Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Altara secures $7 million to bridge the data gap slowing the natural sciences

Kaspersky Suspects Chinese Hackers Put Backdoor in Daemon Tools in ‘Broad’ Attack

India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    ElevenLabs lists BlackRock, Jamie Foxx and Longoria as new investors

    5 May 2026

    OpenAI host Cerebras is on track for a major IPO

    5 May 2026

    In Harvard study, AI provided more accurate emergency room diagnoses than two human doctors

    4 May 2026

    ‘That’s cool’ creator says AI startup stole his art

    4 May 2026

    OpenAI announces new advanced security for ChatGPT accounts, including a partnership with Yubico

    3 May 2026
  • Apps

    Meta will use artificial intelligence to analyze height and bone structure to detect whether users are underage

    5 May 2026

    Image AI models are now driving app development, surpassing chatbot upgrades

    5 May 2026

    5 days to get 50% off a second Disrupt 2026 pass

    4 May 2026

    The Jack Dorsey-backed Vine reboot goes public

    4 May 2026

    Google Photos uses artificial intelligence to make the iconic wardrobe from ‘Clueless’ a reality.

    3 May 2026
  • Crypto

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025
  • Fintech

    Stripe introduces Link, a digital wallet that autonomous AI agents can also use

    1 May 2026

    Y Combinator alum Skio sells for $105 million in cash, raised only $8 million, founder says

    1 May 2026

    Amazon, Meta join the fight to end Google Pay and PhonePe’s dominance in India

    30 April 2026

    Steve Ballmer slams founder he backed, who pleaded guilty to fraud: ‘I was cheated and I feel stupid’

    25 April 2026

    Salmon raises $100 million in equity and debt to bring digital credit to unbanked Filipinos

    24 April 2026
  • Hardware

    Altara secures $7 million to bridge the data gap slowing the natural sciences

    6 May 2026

    This tiny, magnetic e-reader could keep you from doomscrolling

    4 May 2026

    Apple surprised by AI-driven demand for Macs

    1 May 2026

    As Tim Cook departs, Apple hits record sales — but chip shortage looms

    1 May 2026

    More Gemini features are coming to Google TV

    30 April 2026
  • Media & Entertainment

    Netflix delays Greta Gerwig’s ‘Narnia’ for big theatrical push to 2027

    2 May 2026

    Roku’s $3 streaming service Howdy hits 1 million subscribers, per recent report

    29 April 2026

    Australia forces Big Tech companies to pay for news or face 2.25% tax.

    28 April 2026

    India’s app market is booming — but global platforms are raking in most of the profits

    23 April 2026

    YouTube extends its AI similarity detection technology to celebrities

    21 April 2026
  • Security

    Kaspersky Suspects Chinese Hackers Put Backdoor in Daemon Tools in ‘Broad’ Attack

    5 May 2026

    The US government is warning of a serious CopyFail bug affecting major versions of Linux

    5 May 2026

    Hackers are still exploiting the cPanel bug to gain control of thousands of websites

    4 May 2026

    Ubuntu services were affected by outages after the DDoS attack

    1 May 2026

    Dental software maker fixes bug that exposed patients’ medical records

    1 May 2026
  • Startups

    India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

    5 May 2026

    FDA Approval, Fundraising and the Reality of Building Healthcare According to BioticsAI Founder

    1 May 2026

    Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

    1 May 2026

    Bill Gurley, Jack Altman back startup Pursuit, which helps companies sell to the government

    30 April 2026

    BCI startup Neurable wants to license ‘mind reading’ technology to wearable consumer devices

    29 April 2026
  • Transportation

    Moment Energy raises $40M to meet ‘infinite energy demand’ with EV batteries

    5 May 2026

    Ouster’s new color lidar is coming to replace cameras

    4 May 2026

    TechCrunch Mobility: How do you ticket a robotaxi?

    4 May 2026

    Uber taps Hertz to clean, charge and fix Lucid Motors’ robotaxi

    3 May 2026

    Uber wants to turn its millions of drivers into a sensor network for self-driving companies

    2 May 2026
  • Venture

    Get 50% off a second Disrupt 2026 pass to bid more, faster

    5 May 2026

    Nicolas Sauvage bets on the boring parts of AI

    4 May 2026

    Musely secures $360 million from General Catalyst without giving up equity

    2 May 2026

    The climate tech IPO window could finally open

    30 April 2026

    Sources: Anthropic Could Raise New $50B Round at $900B Valuation

    30 April 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Employees at failed startups are at particular risk of personal data theft via old Google logins
Security

Employees at failed startups are at particular risk of personal data theft via old Google logins

techtost.comBy techtost.com19 January 202506 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Employees At Failed Startups Are At Particular Risk Of Personal
Share
Facebook Twitter LinkedIn Pinterest Email

As if losing your job when the startup you work for collapses isn’t bad enough, now a security researcher has found that workers at failed startups are at particular risk of having their data stolen. This ranges from their personal Slack messages to their Social Security numbers and possibly bank accounts.

The researcher who discovered the issue is Dylan Ayrey, co-founder and CEO of Andreessen Horowitz-backed startup Truffle Security. Ayrey is best known as the creator of the popular open source project TruffleHog, which helps monitor for data leaks in case bad guys get their hands on identity-binding tools (ie API keys, passwords, and tokens).

Ayrey is also a rising star in the bug hunting world. Last week on ShmooCon security conferencetalked about a flaw he found with Google OAuth, the technology behind Sign in with Google, which people can use instead of passwords.

