Obsidian Security released its inaugural 2025 SaaS Security Threat Report, reporting a staggering 300% increase in SaaS breaches from September 2023 to 2024. This trend poses significant risks for organizations relying heavily on SaaS applications, which now average a spend of about $8,700 per employee for tools like Workday and Office 365.

The report indicated that 99% of SaaS compromises stem from weaknesses at the identity provider (IdP). Despite the implementation of multifactor authentication (MFA), audits showed it failed to prevent breaches in 84% of attacks, highlighting the need for more robust security measures. Furthermore, incidents unfolded alarmingly fast, with data often exfiltrated within minutes of initial access.

“The data is stark and unmistakable; securing the identity and its dynamic relationship with services and applications should be the first task for every security team,” stated Glenn Chisholm, CPO of Obsidian Security. This emphasis on identity security is crucial as the average cost of a SaaS breach has now reached $4.88 million.

Emerging threats documented in the report include vulnerabilities through SaaS integration and inadequate security for AI applications. Jim Hung, Associate Managing Director at Kroll, noted that threat actors are increasingly exploiting the vulnerabilities in interconnected SaaS environments.

Organizations are encouraged to revisit their security strategies to close the gap between rapidly expanding SaaS application use and current security measures.