SaaS Extortion Groups Hide Inside IdP Access

The break is not in the apps. It is in the identity layer that feeds them. Once attackers steal IdP credentials through vishing and SSO-themed AiTM pages, they can move across multiple SaaS services with few app-level traces, so app-centric detection misses the real intrusion path. CrowdStrike attributes this pattern to Cordial Spider and Snarky Spider, active since at least October 2025. The groups are tied to rapid data theft and extortion campaigns that stay almost entirely inside trusted SaaS environments, which makes them hard to spot from normal SaaS logs alone. The forward risk is broader than one tenant or one vendor. If identity is the control plane, then telephony abuse and IdP telemetry become the main warning sources, and a stolen SSO session can expose several connected apps before defenders see a conventional breach signal.

Part of the PlainSec briefing for 2026-05-02

Sources