | Salesforce contacts, opportunities, quotes, and sales notes; searches for embedded secrets in ticket/case fields |
| Estimated Scope | 195+ Klue customers estimated impacted; 13+ confirmed publicly |
| Confirmed Victims | LastPass, Huntress, Recorded Future, Tanium, Jamf, HackerOne, OneTrust, Snyk, and others |
| Industry Projection | 50% of SaaS breaches will stem from overprivileged OAuth tokens by 2027 (Gartner) |
How OAuth Grant Sprawl Outpaces Security Teams
The Math Doesn't Scale
According to the BleepingComputer/Nudge Security data, the average organization now has 40 apps with programmatic, non-human access to sensitive data — and a thorough manual review of a single OAuth grant takes roughly 45 minutes once an analyst accounts for the requesting app's permission scopes, the vendor's security posture, and the sensitivity of the data it can touch. Multiply that out: a 1,000-person company is sitting on roughly 88,000 total OAuth access paths, with an estimated 31,000 carrying direct access to sensitive data. No security team reviews tens of thousands of grants by hand, which means the overwhelming majority sit unexamined indefinitely.
Why OAuth Grants Evade Normal Access Controls
The report's core point is that OAuth is not a subset of identity and access management (IAM) — it is a separate protocol that most access-review processes were never built to cover. Single sign-on (SSO) governs how a user proves who they are at login; OAuth governs what an app can do with a user's data afterward, and the two don't automatically sync. Disabling a departing employee's account in Google Workspace or Microsoft 365 only suspends the grants that originated inside that platform — a grant issued by a third-party app continues operating uninterrupted, even after the person who approved it is long gone. Many grants also sit dormant for months, generating no log activity at all, yet remain fully valid and exploitable the moment an attacker finds them.
The Klue Breach: A Case Study in Forgotten Credentials
Klue, a Vancouver-based competitive-intelligence platform whose Battlecards product integrates with customer Salesforce instances, is the real-world example the report leans on. On June 11, 2026, the Icarus extortion group used a legacy GitHub personal access token — created in 2022 for a prototype integration that was never launched — to push unauthorized code into Klue's integration service. That credential had sat valid and unmonitored inside Klue's systems for four years. The injected code collected the OAuth access and refresh tokens Klue held on behalf of its customers to connect Battlecards to their Salesforce tenants. With those stolen tokens, Icarus queried customer Salesforce instances directly, posing as the trusted Klue integration, and exported contact records, opportunities, quotes, and sales notes — while also scanning ticket and case fields for embedded secrets such as API keys and passwords.
Salesforce alerted Klue to the anomalous activity on June 12; Klue engaged CrowdStrike for incident response and revoked all outstanding OAuth tokens by June 13, according to RH-ISAC. Estimates of the blast radius vary by source, but 195 or more Klue customers are believed to have been affected, with 13 or more confirming impact publicly, including LastPass, Huntress, Recorded Future, Tanium, Jamf, HackerOne, OneTrust, and Snyk. LastPass confirmed it was affected but said customer vaults were not accessed. The breach never touched Salesforce's own infrastructure — it rode in entirely on OAuth tokens that a trusted third-party integration had legitimately held for years.
Impact Assessment
| Impact Area | Description |
|---|---|
| CRM Data Exposure | Contact names, emails, job titles, phone numbers, sales opportunities, quotes, and notes exported from customer Salesforce tenants |
| Supply-Chain Blast Radius | A single compromised vendor (Klue) exposed data at 195+ downstream customers through standing OAuth trust |
| Secondary Credential Risk | Attackers searched case and ticket fields for embedded API keys, tokens, and passwords, risking further intrusions |
| Reputational | Named security vendors (LastPass, Huntress, Recorded Future, Tanium, Jamf) had to publicly disclose third-party exposure |
| Detection Gap | Dormant, unmonitored grants generate no telemetry, allowing a four-year-old credential to go unnoticed |
| Industry-Wide Trend | Gartner projects half of all SaaS breaches by 2027 will trace back to overprivileged OAuth tokens, not stolen passwords |
Recommendations
For SaaS and IT Admins
- Maintain a continuously updated inventory of every OAuth grant across Google Workspace, Microsoft 365, Salesforce, and other core SaaS platforms — not just the apps IT provisioned, but every integration an employee has personally authorized.
- Set calendar-based expiry or mandatory re-approval on integration credentials, especially those tied to pilots, proofs-of-concept, or vendor integrations that were never fully launched.
- Audit third-party API keys and personal access tokens for age; a credential with no owner check-in for years is a liability regardless of whether it was ever "used."
For Security Teams
- Treat OAuth grants as a distinct risk category from user identity — a disabled account does not mean every grant tied to that account is dead.
- Prioritize review of grants with data-level read/write scopes over login-only or metadata-only scopes; risk-score by vendor security posture, permission breadth, and data sensitivity rather than reviewing every grant equally.
- Build revocation playbooks for third-party SaaS vendors specifically, since a compromised vendor can expose many downstream customers through tokens the vendor — not the customer — controls.
For End Users
- Periodically review and revoke app connections in Google Workspace, Microsoft 365, and Salesforce "Connected Apps" settings, removing anything no longer in active use.
- Be deliberate about what scopes are approved when connecting a new AI tool, note-taker, or productivity app — broader access requested up front means broader exposure later.
- Report abandoned or "never actually launched" integrations to IT so associated credentials get decommissioned rather than left dormant.
Key Takeaways
- The average employee holds 88 OAuth grants, 31 of which carry data-level permissions — a scale no manual review process can keep up with.
- OAuth is a separate protocol from identity and authentication; disabling a user account does not automatically kill grants issued by third-party apps.
- The Klue breach shows how a single forgotten credential — a 2022 API token for an abandoned integration — can sit dormant for years before giving attackers a path into every customer that trusted the vendor.
- Icarus exploited stolen OAuth tokens to impersonate a trusted Salesforce integration, exporting CRM data from 195+ organizations including LastPass, Huntress, Recorded Future, Tanium, and Jamf.
- Gartner projects that 50% of SaaS breaches will stem from overprivileged OAuth tokens by 2027, making grant governance as critical as password hygiene.
- Organizations should inventory, risk-score, and periodically re-approve OAuth grants — with particular attention to abandoned vendor integrations and pilot credentials that outlive their original purpose.