Avatier

Third-party or contractor access

Third-party access

Also called: OAuth app compromise

Third-party access is the standing access that vendors, contractors, partners and connected apps hold inside an organization's systems. Accounts, API keys and OAuth tokens granted to outsiders often carry broad permissions and get less scrutiny. If the third party is breached, the attacker inherits that access and arrives looking like a trusted integration.

How it works

An attacker compromises the vendor itself, or steals the tokens and credentials it uses to connect to customers. They then call the customer's systems through the approved integration, which can sidestep MFA, password resets and login monitoring. Because the traffic comes from a known app, it may not stand out.

A real example

A September 2025 FBI FLASH said that in August 2025 UNC6395 threat actors exploited compromised OAuth tokens for the Salesloft Drift application to compromise victims' Salesforce instances and exfiltrate data.

Source: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12

The Identity Attack Ledger holds 9 cited incidents for third-party or contractor access in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Keep an inventory of every third-party account and connected app, limit each to the data it needs, and revoke tokens and access when the work or contract ends.

Related terms

Threat actors that use it

Sources

  1. Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12

Last reviewed Oct 2, 2026