In August 2025, a single compromised OAuth token from the Salesloft Drift chatbot integration handed attackers access to Salesforce environments across more than 700 organizations — Cloudflare, Zscaler, Palo Alto Networks, and CyberArk among them. The attackers didn't exploit a vulnerability. They didn't brute-force a password. They stole a token that was supposed to be trusted and walked through digital front doors that were already standing open.
That wasn't a fluke. It was the defining attack pattern of 2025.
The Verizon 2025 Data Breach Investigations Report found that 30% of all data breaches now involve a third party, double the previous year's rate. IBM's X-Force Threat Intelligence Index 2026 found supply chain and third-party breaches quadrupled over the past five years. Cyble's threat intelligence tracked supply chain attacks averaging 26 per month since April 2025, twice the long-term average. The cost? IBM pegs the average supply-chain-linked breach at $4.44 million, with the messier incidents running well above that.
The takeaway is hard to dodge: your vendors' security posture is now your security posture. And traditional third-party risk management — annual questionnaires, SOC 2 reports, periodic audits — is structurally unequipped for attackers who exploit trust at machine speed.
I spend most of my time inside customers' SaaS and cloud estates, and the thing that still surprises teams is how little their existing tooling has to say when the access is technically valid. That gap is the whole story here.
How modern supply chain attacks actually work
The supply chain threat has moved well past the SolarWinds model of poisoned software updates. In 2025, attackers settled into a more efficient playbook: target the integrations, steal the tokens, and inherit trusted access to hundreds of downstream organizations at once.
OAuth tokens are the new skeleton key. Token theft accounted for 31% of Microsoft 365 breaches in 2025, overtaking traditional credential compromise as the primary attack vector. A stolen OAuth token isn't like a stolen password. It bypasses MFA entirely, because it represents proof of already-completed authentication. Compromise a vendor's OAuth integration and you get the same persistent, trusted API access the vendor had, usually with broad read and write permissions across customer environments.
The Salesloft Drift breach showed this with brutal precision. Threat actor UNC6395 stole OAuth tokens from the Drift chatbot's Salesforce integration. Those tokens granted API-level access to customer CRM data: contacts, case histories, opportunities, embedded credentials. Cloudflare's forensic analysis laid out the attackers' surgical method. They enumerated objects, fingerprinted workflows, measured API limits, ran dry-run queries, then executed a three-minute Bulk API exfiltration before deleting their jobs to cover their tracks. Obsidian Security researchers found the blast radius was 10 times larger than earlier incidents where attackers had hit Salesforce directly.
The domino effect is speeding up. Salesloft Drift didn't stay contained to Salesforce. Attackers pulled out AWS keys, Snowflake tokens, and API credentials embedded in case text fields, which let them pivot into entirely separate platforms. By November 2025, the same playbook ran again through Gainsight, compromising another 200+ Salesforce instances. Compromise one integration, harvest credentials, pivot to the next: that pattern creates cascading failure across interconnected SaaS ecosystems. We trace one of those cascades in detail in our breakdown of the Anodot and Snowflake SaaS integration token theft.
Access brokers are industrializing the supply chain. Chainalysis found that initial access broker payments spiked roughly 30 days before ransomware attacks. The average price for victim access fell from about $1,427 in Q1 2023 to just $439 by Q1 2026, a reflection of industrialized pipelines, AI-assisted tooling, and an oversupply of cheap access flooding the market. For ransomware crews, buying pre-compromised vendor access now costs less than a monthly software subscription.
Vendor breaches stay hidden for months. Black Kite's research found a median disclosure delay of 73 days between breach and public notification, with more than 26,000 unnamed downstream victims. During that silent window, attackers work freely with trusted vendor credentials, and your security tools have no reason to flag the activity.
Why traditional third-party risk management falls short
Let's be honest about how vendor risk management actually runs in most organizations.
Annual assessments are snapshots, not surveillance. A SOC 2 Type II report tells you a vendor's controls were adequate during a specific audit window. It says nothing about whether those controls hold right now, or whether the vendor is already compromised. The Salesloft Drift attackers had access to Salesloft's GitHub environment from March through June 2025 before they ran the downstream OAuth attack in August. No questionnaire catches that.
You can't audit what you can't see. Most enterprises run roughly 490 cloud applications, many unsanctioned or poorly secured. Each one spins up OAuth tokens, API keys, and integration connections that grow your attack surface without ever landing in a risk register. When a vendor is breached, the tokens they hold become attacker tools, and your CASB, SIEM, and EDR can't tell the vendor's legitimate automated access apart from an attacker riding the same tokens.
Concentration risk is invisible. Black Kite identified an "Elite 50," a small group of widely shared vendors whose compromise would cascade across entire industries. If you share a critical SaaS vendor with hundreds of other companies, one breach in that vendor's environment exposes your data alongside everyone else's. A vendor questionnaire never surfaces that risk.
Token-based attacks sail past your perimeter. When an attacker uses a stolen OAuth token, there's no login event to flag, no MFA challenge to intercept, no credential stuffing to detect. The token is valid. The access is authorized. The API calls look identical to normal integration traffic. That's exactly why conventional monitoring fails. You're hunting for unauthorized access, but the access is technically authorized. It's just the wrong person holding it.
The deception advantage: catching breaches from the inside
Cyber deception offers something no vendor assessment, CASB, or token management platform can: detection at the moment compromised access is turned against your environment, no matter how legitimate that access looks.
The principle is simple. You plant decoy assets — fake credentials, bogus documents, honeytoken API keys — throughout your environment. When a compromised third-party integration or a stolen token is used to reach or enumerate your systems, the attacker inevitably touches a decoy. The alert fires. Zero false positives. No behavioral baselines to maintain. No need to separate legitimate vendor activity from attacker activity, because if anyone touches the honeytoken, it's unauthorized. This is the same model we walk through in our case study on a SaaS company that prevented a breach with Mine2 honeytokens.
