On this page

The New Data Breach Starts With a Login
9 min

The New Data Breach Starts With a Login

For years, people pictured a data breach like a scene from a movie: a hacker in a dark room, breaking through a company’s defenses and forcing their way into the network. That image belongs to an older era. The latest breach activity points to a sharper reality: attackers now walk through trusted access paths. They use valid credentials, stolen tokens, SaaS integrations, OAuth permissions, misconfigured cloud apps, and third-party connections that already have access to sensitive data.

The modern data breach starts with trust. And trust has become one of the softest targets in the enterprise.

April 2026 sent a clear signal. Breachsense tracked hundreds of companies claimed by ransomware and data-extortion groups during the month, across dozens of active groups and countries. Each individual claim still needs verification, but the broader pattern is clear: data theft and extortion are operating at industrial scale. The most important shift is the move from system disruption to data pressure. Classic ransomware locked systems and demanded payment for recovery. The newer model steals sensitive data, proves access, threatens publication, and turns the incident into a reputational, legal, and customer-trust crisis.

That difference changes the entire security playbook. Encryption creates downtime. Data theft creates leverage. A company can restore systems from backups and still face a major breach if customer records, employee data, source code, internal messages, CRM exports, or student information are already in the hands of an extortion group. Recovery matters, but prevention, detection, containment, legal response, customer communication, and external intelligence now matter just as much.

One of the clearest recent patterns is the movement of breaches into the SaaS layer. The Snowflake customer incidents connected to a third-party SaaS integration provider showed how attackers can use stolen authentication tokens from a connected provider to access customer environments. That is the modern breach pattern in one sentence: a trusted integration becomes the path to sensitive data.

This matters because most companies now run on SaaS. Customer data lives in Salesforce. Product data lives in Snowflake. Conversations live in Slack. Source code lives in GitHub. Support tickets live in Zendesk. Financial data, HR data, marketing data, analytics data, and legal documents all sit inside connected platforms. Every integration adds convenience, every permission adds reach, and every token adds a potential path. Attackers understand this architecture. They hunt for the connection point with the most access and the least visibility.

ShinyHunters became one of the visible names in recent reporting around ADT, Instructure, McGraw Hill, and other data-extortion activity. The pattern is consistent: find valuable data, steal it, publicize the claim, and create pressure. ADT confirmed unauthorized access to customer and prospective customer data after ShinyHunters threatened to leak stolen information. Instructure, the company behind Canvas, also confirmed stolen data after ShinyHunters claimed responsibility. McGraw Hill was tied to an April incident involving data connected to millions of accounts, with reporting pointing to a Salesforce-hosted environment and misconfiguration issues.

The lesson is clear. Attackers are building repeatable playbooks around SaaS access, identity, misconfiguration, and data extortion. Many groups now operate like criminal data brokers with a media strategy. They run leak sites, publish countdowns, share samples, contact victims, and create public pressure. The breach becomes both a technical event and a business crisis.

The uncomfortable truth is that many modern breaches look technically legitimate at first. A stolen OAuth token makes approved API calls. A compromised SSO session signs in successfully. An over-permissioned Salesforce profile returns data as configured. A third-party integration exports records using granted access. A service account queries a data warehouse within its assigned role. The activity looks normal because the environment allowed it.

This is the key shift. The old security boundary centered on the network. The new boundary centers on identity, permissions, sessions, tokens, SaaS configuration, and data movement. The core breach question used to be, “Who got into our network?” Now the better question is, “Who can access our data, through which app, with which token, from which location, for how long, and under whose approval?” Most companies need a stronger answer to that question.

The real risk comes from the pileup. Every company now has a sprawling SaaS estate: CRM, data warehouse, BI, email, documents, HR, finance, marketing automation, product analytics, support, dev tools, cloud storage, AI tools, security platforms, contractor systems, and internal automations. Each tool asks for access. Each integration promises productivity. Each approval feels small. Over time, those small approvals become a large attack surface.

A marketing tool can touch customer data. A BI connector can query production datasets. A support integration can access user conversations. A contractor account can reach sensitive workspaces. An AI tool can receive copied customer or company information. A long-lived token can outlast the employee, vendor, or project that created it. This is the modern enterprise reality: data moves through trust relationships faster than security teams can manually track.

That is where solutions like Lunar become especially relevant. Lunar is built for the reality that breach risk begins before a company receives an official notice, before a leak becomes public, and often before internal teams see a clear alert. By tracking stolen credentials, compromised assets, sensitive data exposure, and cybercriminal chatter across open, deep, and dark web sources, Lunar helps organizations detect early warning signs before they turn into full-blown incidents.