Ayrey gave his talk after reporting the vulnerability to Google and other companies that could be affected, and was able to share the details because Google doesn’t ban its bug hunters from talking about their findings. (Google’s ten-year-old Project Zero, for example, often presents the flaws it finds in other tech giants’ products, such as Microsoft Windows.)

He discovered that if malicious hackers bought the damaged domains of a failed startup, they could use them to connect to cloud software configured to allow every employee in the company to access, such as a corporate chat or video application. From there, many of these apps offer company directories or user information pages where the hacker could discover the actual emails of former employees.

Armed with the domain and those emails, hackers could use the Sign in with Google option to access many of the startup’s cloud software applications, often finding more employee emails.

To test the flaw he found, Ayrey bought a failed startup domain and from it was able to connect to ChatGPT, Slack, Notion, Zoom, and an HR system that contained Social Security numbers.

“That’s probably the biggest threat,” Ayrey told TechCrunch, as data from an HR system in the cloud is “the easiest thing to monetize, and Social Security numbers and bank information and whatever else is out there in HR systems are likely to be “targeted. He said old Gmail accounts or Google Docs created by employees, or any data created with Google apps, are not at risk either. Google confirmed.

While any failed company with a domain for sale could fall victim, startup workers are especially vulnerable because startups tend to use Google apps and a lot of cloud software to run their businesses.

Ayrey estimates that tens of thousands of former employees are at risk, as well as millions of SaaS software accounts. This is based on his research that found 116,000 website domains currently being offered for sale by failed tech startups.

Prevention is available but not perfect

Google actually has technology in its OAuth configuration that should prevent the risks Ayrey describes if the SaaS cloud provider uses it. It’s called a “sub-id”, which is a series of numbers unique to each Google account. While an employee can have multiple email addresses linked to their work Google account, the account should only have one secondary ID.

If configured, when the employee goes to sign in to a cloud software account using OAuth, Google will send both the email address and secondary ID to identify the person. So, even if malicious hackers recreated email addresses with domain control, they should not be able to recreate these IDs.

But Ayrey, working with an affected SaaS HR provider, discovered that this ID “was unreliable,” as he put it, meaning the HR provider found it changed a very small percentage of the time: 0.04%. This may be statistically close to zero, but for an HR provider handling huge numbers of daily users, it adds up to hundreds of failed logins every week, locking users out of their accounts. That’s why this cloud provider didn’t want to use Google’s secondary identifier, Ayrey said.

Google disputes that the secondary identifier ever changes. As this finding came from the HR cloud provider, not the researcher, it was not submitted to Google as part of the bug report. Google says that if it ever sees evidence that the secondary identifier is untrusted, the company will address it.

Google changes its mind

But Google also commented on how important this issue was. At first, Google completely dismissed Ayrey’s bug, immediately closing the ticket and saying it wasn’t a bug but a matter of “fraud.” Google wasn’t entirely wrong. This risk comes from hackers controlling domains and abusing email accounts they recreate through them. Ayrey did not dispute Google’s initial decision, calling it a data privacy issue where Google’s OAuth software worked as it should, even though users could still be harmed. “It’s not that cut and dry,” he said.

But three months later, just after his talk was accepted by ShmooCon, Google changed its mind, reopened the ticket, and paid Ayrey a $1,337 bonus. Something similar happened to him in 2021, when Google reopened his ticket after he gave a wildly popular talk about his findings at the Black Hat cybersecurity conference. Google even awarded Ayrey and his bug-finding partner, Allison Donovan, their third Security Researcher of the Year award prizes (plus $73,331).

Google has yet to issue a technical fix for the flaw, nor a timeline for when it might — and it’s unclear if Google will ever make a technical change to somehow address this problem. However, the company has updated documentation to tell cloud providers to use the secondary ID. Google also offers instructions to founders on how companies should properly shut down Google Workspace and prevent the problem.

Ultimately, Google says, the solution is for founders who shut down a company to make sure they properly shut down all their cloud services. “We appreciate Dylan Ayrey’s help in identifying the risks of customers forgetting to delete third-party SaaS services as part of their decommissioning,” the spokesperson said.

Ayrey, a founder himself, understands why many founders may not have ensured their cloud services were turned off. Closing a company is actually a complicated process done during an emotionally painful time – involving many items, from disposing of employees’ computers, closing bank accounts and paying taxes.

“When the founder has to deal with shutting down the company, they’re probably not in a good position to think about all the things they need to think about,” Ayrey says.

data employees failed Google logins OAuth personal Risk startups theft
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFast-growing South African business FARO raises $6 million to source, refurbish and sell surplus clothing
Next Article TikTok is restoring service in the US
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Altara secures $7 million to bridge the data gap slowing the natural sciences

6 May 2026

Kaspersky Suspects Chinese Hackers Put Backdoor in Daemon Tools in ‘Broad’ Attack

5 May 2026

The US government is warning of a serious CopyFail bug affecting major versions of Linux

5 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Altara secures $7 million to bridge the data gap slowing the natural sciences

6 May 2026

Kaspersky Suspects Chinese Hackers Put Backdoor in Daemon Tools in ‘Broad’ Attack

5 May 2026

India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

5 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Stripe introduces Link, a digital wallet that autonomous AI agents can also use

1 May 2026

Y Combinator alum Skio sells for $105 million in cash, raised only $8 million, founder says

1 May 2026

Amazon, Meta join the fight to end Google Pay and PhonePe’s dominance in India

30 April 2026
Startups

India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

FDA Approval, Fundraising and the Reality of Building Healthcare According to BioticsAI Founder

Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.