Third-party or contractor access
Third-party access
Also called: OAuth app compromise
Third-party access is the standing access that vendors, contractors, partners and connected apps hold inside an organization's systems. Accounts, API keys and OAuth tokens granted to outsiders often carry broad permissions and get less scrutiny. If the third party is breached, the attacker inherits that access and arrives looking like a trusted integration.
How it works
An attacker compromises the vendor itself, or steals the tokens and credentials it uses to connect to customers. They then call the customer's systems through the approved integration, which can sidestep MFA, password resets and login monitoring. Because the traffic comes from a known app, it may not stand out.
A real example
A September 2025 FBI FLASH said that in August 2025 UNC6395 threat actors exploited compromised OAuth tokens for the Salesloft Drift application to compromise victims' Salesforce instances and exfiltrate data.
Source: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12
The Identity Attack Ledger holds 9 cited incidents for third-party or contractor access in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Keep an inventory of every third-party account and connected app, limit each to the data it needs, and revoke tokens and access when the work or contract ends.
Related terms
Threat actors that use it
- Scattered Spider
Profile with government sources
Sources
- Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12
Last reviewed Oct 2, 2026