Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

Whitepaper

The 2026 Supply-Chain OAuth Attack Playbook

Five breaches, one pattern. The mechanics behind the new lateral-movement vector and the controls that close it.

Five incidents, one TTP

From 2024 through 2026 the write-ups changed names and stayed mechanically rude: compromise a vendor that holds refresh tokens or long-lived connector creds, replay them against the customer's SaaS or IdP APIs. Drift did it to Salesforce. Connector platforms sat next to Snowflake tenants. Context.ai did it to Google Workspace via an extension. Gainsight-class customer-success tools sit in the same OAuth shape. Okta's 2023 support-case file theft is the cousin: tokens and session material in a support system, not a chat widget.

This playbook is the shared control set. It is not a claim that ScopeMantle was present in those tenants. It is not a count of our customers. Read the long-form breakdowns for Drift, Snowflake, and Context.ai if you need the hour-by-hour versions.

Pattern taxonomy

TypeExample classWhere the token livesRevoke target
AMartech to CRM (Drift)Vendor vault, Salesforce refreshConnected-app consumer key + IdP grant if any
BData connector (Snowflake wave)Keys and OAuth at the connectorWarehouse creds + IdP grants for the BI/ELT SaaS
CAI extension (Context.ai)Extension vendor backend, Google refreshGoogle / Okta client ID, plus Chrome extension ID
DCustomer-success SaaS (Gainsight-class)Vendor vault into CRM or supportSame as A, different brand
ESupport-system theft (Okta support cases)HAR files, session tokens, uploadsRotate everything in the case; treat support as a vault

Every type needs client-ID-level revoke at workforce scale. Brand-level "turn off Drift" misses sandboxes, agencies, and the rename after acquisition.

Prevent

  1. Chrome / Edge extension allow-list. Store installs are how Type C arrives.
  2. Consent-screen blocks for known-bad or unknown client IDs once you have inventory. CASB can help on the first hop only.
  3. Scope Sanity auto-revoke below forty, if leadership signed that policy. 48-hour attestation fast track so people do not flee to personal accounts.
  4. Procurement rule: anything that will hold a refresh token is a vendor, freemium or not.
  5. Block admin.directory.* without an approval ticket. That scope is org-wide blast radius.

Consent firewall / grant-time prevention is on our Roadmap. Until it ships, browser policy plus IdP app-access rules are the preventive controls you already own.

Detect

  1. Daily IdP grant sync (manual CSV if you must, ScopeMantle if you do not want rot).
  2. Alert on new vendor within 24 hours of first grant.
  3. Breach-feed / public-disclosure watch matched to client IDs you already have, not to news headlines alone.
  4. Optional event stream to SIEM. Splunk and Datadog connectors are GA. Elastic is Beta. Chronicle is Roadmap.
  5. Weekly digest to the security champion if you are not ready for SIEM use cases.

Respond

  1. Pre-built client-ID list in the IR binder. Update it monthly from inventory, not from memory.
  2. Named DRI for OAuth revoke, separate from SOC tier-one triage. War-room role, not a hope.
  3. Revoke by client ID across the workforce. Then communicate, unless you are still seeing exfil and need stealth for a few hours (counsel + CISO call).
  4. Parallel DSAR / processor notice if personal data was in scope. Operator templates, counsel send. DSAR playbook.
  5. Export before and after. Hash both. That pair is the CC9.2 packet.

Quarterly tabletop is the minimum I would sign. Semi-annual is what regulated teams often get away with and then regret. Use a fictional client ID so you are not revoking production for sport. Target: under four hours to workforce revoke once inventory exists.

Recover

  • Reset attestation on the category, not only the one vendor. People will install the cousin next week.
  • Board metric: unattested count down QoQ. Slide.
  • RoPA vs OAuth export within the month. Net-new grants become RoPA tickets.
  • Campaign calendar: no reconnect without review.

Controls mapped to the five types

Type A. Salesforce Connected Apps export plus IdP grants. Campaign-calendar gate. See Drift breakdown.

Type B. Warehouse MFA and network policy plus connector RACI plus IdP grants for BI/ELT. See Snowflake breakdown.

Type C. Chrome allow-list plus Google Admin third-party apps plus Scope Sanity on mail+Drive. See Context.ai breakdown.

Type D. Same as A. Success platforms OAuth into CRM and support. Treat them as production integrations, not "CS tools."

Type E. Support systems are vaults. Ban HAR uploads. Rotate any credential that hit a case file. This is process more than ScopeMantle. We will not pretend an IdP grant export fixes a support-tool leak.

What to tell an auditor

"We classify third-party OAuth as CC9.2. Here is inventory cadence, attestation expiry, last tabletop, last bulk-revoke drill, and the CASB limitation note." Do not claim a CASB module is IdP inventory without showing a grant export. Do not claim HIPAA. Do not claim we have a SOC 2 report on this site if you have not seen one. Entra is Beta.

How ScopeMantle fits

Read-only Google and Okta connectors. Score, govern, revoke, DSAR, optional SIEM. SCIM cascade revoke is Beta. HRIS deprovision is Roadmap. $5 / $6, no seat min, custom 500+, 30-day trial. Complementary to CASB, Vanta, and your IR retainer. Not a replacement for any of them.

