OAuth abuse drives identity attacks surge

The Hacker News ↗

The gist

Cybercriminals are ditching old-school software exploits for lightning-fast identity attacks, fueling an 850% surge in breaches by weaponizing trust and misconfigurations.

What to know

  • Attackers now gain initial access in minutes by exploiting misconfigured trust relationships and identity systems, leaving traditional perimeter defenses in the dust.
  • Groups like ShinyHunters and LSHIY LLC bypassed MFA and detection, using OAuth token abuse and vishing to compromise over 700 Salesforce customers and 64 Azure organizations.
  • Despite 85% of organizations knowing exposed credentials are a risk, fewer than 20% actively monitor them—making industrialized identity abuse the new battleground.

Trust: The New Attack Vector

Attackers now weaponize misconfigured trust relationships and legitimate tools, exploiting the security lag behind rapid technology adoption to gain undetected access within minutes.

By early 2026, cybersecurity attackers have decisively shifted from targeting traditional software vulnerabilities to exploiting trust relationships, identity systems, and misconfigurations. This evolution is marked by the industrialization of trust abuse, where adversaries no longer break in forcibly but instead walk through the doors organizations inadvertently leave open, leveraging the speed gap between rapid technology adoption and slower security validation processes. As a result, initial access timelines have compressed dramatically from months to mere minutes or hours, demanding a fundamental shift in defense strategies toward real-time detection and response focused on identity control and supply chain validation.

The growing reliance on AI, cloud-native development, and interconnected ecosystems has elevated the protection of trust relationships to a security priority equal to that of infrastructure itself. Attackers increasingly target critical infrastructure and trusted systems—such as medical research databases and AI development platforms—as exemplified by China’s UNC6508 campaign, which underscores the strategic value adversaries place on long-term intelligence collection through these channels. This shift challenges defenders to move beyond simply identifying vulnerabilities and toward understanding which trusted systems adversaries prioritize and how to safeguard them effectively.

Rather than breaking in, attackers now 'log in' using legitimate credentials and tools, exploiting trust relationships and legitimate platforms like OAuth apps, cloud APIs, and AI assistants to operate undetected within environments. Devon Ackerman highlights that breaches often stem not from failed security controls but from a lack of visibility into how these trusted technologies are weaponized. For example, attackers have used Microsoft Graph API to exfiltrate nearly 8.7 million files over three days without triggering traditional security alerts, demonstrating how the abuse of trusted infrastructure enables rapid data access and exfiltration without lateral movement or typical signs of compromise.

The concept of identity as the new security perimeter, established in 2025, has evolved in 2026 to encompass a broader spectrum of trust exploitation, including email authentication, cloud entitlements, software supply chains, AI gateways, and non-human identities. This expansion introduces complex challenges such as misconfigurations in federated identity systems—like Google Cloud Workload Identity Federation—that can inadvertently open doors to attackers. Furthermore, the visibility gap in administrative logs for token exchanges and the critical role of CI/CD systems as a new trust tier underscore the necessity for enhanced observability and deny-by-default policies. Attackers also industrialize trust abuse by harvesting session tokens and browser cookies to bypass MFA and maintain persistent access, illustrating the sophisticated and systemic nature of this threat landscape.

Sources

Identity Attacks Go Industrial

An explosion of credential leaks and OAuth abuse has turned identity into the primary breach point, with attackers bypassing MFA and exploiting SaaS trust to infiltrate hundreds of organizations.

Since 2022, identity-based attacks have surged to dominate the cybersecurity threat landscape, eclipsing traditional malware and exploits. Reports from Sophos and Red Canary reveal an explosive 850% year-over-year increase in identity threat detections, fueled by the massive availability of over 400 billion compromised credentials collected by firms like Qel. This vast trove enables attackers to bypass conventional hacking methods simply by logging in as legitimate users, underscoring identity as the new security perimeter.

The ShinyHunters group exemplifies the sophisticated exploitation of OAuth token abuse, leveraging social engineering and trusted third-party integrations to infiltrate over 700 Salesforce customers from mid-2025 through mid-2026. By conducting vishing campaigns that trick employees into approving malicious connected apps disguised as Salesforce’s Data Loader, they bypassed MFA and traditional detection, maintaining persistent API access. Compromises of vendors like Salesloft Drift and Gainsight further extended this attack chain, highlighting the cascading risks of overly permissive OAuth consent and misconfigured guest permissions in SaaS environments.

