Connect with us

Hi, what are you looking for?

AI Cybersecurity

AI Agents Compromise 700+ Organizations’ SaaS Security with OAuth Tokens, Survey Reveals

AI agents exploited OAuth tokens in a breach affecting over 700 firms, revealing 91% operate without IT oversight, risking $670K in added breach costs.

Artificial intelligence agents are proliferating within enterprise SaaS environments more rapidly than security teams can monitor, leaving many organizations unaware of the extent of access they have inadvertently granted.

In August 2025, a security breach allowed attackers to infiltrate Salesforce environments at over 700 organizations, including notable firms like Cloudflare, Palo Alto Networks, and Zscaler. Remarkably, the breach did not involve exploiting any vulnerabilities or phishing attempts; instead, the attackers leveraged OAuth tokens from Drift, an AI-powered chatbot connected to Salesforce installations. Following a compromise of Salesloft’s internal systems, the stolen tokens transformed every downstream connection into a pathway for intrusion, mimicking normal software behavior from the system’s perspective.

This incident underscores a widespread governance issue regarding the integration of AI in enterprises. A survey conducted in March 2026 by security firm Vorlon revealed that 99.4% of 500 U.S. Chief Information Security Officers experienced at least one security incident related to SaaS or AI ecosystems in 2025. Only three organizations reported no incidents, yet 89.2% of the same CISOs expressed confidence in their OAuth governance, exposing a significant gap between perceived security and actual outcomes. The report emphasized that the issue is not one of awareness but rather a failure of architectural oversight.

Part of the challenge lies in the seemingly innocuous way AI is integrated into workflows. Employees often connect AI tools—such as writing assistants to email accounts or coding agents to repositories—viewing these choices as productivity enhancements rather than security risks. These access points are rarely subjected to formal review, allowing AI agents to begin operating immediately and without scrutiny.

“The most perilous dynamic here is that, unlike a dormant shadow IT application, an AI agent is perpetually active,” stated Gal Nakash, co-founder and Chief Product Officer at Reco, a SaaS and AI security platform. “It reads, writes, summarizes, and interacts—making the risk dynamic rather than static.”

Existing security tools have struggled to adapt to this evolving landscape. Cloud Access Security Brokers (CASBs) were designed for environments where the primary threat was unauthorized access by human employees, focusing on policy enforcement at the network layer and identifying behavioral anomalies typical of human actions. However, AI agents authenticate via OAuth tokens and API keys, allowing them to operate continuously across multiple systems, often without requiring users to log in repeatedly. This incongruity means traditional security measures may overlook an AI agent quietly amassing excessive access rights.

Nakash emphasized that a fundamentally different approach is necessary. Reco’s platform does not merely monitor the perimeter but instead maps both human and non-human identities within an organization’s SaaS ecosystem, setting behavioral baselines for each. When an AI agent interacts with systems or data outside its expected parameters, the platform flags these anomalies. “While CASBs monitor the front door, Reco observes what’s already inside,” he noted.

The findings from such monitoring can be surprising. Nakash highlighted a frequent scenario involving an AI meeting assistant that multiple employees had independently connected to their Microsoft 365 accounts. This assistant accumulated read access to the inboxes and calendars of over 40 personnel, including executives and legal team members. Although the tool itself was benign, the vendor’s data retention policy was unclear, resulting in a compliance exposure that went unnoticed until Reco’s mapping revealed the breach.

Once the security team identified the issue, remediation was straightforward: the overly broad OAuth grants were revoked, access was reconfigured under a restricted IT-managed setup, and an approval process was established to ensure future AI tool connections were subject to security reviews. “Within the first month, the firm reduced its exposure to third-party AI agents by over 60%,” Nakash explained.

As the integration of AI in enterprise applications accelerates, organizations face increasing risks. By the end of 2026, Gartner predicts that 40% of enterprise applications will incorporate task-specific AI agents, a significant rise from less than 5% today. Additionally, IBM’s 2025 Cost of a Data Breach Report indicated that organizations with high levels of shadow AI incurred an average of $670,000 more per breach compared to those without. Reco’s research further revealed that 91% of AI tools are currently being used without IT oversight or approval, highlighting a critical vulnerability in many organizations.

The AI agents operating within enterprise SaaS environments are not inherently malicious; they are performing as intended. The pressing issue is that in most organizations, there has been no clear designation of who is responsible for monitoring these agents, a decision that is now crucial as enterprises navigate a rapidly evolving digital landscape.

See also
Rachel Torres
Written By

At AIPressa, my work focuses on exploring the paradox of AI in cybersecurity: it's both our best defense and our greatest threat. I've closely followed how AI systems detect vulnerabilities in milliseconds while attackers simultaneously use them to create increasingly sophisticated malware. My approach: explaining technical complexities in an accessible way without losing the urgency of the topic. When I'm not researching the latest AI-driven threats, I'm probably testing security tools or reading about the next attack vector keeping CISOs awake at night.

You May Also Like

AI Cybersecurity

AI-related cyber threats surge, driving CrowdStrike and Palo Alto Networks stocks up 20%, as Anthropic and OpenAI launch new security innovations.

AI Business

Salesforce revenue jumps 83% to $22,000 as AI agents drive usage, while SaaStr ditches Notion amid rising reliance on AI-driven workflows

Top Stories

Meta's recent layoffs of thousands highlight how AI is reshaping the workforce, prompting Clara Shih to launch the New Work Foundation to guide Gen...

AI Business

Salesforce CEO Marc Benioff defies AI job fears by hiring 1,000 new grads and interns, aiming to boost AI development despite industry layoffs.

AI Tools

Federal IT leaders, guided by Salesforce's Mia Jordan, call for a unified platform to enhance efficiency and reduce human error, tackling 1,000 daily application...

AI Government

Palo Alto Networks CTO Lee Klarich warns that advanced AI could uncover zero-day vulnerabilities at scale, transforming cybersecurity defenses in just six months.

AI Tools

Axtria acquires Conexus Solutions to unify AI-driven CRM capabilities, enhancing life sciences customer engagement and operational efficiency.

AI Cybersecurity

Cybersecurity stock investments surge as breaches hit 10,747 in 2025, with top players like Palo Alto Networks and CrowdStrike leading the charge.

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.