Awareness Lessons
4 months ago
Compromised Legacy Credential in Third-Party Integration Leads to Multi-Org Data Breach
A threat actor exploited a compromised legacy credential within Klue's Salesforce integration to generate OAuth tokens, enabling unauthorized access to over a dozen organizations' CRM and contact data. The root failure was the continued existence and use of a stale, unrotated credential tied to a third-party integration — a classic supply chain access control gap. This incident illustrates how a single weak link in a vendor's integration layer can cascade into breaches across multiple downstream customers. It also highlights the danger of OAuth token misuse when initial authentication controls are insufficiently hardened.
Tactical Insight
Immediate actions
- Audit and revoke all legacy, unused, or long-lived credentials associated with third-party integrations immediately.
- Review and disable OAuth tokens granted to any vendor integrations that cannot be verified as actively monitored and necessary.
- Identify all Salesforce-connected third-party applications and validate their current access scopes against the principle of least privilege.
Long-term improvements
- Enforce credential rotation policies for all service accounts and integration credentials on a defined schedule (e.g., 90-day maximum lifetime).
- Implement a formal third-party vendor risk management program that includes periodic security assessments of integration points.
- Adopt a Zero Trust architecture for all third-party integrations, requiring continuous verification rather than relying on persistent credentials.
Detection measures
- Enable Salesforce event monitoring and alert on anomalous OAuth token generation or bulk data export activities.
- Integrate SIEM rules to detect unusual API call volumes or off-hours access patterns originating from third-party integration accounts.
- Require vendors to provide real-time incident notification SLAs as part of contractual agreements to reduce dwell time.