Attackers increasingly exploit identity chains in hybrid cloud environments, using AI to scale lateral movement and privilege escalation with alarming efficiency. Techniques such as session hijacking and adversary-in-the-middle phishing enable them to steal OAuth tokens and session cookies, effectively bypassing MFA protections that once seemed robust. This shift from brute-force password attacks to trust exploitation is evident in sectors like healthcare and legal, where groups like UNC6671 and ShinyHunters employ voice phishing to manipulate employees and helpdesk staff, registering their own MFA devices to maintain stealthy persistence.

Despite widespread recognition of identity-based threats, many organizations lag in continuous monitoring and remediation of exposed credentials, leaving them vulnerable to rapid exploitation. Studies show that while 85% of companies acknowledge compromised credentials as a primary attack vector, fewer than 20% actively monitor and respond to credential exposure, including infostealer logs—a critical blind spot. Experts stress that OAuth consent prompts are not mere formalities but pivotal security decisions requiring rigorous review, as attackers exploit token reuse and session hijacking to operate undetected. Although technical solutions like phishing-resistant MFA and passkeys exist, enterprise adoption remains slow due to fatigue and deployment challenges, emphasizing the urgent need for enhanced identity security practices supported by AI-driven detection.

Sources

Legacy Flows, Modern Breaches

Massive password-spraying campaigns and OAuth consent abuse reveal how outdated authentication flows and overlooked permissions enable attackers to persist invisibly across cloud and SaaS environments.

By mid-2026, the LSHIY LLC network orchestrated a staggering password-spraying campaign exploiting the deprecated OAuth Resource Owner Password Credentials (ROPC) flow in Microsoft Azure CLI environments, resulting in over 81 million login attempts and compromising 78 accounts across 64 organizations. This attack bypassed MFA and Conditional Access Policies because many organizations had misconfigured these controls, applying MFA only to select apps or user groups, leaving legacy authentication flows like ROPC dangerously exposed.

The LSHIY campaign’s sophistication extended to leveraging IPv6 bring-your-own-IP services, primarily from the 2a0a:d683::/32 range registered to LSHIY LLC with ties to Hong Kong and Wuhan, enabling rapid IP rotation that thwarted traditional IP-based defenses. Despite the high volume of successful logins, security researchers like Huntress’s Rich Mozeleski suspect the attackers focused on credential validation for resale rather than immediate exploitation, as no lateral movement or data exfiltration was detected.

Parallel to these credential-based exploits, the ShinyHunters group executed a trust-centric campaign against Salesforce customers from mid-2025 through mid-2026 by abusing OAuth consent mechanisms rather than platform vulnerabilities. Starting with vishing calls impersonating IT support, they tricked employees into authorizing a malicious connected app masquerading as Salesforce’s Data Loader, granting persistent access without malware or stolen passwords and evading traditional sign-in alerts by blending into legitimate user activity.

A major escalation occurred in August 2025 when ShinyHunters stole OAuth tokens from the Salesloft Drift AI chat integration, potentially exposing over 700 organizations including Cloudflare and Palo Alto Networks. By compromising trusted third-party vendors’ OAuth tokens, attackers bypassed conventional authentication alarms and accessed multiple Salesforce customer environments simultaneously, illustrating how exploitation of inter-organizational trust chains can amplify breach impact far beyond initial targets.

Sources

Zero Trust Becomes Survival

Organizations that prioritize real-time identity controls, micro-segmentation, and continuous validation now outperform those clinging to outdated perimeter defenses in the face of industrialized trust abuse.

By early 2026, cybersecurity defense paradigms had decisively shifted from mere prevention to real-time detection and response, with identity recognized as the frontline and the supply chain as the primary battlefield. Organizations that rigorously executed fundamental controls—such as identity governance, supply chain validation, behavioral detection, segmentation, and rapid patching—demonstrated markedly greater resilience against industrialized trust exploitation, underscoring that these controls are no longer aspirational but essential for survival.

The widespread abuse of legitimate credentials compelled a universal adoption of zero trust architectures and micro-segmentation, as attackers increasingly leveraged stolen identities to move laterally undetected within networks. Conditional access policies emerged as critical defenses, enabling organizations to enforce allow lists based on user, device, and contextual factors, thereby flagging anomalous identity usage and thwarting unauthorized pivots that traditional perimeter defenses failed to detect.

The rapid evolution of attacks exploiting trust relationships—particularly in hybrid cloud environments—drove defenders to embrace Identity Security Posture Management (ISPM) solutions like Qualys ETM Identity, which unify identity posture, exploitability, and asset context into a single risk model. Continuous validation and enhanced monitoring of trust relationships across Active Directory, cloud identities, and AI ecosystems became indispensable, especially as attackers increasingly bypassed multi-factor authentication by stealing session tokens or exploiting consent mechanisms granted to malicious applications.

