Obsidian Discovers Expansive Identity Security Risk Impacting HR Systems Used Widely By The Global 2000

The threat research team of SaaS security company Obsidian has found a potentially expansive identity security risk that involves the fintech startup Argyle, an integration service for verifying income and employment data. 

In February, Obsidian detected a risk for organizations who are linked to Argyle through integrations with HR Management (HRM) systems widely used by the Global 2000. Argyle’s service poses serious security implications to these organizations because it prompts their employees to input corporate identity credentials  through “permissioned payroll connections” into the Argyle platform – providing a pathway for unauthorized access and data compromise. 

Argyle collects data that is used by the mortgage, background check, personal lending and banking industries as well as the gig economy.

Based on what Obsidian is seeing in its customer environments, it has reason to believe that many companies are at risk of credential harvesting, session cookie leakage, unauthorized access to other systems, and even falling afoul of U.S. hacking laws. The patterns that Obsidian is seeing resemble common identity theft threats, such as those for initial access from an access broker such as Okta, or fully executed payroll theft after an account takeover. 

You can read the details here.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading