By the time you finish this paragraph, another company’s Salesforce, Slack, or Workday instance has likely been compromised. Attackers aren’t breaking down the door anymore – they’re simply logging in.

Take the August 2025 attack on Workday’s third-party CRM. This breach was part of a larger wave of attacks that hit major companies like Qantas, Adidas, and Google.

Companies are putting more of their important information into cloud-based apps (SaaS), which means attackers are focusing on these apps instead of the company’s internal network. A recent Veeam survey found that nearly 60% of IT leaders feel they have less control over where their company’s data is stored because of all these new apps.

Third-party SaaS breaches are now everyone’s problem. Let’s look at why SaaS is a soft target, how these attacks unfold, and the practical steps you can take to defend your organisation.

SaaS: The new frontier for cyberattacks

The old attacker playbook was to breach the perimeter, pivot through the network, and drop ransomware. That’s hard work. As security commentary in Cyber Defense Magazine puts it, why fight a hardened perimeter when you can just log in with valid credentials?

SaaS platforms make tempting targets because they hold the crown jewels: customer data in CRMs, payroll in HR systems, and candid conversations in messaging tools. But monitoring and defences are typically lighter than on-premises infrastructure.

There’s also a trust problem. SaaS apps implicitly trust valid credentials, sign-in authorisations (OAuth) tokens, and session cookies. From the platform’s point of view, attacker activity looks completely legitimate – because, technically, it is.

This trend is accelerating, according to the Veeam survey – to the point where 49% of IT leaders cite cybersecurity threats as the biggest disruptor for 2026, with AI-generated attacks (66%) now seen as the single greatest threat to data.

How does a third-party SaaS breach actually unfold?

These attacks tend to follow a predictable pattern. Once you can recognise it, you can defend against it. Here’s the typical attack chain, according to Cyber Defense Magazine and CrowdStrike’s 2026 threat research.

  • Step 1 – Credential acquisition: Attackers buy access cheaply. Infostealer malware-as-a-service costs as little as US$50 a month, and stolen credentials flood the market.
  • Step 2 – Targeting the integration: Rather than attacking the main platform, attackers compromise a trusted third-party app with broad OAuth permissions. It’s effectively an open backdoor with a welcome sign on it.
  • Step 3 – Moving fast and staying quiet: Once inside, attackers exfiltrate data using APIs, and create rules in the email system to automatically hide any warning messages, so no one gets alerted to their activity.
  • Step 4 – Extortion: Instead of encrypting systems, attackers threaten to leak stolen customer data. Think of it as ransomware without the malware.

The case studies bring this to life. The Salesloft/Drift campaign hit more than 700 organisations through compromised OAuth tokens, and a Gainsight-related breach affected another 200-plus Salesforce instances. In these incidents, the hackers didn’t take advantage of a software weakness. Instead, they just misused the trust given to these applications.

Why are these breaches so hard to detect?

Most security teams have spent years setting up their monitoring tools for traditional, on-premises software. But when it comes to cloud-based apps, they often have no visibility at all.

Part of the issue is logging. SaaS platforms log differently, and many critical logs (like Salesforce Event Monitoring or extended Slack audit logs) cost extra or aren’t switched on by default. If you’re not collecting the right logs, you can’t detect very much.

Traditional tools also fall short. SaaS attacks happen at the identity and API layer, and they look like normal user activity – because, technically, they are. Even response is tricky. Revoking OAuth tokens across hundreds of integrations breaks functionality and frustrates users, so many organisations quietly accept the risk.

This is a systemic issue, not a matter of trying harder. The Veeam survey backs this up, finding that only 29% of leaders feel very sure they could get their critical data back after an attack using a brand-new vulnerability.

How do you defend against third-party SaaS breaches?

But all is not lost. While the perimeter has moved to identity, there’s plenty you can do to take back control. Here’s a practical checklist.

  • Get visibility across your SaaS estate

Turn on detailed activity logs for all your software tools. You need to be able to see everything that happens to spot a problem. Make a list of all your software and what it’s connected to. For each tool, write down exactly what company data it can see or use.

  • Review which apps are connected to your software

If you find apps you don’t use or that have more access than they need, remove their permissions. It’s best to only give apps access to the exact data they need to do their job. Also, make sure to regularly refresh their access keys and log-out sessions.

  • Make sure users are who they say they are

Use strong multi-factor authentication (MFA) that can’t be easily phished, and set rules for when users can access your systems. Keep an eye out for unusual activity, like strange app permissions being granted, weird API access, or large amounts of data being downloaded suddenly.

  • Build SaaS-specific detection and response

Generic SIEM rules won’t cut it. You need security checks specifically designed for SaaS threats, such as the misuse of OAuth, data theft through APIs, and attackers moving between your cloud apps. The best way to do this is to constantly look for unusual activity, based on what’s normal for each of your apps and users.

  • Check the security of your partners and suppliers

Make sure your contracts clearly state what you expect from new vendors in terms of security. This is becoming a big deal for business leaders. Veeam found that 88% of them think it will be important to make sure their partners meet their cybersecurity standards by 2026.

  • Don’t forget data resilience and recovery

Even with strong defences, assume something will eventually slip through. SaaS data backup and recovery means you can bounce back if data is exfiltrated, deleted, or held to ransom. Solutions like Veeam are built for exactly this kind of SaaS data resilience. Remember, resilience is now a governance issue – not just a technical one.

Don’t wait for the breach notification

Third-party SaaS breaches have become one of the defining security challenges of our time, and the perimeter has well and truly moved to identity. The organisations that fare best won’t be the ones with the tallest walls. They’ll be the ones with the clearest visibility, the tightest integrations, and a solid recovery plan.

Want to know where your gaps are? Book a free consultation with Endpoint Focus to assess your SaaS and identity risk – and subscribe to our blog for more practical security guidance.

Published On: July 16th, 2026 / Categories: Security /

Leave A Comment

Subscribe to Receive the Latest Updates

Get our latest recommendations, advice and offers direct to your inbox.

We won’t share your details – but you can read more in our Privacy Policy.