SaaS & Technology Companies · Cybersecurity Training

SaaS Breaches Don't Start With Code — They Start With People

Okta, Snowflake, MOVEit, Bybit. Every major SaaS incident traces back to stolen credentials, a social-engineered support engineer, or an OAuth token nobody revoked. Live expert training that closes the human layer — and satisfies your SOC 2 auditor.

$4.88M Avg SaaS/tech sector breach cost (IBM 2024)
82% Of breaches involve a human element (Verizon DBIR 2024)
2,700+ Organizations hit via MOVEit supply-chain exploit (2023)

Defining incidents in the SaaS & tech threat landscape

Okta Support Breach — 2022 & 2023
Scattered Spider social-engineered support engineers
Two breaches in 18 months. Attackers impersonated IT staff to reset MFA for Okta support accounts, then used their privileged access to steal data on 5,000+ customers. Cloudflare, 1Password, BeyondTrust, and MGM Resorts were all downstream victims.
Snowflake Tenant Wave — Spring 2024
560M+ records via stolen credentials, no MFA
Infostealer-harvested credentials on contractor machines. No MFA on Snowflake tenants. 160+ enterprise customers exposed — Ticketmaster (560M records), AT&T (110M call records), Advance Auto Parts, Santander. Cl0p exploited the same credential-reuse gap.
MOVEit Transfer — May 2023
2,700+ orgs, 95M+ individuals — Cl0p ransomware
Cl0p exploited a zero-day SQL injection in Progress Software's MOVEit managed file transfer. No phishing needed — but the downstream impact was entirely preventable with vendor risk awareness and contract controls (SOC 2 CC9.2, HIPAA §164.314). BBC, BA, Boots, Shell, and US federal agencies exposed.
Bybit Exchange — February 2025
$1.46B stolen — largest crypto heist in history
Lazarus Group (North Korea) compromised Safe{Wallet} infrastructure and manipulated a multisig signing transaction. The Bybit signer approved what appeared to be a routine cold-wallet transfer — supply-chain social engineering on a privileged signing workflow. $1.46B in ETH transferred to Lazarus wallets in seconds.

Five vulnerabilities unique to the SaaS attack surface

SaaS and technology companies are prime targets not because their code is weak — but because their access sprawl, trust culture, and third-party integrations create attack paths that bypass every technical control. Here's where your exposure lives.

🔑

Stolen-Credential Reuse

Infostealer malware (Redline, Raccoon, Lumma) harvests credentials from developer machines, personal browsers, and contractor endpoints. Those credentials get tested against every SaaS tenant in your stack — Snowflake, GitHub, AWS, Jira — until they hit one without MFA. The 2024 Snowflake wave was credential reuse, nothing more.

📱

Missing MFA on SSO Admin Accounts

Admin accounts — Okta, Entra ID, Google Workspace Super Admin — are the skeleton key for your entire SaaS stack. MFA fatigue attacks (repeated push bombardment until the admin approves) and social engineering attacks (Scattered Spider's signature move) target these accounts specifically. One compromised SSO admin = your entire user directory.

🔗

Third-Party & Vendor Sprawl

The average SaaS company uses 130+ SaaS tools. Each integration is a potential pivot point. MOVEit, Okta, and SolarWinds SUNBURST all show the pattern: attackers compromise a vendor's system, then traverse to every downstream customer. Your vendor's breach is your breach — and your customers will hold you accountable for it.

🎭

OAuth Token Abuse

OAuth consent phishing tricks users into granting a malicious app persistent access to their Microsoft 365 or Google Workspace account — without entering a password or triggering MFA. The app then has access to email, files, and calendar until someone manually revokes it. Engineering teams who regularly authorize OAuth apps are desensitized to consent prompts and especially vulnerable.

📞

Support-Engineer Social Engineering

Scattered Spider's core technique: call your IT helpdesk or support team, impersonate a new employee or a contractor, and request MFA reset. Okta's 2022 and 2023 breaches were both executed this way. Support engineers are trained to be helpful — that culture becomes a vulnerability when the person on the line is a threat actor with LinkedIn-researched details about your company.

