Dormant OAuth tokens and abandoned SaaS integrations give attackers standing access to business systems long after the projects that created them have ended. The June 2026 Klue supply chain breach shows why every small and midsize business needs a third-party app integration inventory and a revocation process.
Most of the security failures we get called about have no villain. Nobody left a laptop in a taxi. Nobody wired half a million dollars to a stranger impersonating the CFO. Instead, somebody was solving an ordinary problem on an ordinary Tuesday, in the most reasonable way available to them . . . but the thing they created to solve it outlived both the problem and their memory of it. Then, some months or years later, a stranger found it and used it exactly as designed.
That a common shape of the incidents we see. It is also, as it happens, the shape of the largest SaaS supply chain breach of this summer.
How One Abandoned Integration Reached Nearly 200 Companies
This June, attackers compromised Klue, a market intelligence platform that hundreds of companies use to sync competitive research into their CRM systems. The intruders got in using a long-disused credential associated with an integration service account. From there they deployed code to harvest OAuth tokens, which let them impersonate Klue and reach into the connected Salesforce and Gong environments of Klue’s customers. Current reporting puts the blast radius at close to 200 organizations. Salesforce disabled the integration on June 17. The data taken was business contact records, pricing and quote information, and the free-text sales notes where employees write down what they actually think.
The victim list includes Huntress, Recorded Future, Tanium, Jamf, BeyondTrust, and LastPass. These are companies whose entire business is protecting other companies. But their core products were not touched. That matters enormously, but it tends to get lost in most of the headlines. What was taken instead was CRM data. And yes, there is a real difference between an embarrassing disclosure and an existential one.
Still. If organizations staffed with full-time threat researchers were exposed through a third-party integration they had authorized and then stopped thinking about, we gently suggest that your forty-person firm is not operating from a position of hidden strength.
Here is the detail that should stick with you. The credential the attackers used had been created for a third-party integration prototype that Klue later abandoned. In other words, somebody built something, evaluated it, decided against it, and moved on to the next thing. Which is entirely correct—that’s how competent organizations work.
The project ended. Trouble is, the credential did not.
Why OAuth Tokens Outlive the Projects That Created Them
You have seen the button. It says “Connect your Google Workspace account” or “Sign in with Microsoft,” and clicking it is a five-second decision. It doesn’t feel like some significant grant of authority. What it actually does is issue a durable token that lets an outside company’s software read your calendar, your files, your mail, or your customer records without anyone typing a password again.
That token has no relationship to your enthusiasm for the tool. It doesn’t lapse when the trial ends, when the vendor gets acquired, or when everyone agrees in a meeting that the pilot didn’t work out. It sits there, still valid. Its only natural predator is somebody deliberately going and revoking it, and that somebody has to know it exists.
We all tend to be disciplined about people and careless about software. That asymmetry is strange when you look at it directly. An employee resigns and a process kicks off: accounts get disabled, the badge comes back, the laptop gets wiped, and somebody signs off on all of it. But when a project dies? Frequently, nothing happens at all. There is no exit interview for an integration.
Compounding this, the person who clicks the button is rarely the person equipped to evaluate what it grants. A marketing coordinator connecting a scheduling tool to the company calendar is being resourceful, which is what you hired her for. She doesn’t mean to be careless. But she’s not in a position to know that the permission scope she just approved includes read access to every calendar in the tenant. That distinction is one my industry consistently fails to make, usually while selling awareness training.
The Integration Inventory Your Company Does Not Have
Ask your team for a current list of every third-party application authorized against your Microsoft 365 or Google Workspace tenant. Not just the applications you are paying for. The applications that are connected. Most companies we ask can’t produce that list inside of a week.
This is less negligence than it is an absence of ownership. Nobody was ever assigned the list, no system was ever designated to hold it, and no recurring calendar item exists to review it. Compare that with hardware: we’ve known for thirty years that you keep an asset inventory and reconcile it. IBM’s X-Force team reports that major supply chain and third-party breaches have quadrupled over the past five years. The attack surface grew faster than the paperwork, which, to be frank, is a pretty fair summary of the last decade.
How to Audit Third-Party App Access Before Somebody Else Does
The good news is that this is genuinely findable. In Microsoft 365, the answer lives in Entra ID under enterprise applications. In Google Workspace, it is the third-party app access controls in the admin console. In Salesforce, it is connected apps and their OAuth usage. Pull those lists, and for each entry ask who asked for this and what it still does. Anything you cannot answer gets revoked.
Then make revocation part of how projects end. When a pilot concludes, somebody signs off that the access created for it has been withdrawn, the same way somebody signs off on the equipment when a person departs.
The predictable failure mode is a message from a colleague two weeks later saying that her weekly report stopped running. That is what we in our business call a cheap afternoon. The alternative? Well, the alternative made the front page of every security publication in June.
So the question we’d put to your leadership team is not whether anyone here has been careless. Instead, ask who owns the list, and then watch what happens to the room.
TMG helps small and midsize organizations find out what they have actually authorized. If nobody in your company can produce that list, we should talk.