Business
Business Security · Overview Executive Protection
Individual
Personal Protection · Overview Personal Credential Scan
Programs
Family Offices Wealth Firms Sports & Entertainment Agencies Reputation Threat Intelligence Wealth Manager Program Business Broker Program Partners
Intelligence
Research Library Threat Intelligence Global Breach Map Recent Breach Disclosures
Company
How It Works About Contact
Sign In
Reference · LeakTrace Intelligence Team

Departed employee retains SSO or SaaS access post-departure

A former employee's corporate SSO, individual SaaS accounts, or personal-device-linked corporate app access remains active after their departure date.

Pattern summary
Category
Insider threat
Severity
High
Prevalence framing
Common in firms without a formal offboarding checklist tied to the identity provider.
Remediation effort
Moderate
Verticals affected
All
Employee departure is a moment where identity hygiene routinely fails. HR closes the employment record; IT disables the primary SSO account; but the long tail of individual SaaS accounts, personal-device-linked apps, and cross-tenant integrations (Slack, project management, marketing platform, code hosting, e-sign) often survives for weeks or months. ## Why attackers exploit it A departed employee with retained access is either a direct insider risk (if the departure was contentious) or an inherited attack surface (if the departed employee's credentials later leak in an unrelated breach and the attacker discovers they still work). Either path leads to a compromise no active-employee monitoring will catch. ## Remediation direction A single offboarding checklist tied to the identity provider that enumerates every SaaS, every shared credential, every OAuth integration, and every personal-device-linked app — completed and signed off on departure day. Quarterly audit of the identity provider for accounts that have not been used in 60+ days.
Concerned this pattern touches your exposure surface?
LeakTrace runs continuous intelligence on principals, households, and advisor tenants across every observable public exposure surface. Discovery call under mutual NDA, first-touch reply within one business day from an authenticated LeakTrace address.
See services and pricing