Stolen OAuth Refresh Tokens Can Survive Password Resets, Leaving SaaS Accounts Exposed
In SaaS environments, attackers who steal OAuth refresh tokens can maintain persistent account access even after a victim resets their password, because many identity providers do not automatically revoke tokens on password change. Refresh tokens are long-lived credentials — valid for days or months — that allow an attacker to continuously generate new access tokens without ever re-entering a password. Common theft vectors include infostealer malware, misconfigured logging pipelines that capture authorization headers, and leaked CI/CD secrets. Security experts recommend that organizations pre-document revocation capabilities for each identity provider, shorten refresh token lifetimes, and enable rotation with reuse detection before an incident occurs. Stronger protections such as sender-constrained tokens (e.g., DPoP) can render stolen tokens useless by cryptographically binding them to a specific client key.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in