Desk live·
ForensicPost
Cloud/Method/File 25-1207

An OAuth Grant Persists Until Somebody Removes It

An OAuth grant persists until somebody removes it. Across this database, the operation that establishes durable access is trivial and the operation that removes it requires a person to notice.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetSaaS authorisations
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

This file records a pattern the 2025 campaign made unavoidable: durable authorisations accumulate, and almost nothing in an enterprise removes them.

The Asymmetry Is Consistent Across The Corpus

An OAuth grant at 25-0806 is created by one click and lives until revoked. An enrolled MFA device at 25-0813 survives a password reset. API tokens sat in support tickets at 25-0826. Machine keys stolen at 25-0723 worked after patching. Integration tokens reached 700 environments at 25-0818.

In each case the credential outlived the circumstance that justified it, and the removal step required somebody to decide it was time.

There Is No Expiry Pressure

Passwords expire because policy forces it. Certificates expire because the protocol does. Long-lived application authorisations have neither: no policy engine tracks them, no protocol retires them, and nothing breaks if they persist.

The failure mode of leaving one in place is invisible. The failure mode of removing one is an integration breaking during business hours, traceable to whoever removed it. Every incentive points the same way.

Which Makes The Inventory The Actual Control

You cannot revoke what you have not enumerated. An organisation that cannot list its connected applications, its enrolled factors and its service tokens has no remediation available after any of these incidents — the position at 25-0723, where the corpus could not establish what proportion of affected organisations completed key rotation.

This is unglamorous, cheap relative to most security spending, and repeatedly absent. Graded medium: it is an argument from the pattern across these files rather than a measured finding, and this desk has found no published data on revocation rates.

This is a method file

It generalises from the incident files in this database, supported by the vendor guidance listed below. No revocation-rate data exists that we could find. Corrections: corrections@forensicpost.com.

Sources
  1. Defending SaaS-based applications against ShinyHunters OAuth abuseMicrosoft Security
  2. ShinyHunters threat actor profile: TTPs, IoCs and attacksHuntress
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary