Critical Flaw in Google’s OAuth Risks Data of Millions From Defunct Startups

In a striking revelation that has sent shockwaves through the tech industry, a critical flaw in Google’s widely-utilized “Sign in with Google” OAuth authentication system has been identified. This vulnerability potentially exposes millions of user accounts to data theft, posing significant risks, particularly to individuals who previously worked for now-defunct startups. The flaw stems from the manner in which Google’s OAuth interacts with domain ownership, enabling malicious actors to exploit abandoned domains and gain unauthorized access to user accounts.

Vulnerability in the OAuth System

Exploiting Abandoned Domains

When users sign in using Google’s OAuth, Google sends third-party services a set of claims, including the user’s email address and a domain-specific identifier (hd claim). These claims are then used by services like Slack, Notion, and Zoom to authenticate users. However, if a startup goes out of business and its domain is subsequently purchased by an attacker, the new domain owner can recreate email accounts belonging to former employees and gain entry into various SaaS platforms. This breach can lead to exposure of highly sensitive information such as Social Security numbers, tax documents, and private messages.

The problem is further compounded by the high failure rate of tech startups, many of which use Google Workspace for their email services. When these companies shut down, their domains become prime targets for exploitation. Using data from Crunchbase, a security researcher estimated that upwards of 100,000 defunct domains are vulnerable, potentially impacting more than 10 million user accounts. This statistical risk underscores the urgency of addressing the flaw to prevent widespread data breaches.

The Inconsistency of the Sub Claim

Google’s OAuth system includes a unique user identifier known as the sub claim, designed to prevent the issue of unauthorized access. However, the sub claim’s inconsistent application renders it ineffective as a verification tool. Many platforms rely solely on email and domain claims for authentication. Since these claims remain valid regardless of ownership changes, this allows attackers to gain unauthorized access merely by controlling the domain.

The deficiency in reliable verification necessitates a more robust solution. The security researcher proposed an implementation of two immutable identifiers within Google’s OpenID Connect (OIDC) claims. One should be a unique user ID that remains consistent over time, and the other a unique workspace ID tied to the domain. This approach ensures that user authentication remains secure even if domain ownership changes. Google’s initial response dismissed the report as a non-OAuth vulnerability, but their stance shifted following the researcher’s presentation at ShmooCon. Acknowledging the issue, Google awarded a bounty and pledged to devise a fix. However, specific details and timelines for the solution remain undisclosed.

Potential Solutions and Recommendations

Steps for Third-Party Service Providers

Currently, third-party service providers face significant hurdles in mitigating this vulnerability without Google’s active intervention. One immediate recommendation for users is to exercise caution when using “Sign in with Google” for critical services. Encouraging startups to adopt more secure single sign-on (SSO) solutions strengthened by two-factor authentication (2FA) remains essential. These measures can provide an additional layer of security and restrict unauthorized access.

Service providers can also introduce additional verification steps to bolster security. For example, integrating SMS code verification or requiring credit card validation during password resets can mitigate the potential risks. Such enhanced verification procedures would make it considerably more challenging for malicious actors to exploit dormant domains, thus protecting sensitive user data.

Google’s Role and the Path Forward

In a startling revelation that has rocked the tech community, a significant flaw has been discovered in Google’s widely-used “Sign in with Google” OAuth authentication system. This vulnerability has the potential to expose millions of user accounts to data theft, posing severe risks, especially for individuals who were once associated with now-defunct startups. The issue arises from the way Google’s OAuth handles domain ownership, allowing malicious actors to exploit abandoned domains. These cybercriminals can then gain unauthorized access to user accounts, putting sensitive personal and professional data at risk. This flaw highlights the need for robust security measures and constant vigilance in managing domain ownership and authentication processes. As the tech industry grapples with this discovery, it underscores the critical importance of securing digital identities and the systems designed to protect them. The response from Google and other tech giants will be closely monitored as they work to mitigate the risks and strengthen their authentication frameworks.

Explore more

OLRB Clarifies Workplace Harassment Investigation Standards

Employers who fail to interview relevant witnesses identified in an initial complaint may find their entire harassment investigation invalidated by regulatory bodies for a lack of procedural thoroughness. This warning stems from a pivotal ruling by the Ontario Labour Relations Board, which recently clarified the murky legal requirements surrounding workplace harassment inquiries. Under the Occupational Health and Safety Act, employers

How Do We Secure the Modern SaaS Attack Surface?

Transitioning to an integrated governance model is essential for preventing security gaps that naturally occur between siloed detection and recovery systems in the cloud. The shift from on-premise infrastructure to these expansive cloud-centric models has fundamentally dissolved the traditional security perimeter that once defined corporate safety. As organizations now manage an average of 100 different software-as-a-service applications, the obsolete walled

NLRB Memo Signals Shift Toward Employer-Friendly Policies

A proposed return to traditional back-pay models would eliminate the Biden-era expansion of consequential damages for foreseeable financial harms in labor disputes. This directive, central to Memorandum GC 26-04 issued on August 26, 2026, by National Labor Relations Board General Counsel Crystal S. Carey, marks a profound pivot in the federal government’s approach to workplace regulation. As the American labor

Can the Middle East Withstand the Massive Surge in Ransomware?

Modern cyber-warfare in the Middle East is being defined by a transition toward high-pressure attacks on sectors that impact the general population. This shift marks a dramatic escalation in the regional threat landscape, where the Gulf states have moved from being secondary targets to the primary focus of global cyber-criminal organizations. Data from recent investigations reveals a staggering rise in

How Does the Iranian Chosen Brick Spyware Campaign Work?

The digital landscape of state-sponsored espionage has undergone a fundamental shift toward the weaponization of human psychology, as evidenced by the persistent Chosen Brick campaign. Orchestrated by the Iranian Ministry of Intelligence and Security, this operation has systematically targeted high-profile dissidents, journalists, and activists who live in exile across various Western nations. Since the middle of 2025, the campaign has