Skip to content
jeffkom story logo
  • Home
  • About Us
  • Stories & Media
    • AI
    • Apple
    • META
    • Venture
    • Security
    • Fintech
    • Hardware
    • Google
    • Microsoft
    • Transportation
    • EVs
    • Instagram
    • Amazon
    • TikTok
    • Cloud Computing
  • News
  • Contact Us
Search
SIGN UP
jeffkom story logo
Search
  • Home
  • About Us
  • Stories & Media
  • News
  • Contact Us
  • Home
  • About Us
  • Stories & Media
  • News
  • Contact Us
SIGN UP

Employees of Failed Startups Face Risks of Data Theft Through Old Google Logins

  • By JeffkomStory Team
  • Published on January 20, 2025
Protect Failed Startups Employees from Data Theft Risks
Advertise with us

Introduction

Failed startups can leave employees exposed to a ton of data risks – stolen Social Security numbers, private messages, bank information, etc. according to Dylan Ayrey, a cybersecurity researcher and CEO of Truffle Security.

Ayrey revealed the vulnerability at ShmooCon, a security conference, after finding flaws in Google OAuth, the “Sign in with Google” feature. Malicious actors can exploit these flaws by buying domains of failed startups. With control of a domain, hackers can log into employee accounts across cloud-based platforms like Slack, ChatGPT, and HR systems using recreated email addresses.

How the Exploit Works

Hackers using defunct domains can log into cloud applications configured for company-wide access. Many apps provide directories or user profiles that allow further discovery of former employees’ data. By using the “Sign in with Google” option, attackers can log into additional SaaS services tied to the startup.

To prove the risk, Ayrey bought a defunct startup domain and was able to log into platforms with sensitive data including HR records with Social Security numbers. Google says Gmail accounts and Google Docs are not affected but employees using SaaS platforms are at risk.

Existing Safeguards and Limitations

Google’s OAuth has a “sub-identifier” to prevent this attack. This identifier is unique to each Google account and should prevent domain-based impersonation. But some SaaS providers don’t use it because of reported inconsistencies. Ayrey found one HR provider had a 0.04% sub-identifier mismatch rate which resulted to failed logins and operational issues. Google disputes this but has updated their documentation to encourage SaaS providers to use sub-identifiers.

Google’s Response and Next Steps

Google initially dismissed the vulnerability as a “fraud issue” then reopened Ayrey’s bug report and paid him a bounty. Google has not fixed the issue but updated their documentation on how to properly shut down Google Workspace and associated SaaS services.

Ayrey said startup founders are overwhelmed during closures and often miss securing their digital infrastructure leaving data exposed. He said “Shutting down a company is an emotionally taxing process, it’s easy to miss critical steps”.

Takeaway

The responsibility lies with both cloud service providers and company founders to mitigate the risk. Properly deactivating SaaS platforms and following Google’s recommendations can reduce the risk of data theft when a startup fails.

