Site navigation

SaaS Security Breaches Surge 300%

Elizabeth Greenberg

,

SaaS security
“The data is stark and unmistakable,” Glenn Chisholm, CPO of Obsidian Security, said. 

Software-as-a-Service (SaaS) security breaches have seen a 300% year-on-year surge from 2023 to 2024, new research from Obsidian Security shows.

The surge in attacks has impacted organisations across all sectors, including major technology and telecommunications companies like Microsoft and AT&T who experienced significant breaches during this period.

This dramatic surge comes as organisations increasingly rely on SaaS applications with current spend on SaaS in the hundreds of billions, or approximately $8,700 per employee for tools such as Workday, Google Workspace, ServiceNow, and Office 365.

Obsidian Security based their findings on their own repository of data from its direct involvement in over 150 incident responses alongside leading firms like GuidePoint and Kroll.

Analysts found that 99% of SaaS compromises originate at the identity provider (IdP), showing the critical importance of securing SaaS identities. Although IdPs help manage access, if they are compromised, attackers can gain lateral movement across entire systems, putting sensitive data at risk.

The report also found faults in classic security fail safes – multi-factor authentication (MFA) failed to prevent attacks in 84% of incident responses. The data shows that MFA alone is insufficient, bringing to light the need for more robust, layered security solutions to defend against modern threats.

Further, SaaS breaches are unfolding at an alarming speed, with the fastest time from initial access to data exfiltration recorded by Obsidian was just nine minutes. Traditional security controls often fail to respond quickly enough, increasing the risk of rapid data loss and necessitating real-time monitoring and response strategies.

“The data is stark and unmistakable; securing the identity and its dynamic relationship with services and applications should be the first task for every security team,” said Glenn Chisholm, CPO of Obsidian Security.

“Our unmatched dataset of real-life, real-time SaaS compromise telemetry, combined with our knowledge graph of identities across hundreds of large enterprises has allowed  Obsidian Security to build AI models with unmatched efficacy. These AI and LLM models continuously learn and adapt to catch attackers before they breach an organisation’s environment through SaaS.”

The report also highlighted critical emerging risks in SaaS environments that organisations need to prepare for.

For instance, the proliferation of third-party applications has created new attack vectors, with Microsoft integration abuse becoming increasingly prevalent.


Recommended reading


Further, the proliferation of AI applications only increases risk, as organisations typically deploy around 100 AI applications, with 60% lacking proper security controls or federation behind the IdP.

As unauthorised applications continue to connect to core environments, security risks continue to emerge as well.

With the average cost of a SaaS breach rising to $4.88 million, it is no wonder that cybersecurity budgets are set to soar. Still, security investment in this area continues to lag behind the rapid adoption of SaaS solutions.

This disparity creates an urgent need for organisations to reassess their security strategies and investments.

“In our breach response and intelligence work, we’re increasingly seeing that threat actors recognize the relatively vulnerable state of interconnected SaaS applications as fertile hunting grounds,” says Jim Hung, associate managing director, SPARK, Cyber Risk at Kroll.

“The quality of malicious tradecraft is improving to rapidly exploit identity and configuration weaknesses to the fullest.”

Elizabeth Greenberg

Staff Writer

Latest News

AI Infrastructure

Scottish Parliament Votes to Pause All AI Data Centre Applications

Cybersecurity Editor's Picks Security

Cyber Essentials Certifications Rise as SME Uptake Remains Limited

AI Editor's Picks Funding

Edinburgh Graduates’ AI Infrastructure Firm Expanse Raises $5.3m

Featured Finance

Fintech Summit 2026 Countdown Enters Final Three Weeks