TL;DR: The Workday breach sits inside a broader 2025 pattern where attackers are using voice phishing, malicious OAuth apps, and social engineering to bypass hardened infrastructure and move through SaaS connectivity, according to Grip Security. The real problem is not perimeter weakness but unmanaged trust across app-to-app connections, consent, and identity visibility, where conventional controls still miss the blast radius.
NHIMG editorial — based on content published by Grip Security covering the Workday breach and the wider SaaS attack wave: Workday breach joins a growing wave of SaaS attacks for 2025
By the numbers:
- In Q3 2024, organizations saw a 75% year-over-year increase in cyberattack volume, averaging 1,876 attacks per week.
- Australia saw data breach reports jump 25% in the second half of 2024 compared with the first half.
- Unit 42 reported that social engineering now plays a role in over a third of major intrusions.
Questions worth separating out
Q: How should security teams handle OAuth consent risk in SaaS environments?
A: Treat OAuth consent as an access control event, not a simple user choice.
Q: Why do SaaS attacks often bypass MFA?
A: Because MFA only protects the login event, while a valid session token or OAuth bearer token can remain trusted after authentication.
Q: What breaks when organisations cannot see shadow SaaS and third-party integrations?
A: Access reviews lose their value because they only cover what is visible.
Practitioner guidance
- Map the SaaS trust graph Inventory every managed app, shadow tenant, and third-party integration that can access business data, then identify which identities can approve exports or grant consent across them.
- Tighten OAuth consent governance Require administrative approval for high-risk OAuth scopes, review new app grants in near real time, and revoke tokens when the connected business need is no longer valid.
- Add identity checks to help-desk and vendor workflows Treat urgent IT, HR, and vendor requests as identity events, with callback verification and policy checks before users install software or approve access.
What's in the full article
Grip Security's full webinar covers the operational detail this post intentionally leaves for the source:
- Step-by-step examples of how malicious OAuth consent gets approved and abused across SaaS environments
- Operational guidance on identifying shadow tenants, unmanaged apps, and risky third-party connections
- Specific response ideas for revoking dangerous app grants and containing suspicious SaaS behaviour
- The webinar framing around the Workday breach and the wider 2025 SaaS attack wave
👉 Read Grip Security's analysis of the Workday SaaS breach wave and OAuth abuse →
SaaS trust failures in 2025: what identity teams are missing?
Explore further
SaaS trust debt is now an identity governance problem, not a single-app security problem. The article’s pattern shows that attackers are exploiting the accumulated trust relationships between users, apps, vendors, and delegated permissions. That is a governance failure because the access chain outlives any individual login event. Practitioners need to treat connected SaaS as a governed identity fabric, not a collection of isolated tools.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared with nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who is accountable when a user approves a malicious SaaS integration?
A: Accountability is shared across identity governance, application owners, and the business team that allowed the integration to exist without adequate review. The user may have clicked the approval, but the control failure sits in how the organisation manages consent, app onboarding, and ongoing recertification of connected access.
👉 Read our full editorial: Workday breach points to a wider SaaS trust failure in 2025