- By JeffkomStory Team
- Published on
Employees of Failed Startups Face Risks of Data Theft Through Old Google Logins
Introduction
Failed startups can leave employees exposed to a ton of data risks – stolen Social Security numbers, private messages, bank information, etc. according to Dylan Ayrey, a cybersecurity researcher and CEO of Truffle Security.
Ayrey revealed the vulnerability at ShmooCon, a security conference, after finding flaws in Google OAuth, the “Sign in with Google” feature. Malicious actors can exploit these flaws by buying domains of failed startups. With control of a domain, hackers can log into employee accounts across cloud-based platforms like Slack, ChatGPT, and HR systems using recreated email addresses.
How the Exploit Works
Hackers using defunct domains can log into cloud applications configured for company-wide access. Many apps provide directories or user profiles that allow further discovery of former employees’ data. By using the “Sign in with Google” option, attackers can log into additional SaaS services tied to the startup.
To prove the risk, Ayrey bought a defunct startup domain and was able to log into platforms with sensitive data including HR records with Social Security numbers. Google says Gmail accounts and Google Docs are not affected but employees using SaaS platforms are at risk.
Existing Safeguards and Limitations
Google’s OAuth has a “sub-identifier” to prevent this attack. This identifier is unique to each Google account and should prevent domain-based impersonation. But some SaaS providers don’t use it because of reported inconsistencies. Ayrey found one HR provider had a 0.04% sub-identifier mismatch rate which resulted to failed logins and operational issues. Google disputes this but has updated their documentation to encourage SaaS providers to use sub-identifiers.
Google’s Response and Next Steps
Google initially dismissed the vulnerability as a “fraud issue” then reopened Ayrey’s bug report and paid him a bounty. Google has not fixed the issue but updated their documentation on how to properly shut down Google Workspace and associated SaaS services.
Ayrey said startup founders are overwhelmed during closures and often miss securing their digital infrastructure leaving data exposed. He said “Shutting down a company is an emotionally taxing process, it’s easy to miss critical steps”.
Takeaway
The responsibility lies with both cloud service providers and company founders to mitigate the risk. Properly deactivating SaaS platforms and following Google’s recommendations can reduce the risk of data theft when a startup fails.
Here are some related articles you may find interesting:
Lucra Raises $20M Without the AI Hype: A Startup Success Story Worth Watching
In today’s startup ecosystem, adding “AI” to a pitch deck often feels like a requirement for attracting...
Patina Startup Is Reinventing the Fragrance Industry With AI-Powered Scent Technology
The fragrance industry has remained largely unchanged for decades. Traditional perfume and scent creation...
Waymo Expands Robotaxi Service Pause Amid Flooding and Safety Concerns
Waymo has expanded its robotaxi service pause to four major U.S. cities after several self-driving vehicles...
Quartermaster Raises $43M to Build a “Hive Mind” for Ships
Oceans are vast, and tracking activity on them has always been a challenge for governments, shipping...
How Google’s New AI Agents Are Transforming Search in 2026
Google is redefining the future of online search with the launch of its new AI agents, announced during...
Why Trust Is Becoming the Biggest Question in the Elon Musk vs OpenAI Trial
The ongoing legal battle between Elon Musk and Sam Altman has become more than just a courtroom dispute....
Malware Data Archives Are Bigger Than You Think: Comparing Cyber Threat Databases to the Eiffel Tower
The world of cybersecurity is growing faster than ever, and so are the massive databases used to track...
Parker Startup Files for Bankruptcy: What Went Wrong for the Fintech Company?
The fintech startup world continues to face major challenges in 2026, and one of the latest names making...
Tesla Model Y Becomes First Vehicle to Meet New US Driver Assistance Safety Benchmark
The 2026 Tesla Model Y has achieved a major milestone in automotive safety by becoming the first vehicle...
Nuro Secures Driverless Permit for Lucid Robotaxis Ahead of Uber’s 2026 Launch
The race toward fully autonomous transportation is accelerating. Nuro has taken a major step forward...
Popular Posts
Lucra Raises $20M Without the AI Hype: A Startup Success Story Worth Watching
JeffkomStory Team
In today’s startup ecosystem, adding

Patina Startup Is Reinventing the Fragrance Industry With AI-Powered Scent Technology
JeffkomStory Team
The fragrance industry has remained

Waymo Expands Robotaxi Service Pause Amid Flooding and Safety Concerns
JeffkomStory Team
Waymo has expanded its robotaxi

Quartermaster Raises $43M to Build a “Hive Mind” for Ships
JeffkomStory Team
Oceans are vast, and tracking
Join Our Newsletter
Start your day with impactful startup stories and concise news! All delivered in a quick five-minute read in your inbox.