Kovrr reported that an affected company searched stolen data from an OAuth supply chain compromise, found 104 of its own API tokens inside it, and rotated all 104.
Public source
Publisher name
Public post
An attacker logged in with credentials that were working exactly as intended. August 2025. A third-party sales chat vendor held standing OAuth tokens for its customers.…
Company
Kovrr
Equipping enterprises to financially quantify cyber and AI-driven risk.
- Industry
- Data Security Software Products
- Location
- Tel Aviv, IL
- Company size
- 11–50 employees
About Kovrr
Kovrr is a leading provider of AI and cyber risk, security, and governance solutions, helping global organizations evaluate exposure, quantify potential business impact, and strengthen resilience with data-driven insights. The platform gives security, risk, and compliance teams the visibility and intelligence they need to manage risk continuously and at scale.
See moreLatest activity
Latest activity from Kovrr
4 signals
Operations & Supply
Kovrr reported that across 48 hours, 142,908 production customer rows left the warehouse.
Research & Knowledge
Kovrr ran agent telemetry in three parts over the past couple of weeks to provide a full report.
Products & Services
Kovrr introduced the AI Interaction Data Fabric to connect internal AI traffic, employee data, and policy outcomes into one account of what happened.
Discover more
Similar signals
Similar public activity from other companies.
Legal & Regulatory
ProvePrivacy
ProvePrivacy platform is built for the shrinking window of data protection and incident response, with the Manchester Airports Group breach following through on its threat this week.
Legal & Regulatory
Secure Blink
Secure Blink reported that McKesson confirmed a breach involving 1TB of patient data exfiltrated from Okta SSO credentials, Salesforce fully accessed, and Snowflake drained of bulk records, filed with the SEC on August 25, 2026, and has not responded to the ransom.
Legal & Regulatory
TorchLight
TorchLight disclosed that an attacker stole one of its model-provider API keys in March, added an SSH key for persistent access, and used the credentials for three weeks.
Legal & Regulatory
Freeze
Freeze reported that McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft following a vishing attack against employees at ShinyHunters.
Legal & Regulatory
Cyderes