Tabletop script (90 minutes)

  1. Inject: "Vendor V discloses token theft at 16:05 Friday. Client ID is on slide 2. Personal data possible in CRM objects."
  2. Revoke DRI finds the ID in the binder and in live inventory. Note the clock.
  3. Execute revoke in a test OU or against a fictional ID if you cannot touch prod. Narrate the prod clicks.
  4. Privacy starts the DSAR / notice fork. Counsel on the line or explicitly deferred.
  5. Comms drafts internal only. No tweet.
  6. Debrief: what file was missing, who was on PTO, whether Entra blindness mattered.

Record hours, not adjectives. "We did well" is not a metric. Store the notes next to the board export so Q4 has a resilience number.

Gainsight-class Type D tools get ignored because customer success is "not production." They OAuth into the same CRM Drift did. Put them on the Type A runbook and stop inventing a friendlier category. Okta-support Type E needs a separate policy on HAR files and screen shares. If your support vendor asks for a HAR, assume it contains session material and rotate after the case. That sentence has saved more than one team that never heard of supply-chain OAuth.

Read-only Google and Okta connectors. Score, govern, revoke, DSAR, optional SIEM. SCIM cascade revoke is Beta. HRIS deprovision is Roadmap. $5 / $6, no seat min, custom 500+, 30-day trial. Complementary to CASB, Vanta, and your IR retainer. Not a replacement for any of them.

Binder contents (print this once)

  1. Current grant export (Google, Okta; Entra if you accept Beta incompleteness).
  2. Client-ID list for Types A to D you actually use, updated monthly.
  3. Chrome extension allow-list export.
  4. Salesforce Connected Apps export if CRM is in play.
  5. Warehouse connector list if Type B is in play.
  6. DRI roster: revoke, comms, privacy, legal.
  7. Last tabletop notes and the before/after hashes.
  8. Link to operator DSAR templates, with the "not lawyer-reviewed" banner intact.

If the binder is a Notion page nobody opened in six months, it is not a binder. Put a calendar reminder on the monthly client-ID refresh. Threat-intel IOCs go in an appendix. They complement Breach History. They do not replace your own inventory.

RACI for the war room

RoleDoesDoes not
OAuth revoke DRIExecute client-ID revoke, confirm countsWrite the customer blog post
SOC leadTimeline, IOCs, laptop checksPretend CASB saw the refresh
PrivacyProcessor notice, DSAR spike planSend counsel-unreviewed letters
CommsInternal and external languagePromise certifications we do not hold

What to do this week

  1. Name the five types in your IR plan with a one-line revoke target each.
  2. Export Google and Okta grants. Build the client-ID binder.
  3. Schedule the quarterly tabletop on a real calendar.
  4. Turn on extension allow-list in one OU.
  5. Read the three breakdowns and the shadow OAuth guide.

What "prevent" looks like in a 400-person company

You do not need a consent firewall (Roadmap) to get through the next quarter. You need: extension allow-list in one OU, Admin app-access blocks for a short deny list of client IDs, a weekly new-grant email, and a named human who revokes orphans. That is a program. Add scoring when the email is too long to read. Add auto-revoke when leadership is tired of asking.

Type E (support-case theft) still sits outside that loop. Train people not to upload HAR files. Rotate after any live support session that saw an admin console. Put that in the IR plan even if you never buy ScopeMantle. We will not sell you a HAR scanner we do not have. Threat-intel IOCs go in the binder appendix. They complement Breach History. They do not replace the monthly client-ID refresh. If the Notion page has not been opened in six months, it is not a binder.

Field guide: building the binder in a week

Monday: Google and Okta exports. Tuesday: Chrome allow-list export and Salesforce Connected Apps if CRM matters. Wednesday: warehouse connector list if Type B matters. Thursday: DRI roster and last tabletop notes (or schedule one). Friday: client-ID list for tools you actually use, not a fantasy denylist of every brand in the news. Put a monthly reminder on the client-ID refresh. If nobody opened the page in six months, it is not a binder.

Type E HAR hygiene is a poster, not a SKU. Consent firewall is Roadmap. SCIM cascade is Beta. HRIS deprovision is Roadmap. $5 / $6, no seat min. Trial.

Name Types A through E in the IR plan with one revoke target each. Quarterly tabletop, hours not adjectives. HAR files are a poster. Consent firewall is Roadmap. Keep the binder monthly or admit you do not have a binder.

If you only remember one operational sentence: five types, one TTP, client-ID revoke, quarterly hours-to-contain, HAR hygiene on a poster. Prevention at consent is Roadmap. Inventory is today. The binder is a calendar reminder or it is fiction.

Print the RACI table from this playbook into the IR plan. If the revoke DRI is also writing the customer blog post, split the roles before the next disclose. Hours-to-revoke is the metric. Adjectives are not.

Update the client-ID binder within a week of any disclosure in your category, even if you were not hit. Reset attestation on the category, not only the one vendor. People install the cousin. Hours, not adjectives.

Related reading stays on the internal paths already linked above: platform, integrations, demo, and the companion resources or blog posts for this topic. Use those links when you brief a colleague so they get the same product truth: public $5 / $6 pricing, no seat minimum, custom at 500+, Entra labelled Beta, DSAR templates operator-reviewed, no HIPAA attestation, no invented logos. That is the briefing. Everything else is the procedure you can run this week.

FAQ

Common questions

About ScopeMantle

ScopeMantle is an OAuth-grant audit and DSAR-automation platform for mid-market SaaS companies, sold primarily through an open MSSP partner program (70/30 wholesale split, deal registration, no direct-sale conflict in partner territories) and secondarily direct. Built in 2026.

Explore the partner program →

70 / 30 wholesale · deal registration honoured · no direct-sale conflict

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.