When it went wrong — and what it cost

Identity Platform · 2022 & 2023

Okta Support System Breaches

Two separate breaches in 18 months, both via social engineering of support engineers. In 2022, Scattered Spider compromised a third-party support contractor. In 2023, attackers used a stolen service account to access Okta's support case management tool. Downstream victims included Cloudflare, 1Password, BeyondTrust, and MGM Resorts ($100M+ impact). Okta's market cap dropped $2B+ following the 2023 disclosure.

$2B+ Market cap impact · 5,000+ customers exposed
Cloud Data · Spring 2024

Snowflake Credential Wave

Infostealer-harvested credentials used against 160+ Snowflake tenants with no MFA enforced. Ticketmaster (560M records), AT&T (110M call metadata records), Advance Auto Parts, Santander Bank, and LendingTree were among victims. A single control — mandatory MFA on all Snowflake tenant accounts — would have stopped every compromise. Mandiant attributed the campaign to threat actor UNC5537.

560M+ Records exposed · 160+ enterprise tenants
Supply Chain · May 2023

MOVEit / Progress Software

Cl0p ransomware group exploited a zero-day SQL injection in MOVEit Transfer. 2,700+ organizations affected — BBC, British Airways, Boots, Shell, US Department of Energy, TIAA, and government agencies across 8 countries. 95M+ individuals' data exposed. The breach required no phishing — but downstream risk was entirely preventable with vendor security questionnaire requirements and contractual controls.

2,700+ Organizations affected · 95M+ records
Crypto Platform · Feb 2025

Bybit $1.46B Cold-Wallet Heist

North Korea's Lazarus Group compromised Safe{Wallet} multisig infrastructure and injected a malicious smart contract into a transaction a Bybit signer approved. The signer saw a familiar interface — he was approving what he believed was a routine cold-wallet operation. In seconds, $1.46B in ETH was drained. Attribution confirmed by FBI (March 2025). The human-verification gap was the entire attack surface.

$1.46B Stolen · Largest crypto heist in history

The SaaS compliance stack — what your auditors and customers actually require

SOC 2, ISO 27001, and enterprise security questionnaires all have explicit requirements for security awareness training. Here's what applies and what's at stake.

SOC 2 CC6 & CC7 — Logical Access & Incident Response

SOC 2 CC6.1 requires logical access controls, which auditors routinely support with evidence of security awareness training for all users who handle production systems. CC7.2 (monitoring for anomalies) pairs with CC2.2 (communicating security requirements). Auditors expect training completion records as supporting documentation — missing them triggers exceptions.

Type II opinion risk without training records

ISO 27001:2022 — A.6.3 & A.5.10

ISO 27001:2022 Annex A.6.3 (information security awareness, education, and training) requires organizations to ensure all personnel receive appropriate awareness training. A.5.10 (acceptable use of information and other assets) requires documented policies and evidence of training. Certification auditors will request training completion records as objective evidence during Stage 2 audit.

Certification blocked without documented training

Customer Security Questionnaires (SIG, CAIQ)

Enterprise deals now routinely include SIG (H domain: Human Resources) or CSA CAIQ (GRC-06, HRS-09.02) questionnaires that ask directly about security awareness training frequency, content, and documentation. A 'no' or 'partial' on training questions delays deals and triggers remediation requirements. SecurEveryone provides completion certificates that answer these questionnaire items with a clean 'yes.'

Deal delays + remediation requirements

State Breach Notification Laws

SaaS companies typically process personal data for customers across all 50 US states. California (CPRA), New York (SHIELD Act), Texas, and 47 other states have breach notification laws that trigger when personal data is accessed without authorization. A breach caused by inadequate security training — the pattern in Okta, Snowflake, and MOVEit — exposes the company to notification obligations in every state where affected individuals reside.

50-state notification · AG enforcement risk

Three drills your SaaS team needs — built for actual SaaS workflows

Generic phishing simulation doesn't address the specific attack patterns targeting SaaS companies. These three drills cover the Okta-style support attack, MFA bypass at scale, and the OAuth consent phishing that bypasses your identity platform entirely.

