logo
Background Pattern
Blogs | Password Breach? It’s an OAuth Grant Breach Now
StarCybersecurity

Password Breach? It’s an OAuth Grant Breach Now

Password Breach? It’s an OAuth Grant Breach Now & Nobody Even Remembered Giving Approval

Cybersecurity companies in the USA, UK, and Qatar understand and acknowledge the danger looming over company databases. Being one of the most renowned cybersecurity companies, Tycoonz Solutions has assisted startups, SMEs, and big corporations in these countries and others worldwide by working on cybersecurity projects and data preservation.

If you are a business owner, knowing how security is changing and why companies should not take the upgrades lightly is crucial.

It used to always be about the passwords. The solution? Make it difficult, add symbols, and keep changing it every now and then. For twenty years, the cybersecurity industry optimized for one threat model: a human with a password, and an attacker trying to guess or steal it.

That problem is, more or less, solved. MFA, password managers, and identity providers have made credential theft harder than it used to be. But new problems keep on coming. Nobody solved the next problem, because most companies didn't realize it existed yet. The older cybersecurity threats were easy, convenient, and had a solution, but breaches evolved.

How’s It Going?

By 2026, machine identities, including AI agents, outnumber human identities 109 to 1 inside the average enterprise, according to Palo Alto Networks' Identity Security Landscape report. This report was based on a survey of nearly 3,000 security decision-makers.

Before:

That ratio was 82 to 1 just a year earlier.

Now:

It is currently 109 to 1, on average.

Of every 109 machine identities per human, roughly 79 are AI agents.

Other researchers count more conservatively. Cloud Security Alliance-aligned research puts the median at 45 to 1, up from 17 to 1 in 2023, and notes that most CISOs admit they can't fully estimate half the machine identities running in their own environment. The exact number depends on who's counting and how. The direction doesn't.

This isn't an abstract governance problem. IBM’s newly released Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million. This breach shows a 12% jump over last year and a record-high one too. This huge jump was found to be driven by higher detection, escalation, and ultimately lost-business costs.

To be exact, AI-driven attacks, led by deepfake impersonation and AI-enabled malware, rose 56% year over year. These AI-driven attacks are not going to stop; in fact, we see them rise in the upcoming days.

IBM's own recommended response, front and center in that report, isn't “train employees to spot phishing.” It's securing agentic identities. And this is exactly what the Tycoonz Solutions team stands for as well. Identifying, accepting, planning, and being an aggressive player in fighting the security breaches before they happen is crucial.

Case One: The Nation-state Playbook Hasn't Changed, Only The Target

In January 2024, Microsoft disclosed that Midnight Blizzard, which is the Russian state-sponsored group also known as APT29, responsible for the SolarWinds compromise, had been inside its corporate environment since November 2023.

The entry point was a legacy, non-production test account that had never been updated to meet modern security standards: an easy-to-guess password, no MFA.

Indeed, don’t just wait for it to happen.

Because here, from that low-value account, the attackers found and compromised a legacy test OAuth application that still carried elevated access to Microsoft's corporate environment, specifically, the Office 365 Exchange Online full_access_as_app permission.

That single forgotten OAuth grant is what turned a throwaway test account into unrestricted access to the mailboxes of Microsoft's senior leadership and security teams.

The lesson wasn't "use MFA everywhere," although that's true. It was: an OAuth token doesn't care how unimportant the account attached to it looks.

Note: Privilege travels with the grant, not with the account's perceived importance.

Case Two: When The Platform Is Secure, But The Identity Hygiene Isn't

In mid-2024, roughly 165 organizations using the cloud data platform Snowflake were breached. And this was not because Snowflake's platform had a vulnerability, but because attackers, tracked as UNC5537 and operating publicly as ShinyHunters, used credentials harvested years earlier by infostealer malware from employee devices to log directly into customer tenants that had never enabled multi-factor authentication.

Note: Now you get why your employers request you to turn on multi-factor authentication, right?

The damage?

It turned out to be roughly 110 million AT&T customers' call and text metadata and around 560 million Ticketmaster customer records, among other victims including Santander and Advance Auto Parts. Yes, the threat actor behind it was arrested in October 2024. But there is a lesson here.

The platform did its job.

But the customers' identity hygiene didn't.

You have to understand how the whole problem starts; be it with Tycoonz Solutions or any other reliable cybersecurity company in your country, give us/them a call. Our team is ready to help your company’s cybersecurity.