Honeytokens in SaaS environments detect token abuse
The Salesloft Drift attackers methodically enumerated Salesforce objects to find high-value data. Mine2 honeytokens planted inside your Salesforce instance — fake customer records, bogus case entries with embedded decoy credentials, honeytoken API keys stuffed into custom fields — create tripwires that fire the moment an attacker or a compromised integration starts enumerating.
This works especially well against supply chain attacks because the attacker's method demands broad discovery. They don't know where the valuable data sits, so they query everything, and the honeytoken catches the sweep before real data leaves.
Decoy credentials catch credential harvesting
One of the most damaging parts of Salesloft Drift was the extraction of embedded credentials — AWS keys, Snowflake tokens, API secrets — sitting in Salesforce case text fields. Attackers harvested them to pivot into new platforms.
Mine2 honeytokens planted as fake AWS keys, bogus database connection strings, and decoy API tokens in the places real credentials tend to pile up (config files, documentation wikis, support ticket fields, code repositories) act as canaries. When an attacker, whether through a compromised vendor integration or a direct breach, finds and tries to use a honeytoken credential, you get an immediate alert that identifies both the compromised access vector and the attacker's intent. The same dynamic shows up across the OAuth token theft and device-code phishing pattern we've documented.
MineField decoy services detect vendor credential abuse on your network
When third-party vendors have VPN access, RMM tool access, or direct network connectivity, a breach at the vendor level hands attackers a trusted path into your infrastructure. Mine2's MineField deploys decoy services that vendor tooling should never touch. Any connection from a vendor's IP range or credential set to a decoy service is an immediate sign that the vendor's access has been compromised.
That directly tackles the access broker problem. When a purchased credential or compromised vendor account starts scanning your network, MineField catches the reconnaissance before the attacker reaches real production systems.
Cloud Mines detect compromised cloud integration access
Cloud-native supply chain attacks target IAM roles, service accounts, and cross-account trust relationships. Mine2's Cloud Mines scatter fake AWS resources — phantom S3 buckets, decoy Lambda functions, honeytoken IAM credentials — across your cloud footprint. When a compromised integration tries to enumerate resources using valid but attacker-controlled credentials, Cloud Mines trigger before any real resource is touched.
This is particularly effective against the cascading pivot pattern from 2025's major incidents, where attackers used credentials pulled from one platform to move into cloud environments.
A practical playbook for deception-layered supply chain defense
Here's how to build a deception layer aimed specifically at third-party and supply chain breaches.
1. Audit and seed your SaaS integrations
Map every OAuth integration, API key, and service account connection in your SaaS estate. For each one, plant honeytoken records in the connected application — fake records in Salesforce, decoy entries in Workday, bogus files in Google Drive — that only fire when reached through unauthorized enumeration. (The Workday phishing and CRM breach warning is a good reminder of why these connected apps matter.)
2. Plant honeytoken credentials where real secrets accumulate
Secrets end up where they shouldn't: support tickets, internal wikis, shared drives, Slack channels, code repositories. Plant honeytoken AWS keys, database passwords, and API tokens in those same spots. When a supply chain breach leads to credential harvesting, the honeytokens fire before real secrets get exploited.
3. Deploy MineField on vendor-accessible network segments
Put decoy services on segments reachable by third-party VPN connections and RMM tools. Establish a baseline of legitimate vendor traffic: which IPs, which services, which times. Any vendor credential that lands on a MineField decoy points to compromised access.
4. Extend Cloud Mines across cross-account trust boundaries
Deploy honeytokens in cloud accounts with trust relationships to vendor-managed infrastructure. Focus on IAM role assumption paths and cross-account S3 access patterns. When an attacker pivots through a compromised vendor's cloud access, the Cloud Mines fire at the boundary.
5. Harden the foundation with Fortify
Use Mine2's Fortify to remove unnecessary privileges, disable dormant service accounts, and trim OAuth scopes to the minimum required. Hardening shrinks the blast radius of any vendor breach, while deception catches the breaches that get through.
6. Wire deception alerts into your vendor incident response
When a honeytoken fires on a vendor-accessible segment, your automated response should immediately revoke the vendor's OAuth tokens, disable the integration, isolate affected systems, and notify the vendor of potential compromise. Speed is everything here. Cloudflare's analysis showed the Salesloft Drift attackers finished their exfiltration in three minutes.
Where this leaves you
The supply chain attack epidemic isn't slowing. Third-party breaches have doubled, token theft has eclipsed credential abuse as the primary vector, and access brokers have industrialized the market for compromised vendor connectivity. Your vendors' security is your security, and annual questionnaires won't protect you from an attacker who can exfiltrate your data in under three minutes with a valid OAuth token.
Deception technology addresses the blind spot directly. It doesn't need to know whether a third-party integration is legitimate or compromised. It doesn't lean on behavioral baselines that attackers can evade. It just makes sure every enumeration, every credential harvest, and every unauthorized access attempt runs into a tripwire that fires with certainty.
When a single compromised chatbot integration can cascade into 700+ breached organizations, that certainty is the difference between catching the breach and becoming another unnamed entry in the downstream victim count.
Want your vendor integrations working as a detection layer instead of a liability? See how Mine2's honeytokens catch supply chain breaches →
Neha
Cloud Security Architect, Mine2
Neha works on cloud and identity security at Mine2, covering SaaS, OAuth, and the credential-theft paths attackers favour in the cloud.
Recent Articles
Need Security Help?
Protect your organization with MINE2's cyber deception platform.