As attackers harnessed AI to scale sophisticated credential and token reuse attacks, defenders responded by integrating AI-driven analytics to sift through voluminous logs and detect subtle anomalies like session token theft and MFA bypass. This technological evolution was complemented by a strategic emphasis on phishing-resistant authentication methods such as FIDO2 keys and passkeys, continuous compromised credential monitoring—which remains underutilized despite 85% of organizations recognizing credential compromise as a primary attack vector—and rigorous governance of AI assistants and cloud APIs, which have emerged as critical trust surfaces requiring vigilant oversight.

Sources

People: The Weakest Link

Sophisticated vishing, social engineering, and helpdesk manipulation bypass technical controls, proving that human vigilance and resilient processes are as vital as technology in stopping identity-driven breaches.

By mid-2026, it became clear that human factors such as social engineering remain a linchpin in trust-centric cyberattacks, with threat actors like ShinyHunters exploiting vishing tactics to manipulate employees into authorizing malicious OAuth applications or resetting credentials. These attacks, targeting major firms including Medtronic and OneMedical, reveal that technical controls like MFA are routinely bypassed through sophisticated impersonation and session hijacking, underscoring the vital need for robust identity verification processes and continuous human vigilance alongside evolving technical defenses.

Operational resilience has emerged as an indispensable complement to technical safeguards, requiring organizations to implement rigorous process controls such as 'no same-call' policies for helpdesk resets, manager approvals for privileged account changes, and rapid incident containment protocols. The Levi Strauss breach exemplifies how swift detection and containment, combined with strong communication strategies, can mitigate the fallout from social engineering attacks without disrupting business operations or compromising consumer data, highlighting that resilience is as much about process and people as it is about technology.

Communication strategies have become integral to cybersecurity, as evidenced by Origin Energy’s emphasis on preemptive, transparent messaging to counter misinformation during incidents and the widespread challenge that 40% of users still trust malicious messages. This human-centric approach extends to educating help desk personnel to recognize social engineering ploys and enforcing phishing-resistant authentication methods like FIDO2 security keys, reflecting a broader MSSP shift from traditional alert monitoring to managing complex identity and AI-driven environments where trust relationships are continuously evaluated and validated.

The evolving threat landscape, highlighted at BSides Las Vegas 2026, stresses that attackers increasingly exploit valid trust relationships rather than traditional vulnerabilities, pushing security responsibility deeper into trust policies, authorization processes, and human oversight. This shift demands enhanced observability, deny-by-default federation policies, and continuous assessment of all control planes, recognizing that human and process resilience—including rigorous identity verification and communication—are essential to detect and disrupt misuse of trust before attackers can leverage session artifacts or authentication tokens to bypass even advanced technical controls.

Sources

Trust Is Critical Infrastructure

Attackers target the interconnected web of SaaS, AI, and supply chains, forcing defenders to treat trust relationships as assets requiring continuous governance and risk validation far beyond traditional IT boundaries.

By mid-2026, the definition of critical infrastructure in cybersecurity has dramatically expanded beyond traditional IT assets to encompass supply chains, SaaS integrations, AI systems, and vendor relationships. This evolution reflects attackers’ strategic shift to exploit trust relationships rather than isolated vulnerabilities, as seen in breaches involving Valve's Steam data through CEVA Logistics and Levi Strauss's multifactor authentication compromise by the UNC6671 group. These incidents underscore the urgent need for holistic governance frameworks and continuous risk assessment that extend trust validation beyond internal systems to include OAuth tokens, AI plugins, third-party JavaScript, and cloud identity platforms.

The rapid adoption of AI technologies and cloud-native development has outpaced security measures, introducing novel vulnerabilities in AI model proxies and orchestration frameworks that broaden the attack surface. Attackers increasingly operate within trusted environments by leveraging compromised identities and delegated access, effectively inheriting trust controls rather than bypassing them. This shift compels defenders to continuously adapt to sophisticated tactics targeting not just systems but the very trust relationships that underpin modern infrastructure, transforming cloud and SaaS platforms into preferred operating environments for adversaries.

Effective management of trust as an attack surface now demands unprecedented visibility and governance across a diverse array of components including supply chains, development environments, browser extensions, and vendor-issued credentials. Traditional security approaches focused on patching and prevention are no longer sufficient; instead, trust validation must be integrated into cybersecurity defense strategies to mitigate risks stemming from trusted relationships. As one expert noted, 'Every major breach discussed today succeeded because attackers found a trusted relationship and exploited it,' highlighting the critical importance of trust validation alongside conventional security controls.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.