Drill 1 · IT Support & Security Teams
📞

Okta-Style Support Social-Engineering Drill

Walk your IT helpdesk and support engineers through the exact Scattered Spider technique — impersonation calls from "new employees" or "contractors" requesting MFA reset, with LinkedIn-researched organizational details to establish credibility. This is the kill chain that brought down Okta, MGM Resorts, and Caesars Entertainment.

  • Identity verification protocol before any MFA reset
  • Recognizing social engineering pressure tactics on calls
  • Out-of-band confirmation via HR or manager (not the caller)
  • Documentation requirements for all helpdesk MFA exceptions
  • How to escalate a suspected social-engineering attempt in real time
Drill 2 · Engineering & Admin Teams
📱

MFA Bypass & Push-Fatigue Tabletop

MFA push bombing — sending repeated authentication requests until a tired admin approves one — is documented in Uber, Cisco, and dozens of SaaS breaches. This tabletop covers push-fatigue recognition, phishing-resistant MFA options (hardware keys, passkeys), and the procedures to follow if an admin accidentally approves a fraudulent push request.

  • How push bombing works and why tired engineers approve
  • Phishing-resistant MFA: FIDO2, passkeys, hardware tokens
  • Emergency procedure if an MFA approval was unauthorized
  • Conditional access policies that reduce push-bombing exposure
  • Number matching and additional context in authenticator apps
Drill 3 · Engineering & Product Teams
🎭

OAuth Consent Phishing Simulation

OAuth consent phishing targets engineers who routinely authorize new apps — making them the highest-risk group. This drill covers illicit consent grant attacks against Microsoft 365 and Google Workspace, recognition of suspicious OAuth permission scopes, and the process for auditing and revoking unauthorized app consents across your organization.

  • Recognizing suspicious OAuth permission scopes (mail.read, files.readwrite.all)
  • Why OAuth consent phishing bypasses MFA entirely
  • Entra ID / Google Workspace admin controls to restrict consent
  • Quarterly OAuth app audit procedure for your tenant
  • Incident response if a malicious OAuth app was already consented

Free playbooks and tools for SaaS security teams

These free resources cover the specific attack patterns and compliance requirements SaaS and tech companies face. Download them and put them to work today.

One price. Unlimited sessions.

No per-seat licensing. No annual contracts. Book a session, train your engineering team, satisfy your SOC 2 auditor.

Individual Contributor — IC
$150
Per person, per session. 60-minute personalized session for engineers, product managers, and individual security-sensitive roles.
  • 60-minute expert coaching
  • OAuth consent phishing recognition drill
  • Credential hygiene & MFA best practices
  • SOC 2 CC6 training completion certificate
Train Your ICs →
Executive & Org-Wide
$900
Unlimited users, per session. Org-wide training with custom tabletop exercises and board/investor briefing materials.
  • 120-minute org-wide session
  • All 3 drills + executive threat briefing
  • SOC 2 + ISO 27001 documentation package
  • Customer questionnaire (SIG/CAIQ) evidence kit
  • 30-day coaching access for follow-up questions
Get an Org-Wide Assessment →

Questions from SaaS security teams

Does SOC 2 require cybersecurity awareness training for SaaS companies?

Yes. SOC 2 Trust Service Criteria CC1.4 and CC2.2 require organizations to communicate security expectations to personnel, and CC6.1 requires logical access controls that include training on recognizing social engineering. Auditors commonly ask for evidence of security awareness training — completion records, training materials, and attestation from employees — as supporting documentation for CC6.1 and CC6.2 (logical access provisioning). SaaS companies that lack documented training risk a qualified opinion or exceptions on their Type II report. SecurEveryone provides a training completion certificate you can include in your SOC 2 evidence package.

How did the Snowflake / Ticketmaster breach happen, and what could have stopped it?

