
Unosecur CEO Santhosh Jayaprakash says attackers target stale OAuth tokens and vendor integrations, not perimeter controls, citing Vercel and Snowflake breaches.
The most dangerous credential in an organization is often the one nobody remembers provisioning. That is the pattern behind a series of identity attacks in 2025 and 2026 that targeted trust relationships between companies, according to a Forbes article by Santhosh Jayaprakash, founder and CEO of identity security firm Unosecur.
Attackers have shifted strategy. Instead of breaking into a target directly, they now read the map of what the organization trusted and forgot to review: stale OAuth tokens, ownerless service accounts, vendor-held API keys with no expiry, Jayaprakash wrote.
The Vercel breach in February 2026 illustrates the pattern. According to a Trend Micro report cited by Jayaprakash, attackers compromised Context.ai, a small AI productivity tool used by a Vercel employee, by infecting the employee's device with Lumma Stealer malware and extracting the employee's Google Workspace OAuth tokens. Those tokens granted broad access to Vercel's internal systems. The breach went undetected for approximately two months before Vercel's own investigation surfaced it. Context.ai did not detect the compromise itself.
"Instead of attacking Vercel, they attacked what Vercel trusted," Jayaprakash wrote.
In April 2026, the group ShinyHunters claimed responsibility for extracting authentication tokens from Anodot, an analytics vendor, and using them to reach Snowflake environments across more than a dozen downstream companies. One compromised analytics vendor led to access to a dozen enterprises. The credential that opened those doors was not one that any of the victim organizations had issued.
A third campaign, the Salesloft Drift incident, reached 700 Salesforce customers across 10 days before tokens were revoked. The attackers ran bulk Salesforce API exports that matched exactly what Drift's integration did every day. Behavioral monitoring missed the intrusion because the attacker stayed inside the credential's normal profile.
"There was nothing to detect because there was no deviation. The attacker had simply become the credential," Jayaprakash wrote.
The pattern explains why multifactor authentication did not stop any of these campaigns. When OAuth tokens are lifted from a vendor's infrastructure, the authentication event has already occurred. The attack surface is post-authentication, he wrote. The controls that matter are what the credential is allowed to do after it gets through the login gate.
Jayaprakash traced the evolution of identity attacks from 2022, when stolen contractor VPN credentials and MFA fatigue breached Uber, to the 2023 compromise of Okta's support system, to the 2024 Snowflake campaign that reached approximately 165 organizations from infostealer-harvested logins. By 2025, attackers exploited vendor integrations through Salesloft Drift. In 2026, the vector moved to AI tooling and developer productivity software.
"Each year, the entry point moves one step further from the target," he wrote. "The credential that determines your exposure is increasingly becoming the one your vendor issued on your behalf to a system that trusts it unconditionally."
Most organizations have a reasonable inventory of the credentials they issued. Almost none have a complete map of the trust graph they participate in, Jayaprakash said. The gap between those two things is where these campaigns live. He wrote that every active integration needs one question answered: If this vendor's environment were compromised tomorrow, what would attackers reach in ours?
The Vercel breach ran undetected for two months. The Salesloft Drift campaign reached 700 Salesforce customers across 10 days before tokens were revoked.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.