This external visibility matters because attackers rarely operate in silence. Credentials appear in infostealer logs. Corporate email addresses show up in breach corpuses. Threat actors discuss access, samples, vulnerabilities, and targets in criminal communities. Ransomware and extortion groups publish victim claims on leak sites. Sensitive data can surface in markets, paste sites, Telegram channels, and forums before legal, security, or customer teams have a complete picture. Lunar gives security and risk teams a way to connect those signals to real business exposure.

For example, if employee credentials tied to Salesforce, Snowflake, GitHub, or Google Workspace appear in infostealer data, the organization can act before those credentials become the entry point for a breach. If a threat actor starts discussing access to a company’s environment, Lunar can help surface that chatter early. If sensitive company data appears outside approved systems, Lunar can help identify the exposure and support a faster response. If a ransomware group claims a vendor or partner, Lunar can help teams assess whether that third-party incident creates downstream risk.

This is the direction security is moving: from waiting for alerts inside the environment to combining internal telemetry with external intelligence. Identity tells you who or what has access. Data movement tells you what that access is doing. External intelligence shows what attackers already know, what they have collected, and what they may be preparing to use. The strongest security programs connect all three.

Companies should treat identity and data movement as one connected control plane. A login alone gives partial context. A query alone gives partial context. An export alone gives partial context. The full picture comes from connecting identity, permissions, behavior, data sensitivity, and external exposure. A strong program can answer who accessed the data, whether the actor was a human, app, service account, vendor, or AI agent, what permissions made the access possible, whether the access matched the role, how much data moved, whether the destination was approved, and whether the same path could be used again tomorrow.

The practical response is to reduce invisible trust. Start with SaaS integrations and OAuth apps. Review Salesforce, Snowflake, Google Workspace, Microsoft 365, Slack, GitHub, Zendesk, HubSpot, Atlassian, Dropbox, BI tools, analytics tools, and AI platforms. Remove unused integrations, reduce scopes, assign owners, and review high-risk grants regularly. Treat tokens like powerful credentials. API keys, OAuth refresh tokens, service accounts, CI/CD secrets, warehouse credentials, and environment variables need ownership, rotation, expiration, least privilege, and monitoring.

Companies should also watch data movement with the same seriousness they apply to login security. Unusual exports, large queries, new destinations, abnormal API usage, access outside expected regions, and activity from dormant accounts or rarely used integrations all deserve attention. Salesforce and externally exposed SaaS surfaces deserve particular focus, including guest profiles, Experience Cloud sites, public pages, exposed APIs, connected apps, sharing rules, and excessive permissions. Vendors with sensitive access should be treated as part of the production attack surface, because their controls, tokens, employees, subcontractors, and integrations directly affect the company’s risk.

AI tools also belong in this governance model. AI apps and agents introduce new ways for sensitive data to leave controlled environments. They need data-use rules, logging, access limits, approved workflows, and clear ownership. As AI agents gain the ability to read, write, summarize, move, and act across business systems, they become another identity layer, and another data movement layer, that security teams need to understand.

For executives, the message is simple: your company’s sensitive data lives across a web of platforms, vendors, integrations, tokens, automated workflows, and external exposure points. Attackers have adapted to that structure. Security programs should adapt with the same urgency. The next breach may start with an old integration, an overpowered token, a misconfigured SaaS page, a compromised SSO account, a vendor connection, a leaked credential, or a service account with broad access.

The strongest companies will know where their data lives, who can access it, which systems can move it, what normal usage looks like, and where early warning signs are appearing outside their walls. That knowledge is now a competitive advantage.

The new data breach starts with a login. It looks like an API call. It looks like a Salesforce export. It looks like a Snowflake query. It looks like an OAuth app doing exactly what it was allowed to do. That is what makes this moment so important.

Security teams need to move beyond the old idea of defending a perimeter. The real mission is to govern trust: identities, tokens, apps, vendors, permissions, AI tools, data flows, and external signals. Modern attackers follow trust. Modern defenders need to map it, limit it, monitor it, and enrich it with intelligence from the places where breach risk first becomes visible.

That is where Lunar fits into the new security model. It helps teams see the breach signals forming outside the company, connect those signals to internal exposure, and act before stolen credentials, compromised assets, sensitive data leaks, or criminal chatter become tomorrow’s headline.

Ran Geva
Ran Geva rangeva
linkedin
Spread the news

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.