Stop a legitimate or compromised identity from reaching too much data, for too long, without anyone noticing.
A data breach is not always an authentication failure. More often, an identity holds access that is valid but too powerful, too durable, insufficiently monitored, or used in an abnormal context.
Nobody can say which identities are able to read the most sensitive data.
Technical accounts and integrations hold broad, permanent access.
Entitlements pile up as people move roles and are never removed.
Tokens and API keys are long-lived with a vague scope.
Bulk data access triggers no signal at all.
Incident analysis stops at the entry vector and never looks at the rights used.
Start from what your identities can actually reach
Before discussing exfiltration, you need to answer a simple question: who, human or non-human, can read which data, and why does that right still exist?
Entitlement governance provides that visibility, makes it reviewable, and lets you remove what is no longer justified without blocking the business.
Perfectly legitimate access can turn into an exfiltration channel. We analyse real incidents to understand which IAM controls could have broken the attack chain or reduced its impact.
March – August 2025
Salesloft/Drift: when an OAuth token turns a SaaS integration into a front door
More than 700 organisations affected by stolen OAuth tokens tied to Drift integrations. A trusted application, a valid credential, and human authentication is no longer the relevant barrier.
Allianz Life: when a phone call is enough to get the attacker's app authorized
A legitimate, properly authenticated user is talked into authorizing a Connected App controlled by the attacker. From then on, the API calls look like those of an approved application.
Discord: when a third-party support identity opens the door to sensitive data
A support access used by an external provider was enough to reach Discord's customer support environment. Less a “Zendesk flaw” than a problem of governing third-party identities, their capabilities and their behaviour after authentication.
Jaguar Land Rover: when a cyberattack stops the production line
From 31 August 2025, a cyberattack led Jaguar Land Rover to shut down part of its IT estate. The immediate consequence: production and retail operations came to a halt. The initial access vector has not been publicly confirmed.
Real engagements whose approach sheds light on this situation.
Sector : Banking
Industrializing identity governance in a complex banking environment
A French banking organization set out to industrialize identity lifecycle management and strengthen access reviews through the deployment of an IGA platform.
Illustrates how entitlements are put back in order in a heavily regulated environment.