TL;DR: Cross-tenant analysis of the Salesloft-Drift supply chain breach identified every impacted organization in its customer base within 30 minutes and surfaced Google Workspace scope before others reported it, showing how SaaS integrations can hide cross-service compromise across 700+ victims, according to Obsidian Security. The lesson is that integration-layer visibility, not isolated log search, now determines whether SaaS identity risk can be investigated at all.
NHIMG editorial — based on content published by Obsidian Security covering the Salesloft-Drift breach: How Obsidian Security Found What 700 Companies Couldn't: A SaaS Supply Chain Investigation
By the numbers:
- Obsidian Security found the blast radius of this supply chain attack was 10x greater than previous incidents, where attackers infiltrated Salesforce directly.
Questions worth separating out
Q: What breaks when SaaS integrations are not governed as non-human identities?
A: Teams lose visibility into who or what can reach connected systems, and attackers can use trusted credentials to move through those integrations without triggering normal human-account controls.
Q: Why do SaaS supply chain breaches often outpace single-tenant investigations?
A: Because the same malicious activity can look normal in one environment and only become obvious when compared across many.
Q: What do security teams get wrong about OAuth and connected apps?
A: Teams often assume a delegated app is safe because it was approved once, but approval is not the same as ongoing trust.
Practitioner guidance
- Inventory every SaaS integration as a governed identity Build a complete register of OAuth grants, connected applications, and service tokens, including owner, scope, expiry, and the business service each one can reach.
- Correlate SaaS telemetry across tenants and services Normalise user-agent, IP, email, UPN, and display name fields so an indicator in one platform can be compared against activity in another.
- Tie integration offboarding to access revocation When a vendor relationship changes or an app is no longer required, revoke the token, disable the grant, and verify the removal across all connected SaaS systems.
What's in the full report
Obsidian Security's full blog post covers the operational detail this post intentionally leaves for the source:
- The cross-tenant query logic used to identify impacted organisations across more than 200 connected SaaS platforms
- The specific detection patterns for user-agent baselining, IP prevalence scoring, and identity field normalisation
- The sequence of investigation steps that surfaced Google Workspace scope before wider public reporting
- The practical examples of how expanded IOC lists were used to stabilise the victim set
👉 Read Obsidian Security's analysis of the Salesloft-Drift SaaS supply chain breach →
Salesloft-Drift and SaaS supply chain risk: what changed for teams?
Explore further
Integration-layer identity is now the real SaaS perimeter. Obsidian's research reinforces that the attack surface in SaaS is not just the human user or the application itself, but the delegated identity sitting between them. OAuth grants, connected apps, and service tokens create standing access relationships that can be abused at scale when trust is inherited from the integration rather than continuously verified. Practitioners should treat every connected app as a governed identity with scope, ownership, and expiry.
A few things that frame the scale:
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
- That same report says 80% of organisations report AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, and revealing credentials.
A question worth separating out:
Q: Who is accountable when a compromised SaaS integration is used to move across multiple clouds?
A: Accountability sits with the teams that own connected-app governance, SaaS administration, and cloud identity controls, because the failure crosses system boundaries. A single platform team cannot see the whole path. Organisations should map responsibility for consent, revocation, logging, and secret response before the next integration is authorised.
👉 Read our full editorial: Cross-tenant intelligence exposed the full Salesloft-Drift blast radius