Advertise with us
PrevPreviousNew York VC Leader Insight Partners Secures $12.5B Fund
NextPresident Trump Repeals Biden’s AI Executive Order on First DayNext
Here are some related articles you may find interesting:
Self-Driving Car Duck Incident Sparks AV Safety Debate
Self-Driving Car Controversy in Texas: Duck Incident Sparks Debate on Autonomous Vehicles
The promise of safer roads and smarter transportation that comes with autonomous vehicles has always...
Chrome Vertical Tabs: Smarter Way to Manage Open Tabs
Chrome Introduces Vertical Tabs: A Smarter Way to Manage Too Many Open Tabs
Introduction Google Chrome’s been struggling to keep up with users having dozens of tabs open for...
Delve and Y Combinator Split Amid Startup Controversy
Delve and Y Combinator Part Ways: Inside the Startup Controversy Shaking the Compliance Industry
The compliance startup scene has been sent into a tailspin by the sudden fallout between Delve and Y...
Amazon Fuel Surcharge 2026: Impact on Sellers & E-commerce
Amazon Adds Fuel Surcharge as Iran War Disrupts Global Oil Markets
Introduction The global economy is once again feeling the ripple effects of geopolitical conflict. The...
Uber Acquires Blacklane to Expand Uber Elite Luxury Travel
Uber Acquires Blacklane to Expand Luxury Travel with Uber Elite Services
Uber is making a strategic move into the premium mobility segment by acquiring Berlin-based startup Blacklane....
Shield AI Hits $12.7B Valuation After Air Force Deal
Shield AI Hits $12.7B Valuation After Major U.S. Air Force Deal and $1.5B Funding Round
The Defense Tech Sector is really starting to heat up and Shield AI has just made a move that’s...
Modal Labs Eyes $2.5B Valuation in New AI Funding Round
AI Inference Startup Modal Labs in Talks to Raise at $2.5B Valuation
Modal Labs, an AI inference infrastructure startup, is reportedly in discussions with venture capital...
Amazon May Launch AI Content Licensing Marketplace
Amazon May Launch AI Content Marketplace for Media Publishers
Amazon may soon launch a new content marketplace. This platform would allow media companies to sell their...
Waymo Starts Driverless Robotaxi Testing in Nashville
Waymo Begins Driverless Robotaxi Testing in Nashville Ahead of 2026 Launch
Waymo has officially removed human safety drivers from its autonomous test vehicles in Nashville, marking...
a16z Warns Founders to Stop Chasing $100M ARR Hype
a16z Warns Founders: Don’t Chase Hype-Driven ARR, Build Durable Growth Instead
The AI startup boom has reignited a familiar Silicon Valley pattern: massive venture capital flowing...
Popular Posts
Self-Driving Car Duck Incident Sparks AV Safety Debate

Self-Driving Car Controversy in Texas: Duck Incident Sparks Debate on Autonomous Vehicles

JeffkomStory Team

The promise of safer roads

Chrome Vertical Tabs: Smarter Way to Manage Open Tabs

Chrome Introduces Vertical Tabs: A Smarter Way to Manage Too Many Open Tabs

JeffkomStory Team

Introduction Google Chrome’s been struggling

Delve and Y Combinator Split Amid Startup Controversy

Delve and Y Combinator Part Ways: Inside the Startup Controversy Shaking the Compliance Industry

JeffkomStory Team

The compliance startup scene has

Amazon Fuel Surcharge 2026: Impact on Sellers & E-commerce

Amazon Adds Fuel Surcharge as Iran War Disrupts Global Oil Markets

JeffkomStory Team

Introduction The global economy is

Join Our Newsletter

Start your day with impactful startup stories and concise news! All delivered in a quick five-minute read in your inbox.
Join Our Newsletter
Start your day with impactful startup stories and concise news! All delivered in a quick five-minute read in your inbox.
jeffkom story logo
Stories
  • AI
  • Start Up
  • Apps
  • Fintech
  • Ventures
  • EVs
  • Fundraising
COmpanies
  • Apple
  • Amazon
  • Google
  • Meta
  • Microsoft
  • Tik Tok
Pages
  • About Us
  • Stories & Media
  • News
  • Contact Us
Follow Us
X-twitter Facebook-f Instagram Linkedin-in Youtube

Become Premium Member Now

Subscribe @ $9.99 Per Month only
  • Privacy
  • Terms
© 2024 jeffkomstory. All Rights Reserved.
Join Our Newsletter
Start your day with impactful startup stories and concise news! All delivered in a quick five-minute read in your inbox.
Log in or create your account
Subtract
Subtract (Half Circle)
Unlock

Unlock expert knowledge

Startup Shadow
Process

Practical Steps

checked

Successful Business

GET YOUR ULTIMATE GUIDE

Kickstart your startup journey with our must-have ebook, “A Step-by-Step Guide to Registering Your Startup in the USA.”
Guidance

Comprehensive Guidance

Ellipse Circle
Resource Allocation

Essential Resources

Proven Strategies

Startup Shadow

GET YOUR ULTIMATE GUIDE

Kickstart your startup journey with our must-have ebook, “A Step-by-Step Guide to Registering Your Startup in the USA.”
Bokep Indonesia Bokep Jepang Jav Bokep jilbab SLOT GACOR SLOT GACOR bokep viral Bokep Tanpa VPN Bokep Indonesia