Case Three: The 2026 Pattern: Shadow AI As The New Supply Chain

This is the case study that defines where the identity problem is heading.

Also, this case is not even a year old.

In February 2026, an employee at an AI startup called Context.ai had their machine infected with Lumma Stealer malware, which harvested corporate credentials, browser session cookies, and stored OAuth tokens.

The connection to Vercel, which is basically a widely used cloud deployment platform, existed only because a Vercel developer had personally trialed Context.ai's consumer AI tool and authenticated it with their corporate Google Workspace account.

Sadly, this was an integration that was never reviewed or approved by security.

OAuth tokens function as bearer credentials, and so whoever holds one can query the APIs it authorizes, with requests appearing to come from a legitimate, already-authenticated client. That means interactive MFA is bypassed entirely, and the access stays valid until someone actively revokes it.

The attacker used the stolen token to walk directly into the Vercel employee's account, reached into internal dashboards, employee records, API keys, and both NPM and GitHub tokens.

Vercel disclosed the incident on April 19, 2026, confirming that environment variables for a limited subset of customer projects had been exposed and noting the compromise stemmed specifically from third-party OAuth integrations and unauthorized "shadow AI" tool use.

Nobody phished Vercel. Nobody cracked a password. An employee tried a consumer AI product, and that single, well-intentioned OAuth click became the entire attack surface.

This is not an isolated incident. Other cases also surfaced in different years before 2026.

Different companies, different entry points, same structural failure: identity governance built for humans, applied to a world that's now mostly machines.

Why Does The Old Playbook Not Reach This Problem?

Vaults were built by infrastructure teams for infrastructure teams.

Identity governance was built by IT and compliance for human employees.

For years, these two disciplines have been treated as separate silos.

And that divide is now a structural security hole, because nobody owns the lifecycle of the credential in between.

Tycoonz Solutions teams have worked with various clients around the world and found the following:

A service account created for a two-week project doesn't get decommissioned when the project ends.

You cannot govern an identity that no longer has a human owner attached to it.

And based on the above and more lessons, we need to bring changes very, very soon.

What Actually Needs To Change In Order

1. Inventory before you govern.

We highly recommend that you discover every non-human identity, classify it, rotate the short-lived ones, kill the long-lived ones that shouldn't exist, and build an attribution chain back to a specific human owner for every credential that remains.

2. Make OAuth consent a privileged-access decision, not a UX click.

Next, make sure that you and your team (or us when you hire our team) audit every “Allow All” scope grant against Google Workspace or Microsoft 365 today, not next quarter.

3. Give employees a sanctioned path, or they'll build an unsanctioned one.

A security team that has no approved AI-tool pipeline is guaranteeing more Context AI similar incidents, not preventing them.

4. Move from static to ephemeral credentials.

A stolen API key that's already dead by the time anyone tries to use it is a very different risk than one that's been valid, unrotated, and unwatched since 2020.

5. Build runtime controls for agentic AI specifically, not just for the humans who deployed it.

IBM's own guidance for 2026 calls for dynamic, identity-based access controls for AI agents. It means tightly scoped permissions enforced continuously at runtime, with human attribution and auditability for every action an agent takes. Recent data shows that the above is now a standard already adopted by 61% of US companies that now mandate a human-in-the-loop requirement before an autonomous agent can act.

The Point Companies Keep Missing

None of the incidents above involved a sophisticated zero-day. At one end, someone used a weak password on a test account.

In another incident, the attackers used credentials that were already for sale.

In yet another case, the breach started with an employee trying a productivity tool.

In every setup, the technology already existed to prevent it. This means MFA, rotation, scoped permissions, and discovery tooling.

What was missing was the assumption that these accounts mattered enough to govern in the first place.

Going into 2027, the question worth asking in every security review isn't “who has access to this system.” It's “what has access, and does anyone still know why?” If you have the answer to these questions, you are already in the lead.

Finally, this is the time to take matters into our own hands with specialists working in cybersecurity: Tycoonz Solutions’ team is already on standby. Call the team right now.

Tycoonz

Chat With Our Team

Online
Tycoonz

Hi! I'm the Tycoonz Solutions assistant. Ask me about our services (blockchain, AI, cybersecurity, post-quantum crypto, web & mobile), our process, or industries we work with.

10:09 AM