The 2024 Snowflake-linked breach affecting Ticketmaster (560M+ records), AT&T, and over 160 other tenants was caused by stolen credentials — specifically, infostealer malware on contractor machines that harvested Snowflake credentials. Snowflake itself was not breached; the attackers used valid usernames and passwords with no MFA to authenticate. The single control that would have stopped every compromise: mandatory MFA on all Snowflake tenant accounts. This is exactly the kind of human-layer failure our MFA Rollout Playbook and phishing-resistance training prevent — attackers stole credentials via phishing/stealer malware, then used them on a platform that didn't enforce MFA.

What is OAuth consent phishing and how does it threaten SaaS engineering teams?

OAuth consent phishing (also called 'illicit consent grant') tricks a user into authorizing a malicious third-party application access to their Microsoft 365 or Google Workspace account via a legitimate OAuth flow. Because the victim never enters their password on a fake page — they click 'Allow' on an OAuth permissions screen — it bypasses MFA entirely. The malicious app then has persistent access to email, files, and calendar. Engineering and admin teams are especially vulnerable because they regularly authorize new OAuth apps for legitimate development work and are less suspicious of consent prompts. Microsoft DART and Google TAG have both documented active campaigns targeting SaaS companies via this vector.

How do customer security questionnaires (SIG, CAIQ) apply to our team's training obligations?

The Standardized Information Gathering (SIG) questionnaire (domain H — Human Resources) and the Cloud Security Alliance CAIQ (GRC-06, HRS-09) both ask directly whether employees receive security awareness training, how often, and whether training completion is documented. Enterprise customers increasingly require SIG or CAIQ responses as part of vendor qualification — a 'no' on training documentation can block a deal or trigger a remediation requirement. The fastest path to a clean 'yes': documented live training sessions with completion records per employee. This is exactly what SecurEveryone provides, and it satisfies both the SIG H domain and CAIQ HRS-09.02.

What is the Bybit $1.46B breach and why does it matter for SaaS security teams?

In February 2025, Bybit suffered the largest cryptocurrency theft in history — $1.46B in ETH stolen via a social engineering attack that compromised a Safe{Wallet} cold-wallet signer. Attackers (attributed to North Korea's Lazarus Group) compromised the Safe multisig infrastructure and manipulated the transaction a Bybit signer was approving, substituting a malicious contract at the last second. The signer saw a familiar-looking interface and approved a transaction they believed was routine. The lesson for SaaS security teams: supply-chain social engineering can compromise the software your team uses to authorize critical operations. Reviewing deployment pipelines, signing authorities, and any third-party infrastructure used for privileged operations is essential — and training signers to verify out-of-band is the human layer that the Bybit team lacked.

What's the difference between SecurEveryone training and a phishing simulation platform?

Phishing simulation platforms (KnowBe4, Proofpoint Security Awareness) send fake phishing emails and track click rates. That's useful for awareness metrics, but it doesn't build the judgment to handle a live BEC attempt, an OAuth consent phishing flow, or a Scattered Spider-style helpdesk call. SecurEveryone training is live, interactive, and expert-led — your team works through real-world SaaS attack scenarios with a human expert who can answer 'but what if they said X?' in real time. Simulation platforms give you click data. SecurEveryone gives your team the mental models to make good decisions under pressure. Most SaaS companies benefit from both — simulation for ongoing reinforcement, live training for the playbooks that actually stop the hardest attacks.

Free Download

Got enterprise customers with a SIG or CAIQ questionnaire backlog?

The Vendor Questionnaire Response Library has 80+ pre-written, audit-ready answers across 12 security domains. Includes a SIG Lite/Core → CAIQ v4 crosswalk and a Red-Flag Guide for answers that trigger extra scrutiny. Free PDF + editable DOCX.

Download Free — PDF + DOCX →
80+
Pre-written responses
12
Security domains
PDF+DOCX
Free download

Your engineering team is your strongest security control — or your biggest liability

Book a live session today. Sessions are 60–120 minutes, held over Zoom, and built around your team's actual SaaS stack — Okta, GitHub, AWS, Snowflake, Slack. Walk away with SOC 2 evidence, a vendor risk checklist, and a team that knows what Scattered Spider looks like in the wild.

SecurEveryone · SOC 2 CC6/CC7 / ISO 27001 A.6.3 / SIG & CAIQ · $150–$900 · Live expert coaching