Skip to content
BreachPathAttack Path LibraryStart
IntermediateAccount takeoverData theft

SaaS administrator compromise

A phished SaaS administrator identity is used to weaken tenant security settings, establish persistence via integrations, and access or export the customer and business data the platform holds.

Technologies
SaaS (generic), Google Workspace, Microsoft 365
Entry points
Phishing, Stolen credentials
Sectors
SaaS & technology, Professional services, Retail
Stages
3
01

A SaaS administrator identity is compromised

The attacker targets an administrator with a convincing sign-in lure or uses reused credentials, obtaining an identity that controls tenant-wide settings and data.

Attacker objective

Obtain access to an account with administrative rights over the SaaS tenant.

Controls that should stop this
  • Phishing-resistant MFA required for administrative roles
  • Dedicated admin accounts separate from day-to-day identities
  • IP or device restrictions on administrative access
What defenders should see
  • Admin sign-ins from new locations or devices
  • Risky sign-in alerts on privileged accounts
  • Administrative logins outside normal hours
What a pentest validates
  • Phishing assessment focused on privileged users
  • Test MFA strength and admin-account separation
  • Review conditional restrictions on admin access
Business impact

The attacker holds tenant-wide administrative control.

02

Security is weakened and persistence is established

The attacker relaxes security settings, adds an OAuth integration or API token, or provisions an additional admin identity, so their access persists even if the original account is remediated.

Attacker objective

Reduce defences and secure durable access that survives a password reset.

Controls that should stop this
  • Alerting on security-setting and MFA-policy changes
  • Restrict and review third-party app and API-token grants
  • Approval and alerting on new administrator provisioning
What defenders should see
  • Changes to security policies or MFA enforcement
  • New OAuth grants, API tokens or admin accounts
  • Configuration changes from a recently risky session
What a pentest validates
  • Test detection of security-setting downgrades
  • Enumerate existing integrations and token grants for over-privilege
  • Validate that response revokes tokens and extra admins, not just passwords
Business impact

The attacker's access is now durable and the tenant's defences are degraded.

03

Customer and business data is accessed and exported

Using administrative capability, the attacker accesses records across the tenant and uses built-in export or API features to remove data in bulk.

Attacker objective

Reach and export the data the platform holds.

Controls that should stop this
  • Rate limits and alerting on bulk export and API data pulls
  • Field-level access controls and data minimisation
  • Audit logging with retention and monitoring
What defenders should see
  • Large export jobs or high-volume API reads
  • Access to records across many customers or datasets
  • Export activity outside normal operational patterns
What a pentest validates
  • Test whether admin access enables undetected bulk export
  • Validate alerting on export and high-volume API use
  • Confirm audit logs capture administrative data access
Business impact

The platform's data is exported — a breach affecting the organisation and, potentially, its own customers.

ATT&CK techniques in this chain

If this chain completes

Administrative control of a business-critical SaaS platform, allowing weakened security, durable persistence and bulk export of the data the organisation relies on that platform to hold.

Should you test this against your environment?

Turn this chain into a scoped red-team brief — objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.