Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

SaaS trust failures in 2025: what identity teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: The Workday breach sits inside a broader 2025 pattern where attackers are using voice phishing, malicious OAuth apps, and social engineering to bypass hardened infrastructure and move through SaaS connectivity, according to Grip Security. The real problem is not perimeter weakness but unmanaged trust across app-to-app connections, consent, and identity visibility, where conventional controls still miss the blast radius.

NHIMG editorial — based on content published by Grip Security covering the Workday breach and the wider SaaS attack wave: Workday breach joins a growing wave of SaaS attacks for 2025

By the numbers:

Questions worth separating out

Q: How should security teams handle OAuth consent risk in SaaS environments?

A: Treat OAuth consent as an access control event, not a simple user choice.

Q: Why do SaaS attacks often bypass MFA?

A: Because MFA only protects the login event, while a valid session token or OAuth bearer token can remain trusted after authentication.

Q: What breaks when organisations cannot see shadow SaaS and third-party integrations?

A: Access reviews lose their value because they only cover what is visible.

Practitioner guidance

  • Map the SaaS trust graph Inventory every managed app, shadow tenant, and third-party integration that can access business data, then identify which identities can approve exports or grant consent across them.
  • Tighten OAuth consent governance Require administrative approval for high-risk OAuth scopes, review new app grants in near real time, and revoke tokens when the connected business need is no longer valid.
  • Add identity checks to help-desk and vendor workflows Treat urgent IT, HR, and vendor requests as identity events, with callback verification and policy checks before users install software or approve access.

What's in the full article

Grip Security's full webinar covers the operational detail this post intentionally leaves for the source:

  • Step-by-step examples of how malicious OAuth consent gets approved and abused across SaaS environments
  • Operational guidance on identifying shadow tenants, unmanaged apps, and risky third-party connections
  • Specific response ideas for revoking dangerous app grants and containing suspicious SaaS behaviour
  • The webinar framing around the Workday breach and the wider 2025 SaaS attack wave

👉 Read Grip Security's analysis of the Workday SaaS breach wave and OAuth abuse →

SaaS trust failures in 2025: what identity teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

SaaS trust debt is now an identity governance problem, not a single-app security problem. The article’s pattern shows that attackers are exploiting the accumulated trust relationships between users, apps, vendors, and delegated permissions. That is a governance failure because the access chain outlives any individual login event. Practitioners need to treat connected SaaS as a governed identity fabric, not a collection of isolated tools.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared with nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when a user approves a malicious SaaS integration?

A: Accountability is shared across identity governance, application owners, and the business team that allowed the integration to exist without adequate review. The user may have clicked the approval, but the control failure sits in how the organisation manages consent, app onboarding, and ongoing recertification of connected access.

👉 Read our full editorial: Workday breach points to a wider SaaS trust failure in 2025



   
ReplyQuote
Share: