How SSPM Could Have Prevented Three Recent Incidents
As Software as a Service (SaaS) security incidents surge, from token theft to data leakage and phishing attacks, organizations need SaaS Security Posture Management (SSPM) to detect misconfigurations, prevent unauthorized access, and reduce third-party integration risks. In this blog I will examine three cybersecurity incidents that occurred in 2025 and based on published information, I will explore how SSPM tools could have helped SaaS user organizations to reduce their impact or prevent them altogether.
Using SaaS applications has introduced new risks, many of which stem not from advanced malware or state-sponsored actors, but from poorly managed SaaS configurations, excessive permissions, and the absence of visibility. SSPM solutions do not replace good cyber security practices, however they do support their enforcement and provide visibility into weaknesses in their implementation.

Commvault Metallic & Microsoft 365 Secret Leakage
Incident Overview
According to the US CISA, in May 2025, attackers exploited a zero-day vulnerability (CVE-2025-3928) in Commvault’s web server, allowing attackers to extract OAuth tokens and client secrets used to access customer Microsoft 365 tenants via Commvault's SaaS backup offering, Metallic.
The breach originated from Commvault’s infrastructure, but the stolen credentials were used to access Microsoft 365 data from within the affected customer environments. This made the blast radius dependent on how the customers had configured M365 and governed their integrations.
How Customer-Side SSPM Could Have Helped
SSPM could not have blocked the original server-side vulnerability in Commvault’s infrastructure. It also would not detect token theft occurring within the Commvault environment (that would be Commvault’s responsibility). But once the stolen secrets were used against the customer’s own SaaS estate, SSPM becomes the last line of defense.
- SSPM provides visibility into third-party SaaS integrations. This includes backup providers like Metallic.
- It surfaces the scope of granted OAuth permissions and alerts if the scope is too broad or inconsistent with organizational policy. It tracks and analyzes API calls made using OAuth tokens (including those made on behalf of sanctioned apps) and detects suspicious behavior patterns.
- It also identifies Non-Human Identities (NHIs) with high privilege, orphaned apps (for example an app no longer managed by any admin), overprivileged apps relative to their actual activity and apps with excessive delegated permissions.
Zapier Code Repository Breach
Incident Overview
According to the Verge, in February 2025 an unauthorized user accessed internal Zapier code repositories containing debugging artifacts, some of which included sensitive customer data. Although core production systems were unaffected, the presence of regulated data in developer environments, and a lack of segmentation or Data Leak Prevention (DLP) controls presented a significant data exposure risk. This is an example where SSPM could detect and control insecure handling and storage of sensitive data within dev pipelines (CI/CD, version control, and SaaS-based code management tools).
How Customer-Side SSPM Could Have Helped
SSPM would not prevent Zapier’s own internal failure to segment its customer data from its dev environments, which is a vendor-side DevSecOps issue. However, if an organization were storing its own customer data in SaaS-based developer tools, SSPM could help catch that before a breach occurs.
- SSPM includes DLP capabilities that can help to prevent customer data from being stored in dev or test environments, even if accidentally included in debugging logs or payload samples.
- DLP can also identify and remove shadow data and data residues in places not covered by standard data governance controls.
- It provides visibility into which SaaS services are used by developers, including those that may not be officially sanctioned. It also scans the configurations of SaaS Dev apps like GitHub for lack of 2FA or SSO as well as for overprivileged accounts.
ShinyHunters & Salesforce Data Loader Phishing
Incident Overview
According to the FBI, since October 2024, threat actors from the group UNC6040 (ShinyHunters) have been executing a voice phishing (vishing) campaign impersonating internal IT support. They trick users into downloading and installing a “trojan” version of Salesforce Data Loader, a legitimate Salesforce tool used for mass importing and exporting CRM data. This malicious version gives attackers access to large volumes of sensitive data, including customer records and account information.
How Customer-Side SSPM Could Have Helped
SSPM cannot stop social engineering, particularly when attackers impersonate internal IT staff through phone calls or emails and convince users to take malicious actions (e.g., installing a compromised Data Loader). While the attack vector was social engineering, the damage was enabled by weak access controls and lack of oversight within the Salesforce environment. This is where SSPM can help.
- SSPM detection of abnormal data export activity. Even if the malicious data loader were installed, SSPM could have detected suspicious API behavior and triggered real-time alerts or automated responses (via SOAR).
- Control over SaaS administrative tools and permissions. This can help to prevent users from having unnecessary access to tools that can extract large datasets.
- Third-party tool and OAuth app risk governance can alert security teams if a new or modified version of data loader is used, especially one that deviates from normal behavior or permission scope.
- Policy-based restrictions for high-risk operations can force administrative oversight or MFA re-verification before mass exports.
Opinion
Each of these incidents illustrates a common problem: an absence of continuous, risk-aware oversight of SaaS configurations, identities, and data flows. SSPM bridges this gap by delivering cross-cloud policy enforcement, entitlement risk detection, data protection, app governance, and threat detection.
Organizations using SaaS applications for business purposes must ensure that these are deployed and used in a way that meets their cyber risk appetite and regulatory obligations. Organizations must set appropriate cyber-security policies around the use of SaaS and implement good cyber hygiene. SSPM solutions provide capabilities to measure and improve the achievement of these objectives across multi-cloud SaaS applications.
Our Buyers Compass SaaS Security Posture Management provides guidance to help organizations select the SSPM solution that is most appropriate for their use cases.
To explore best practices in SaaS and Cloud security, join us at Identity-Centric Cybersecurity Impact Day 2025 in Frankfurt November 6th, 2025.