Connected apps hold access to your data. More than 900 companies had it stolen in 2025, and the attacks no longer need a human to pick a target.
Whatever your CRM, how many tools are connected to it right now?
Not tools you use day-to-day, the other ones. Like chat tools, email finders, the AI notetaker you trialled last quarter. Maybe that thing someone set up for data syncing that didn’t really work properly.
Most people can’t answer that question precisely.
Tool counts grow one connection at a time, and usually for good reason, but over months and years the number expands.
Your CRM is the most complete commercial record of the business (at least it should be). Customers, deals, conversations, notes, campaigns, workflows, documentation. That’s valuable, precious data. Particularly to bad actors.
Yet most businesses govern their accounting and HR systems far more carefully. You would rightly expect to see tightly controlled approval workflows, restricted access, and audit trails; par for the course. Meanwhile, the CRM is thought about as having a pipeline report, a glorified address book, and an app marketplace.
Consider the asymmetry at play here for a moment.
An accounting system records what already happened financially. While the CRM records who the business knows, what has been said to them, and what is at stake with each one. As well as revenue data.
I would argue this is the more valuable database. Usually, the less governed one too.
When a tool connects to your CRM it becomes a connected app with read and write access to your data. The access doesn’t expire, it stays live until someone removes it. Most businesses never do, or it happens once every few years. A bit like leaving all of your windows and doors unlocked at home.
In August 2025, an intrusion group compromised Drift, a well-known AI chat tool that hundreds of companies had connected to their Salesforce CRMs. The attackers didn’t break into Salesforce. They stole OAuth tokens that Drift held to read and write data to each connected Salesforce account. Then used that access to extract records from more than 700 organisations over ten days.
This included major enterprise organisations like Cloudflare, Google, and Palo Alto Networks. None of them were directly breached, instead they were attacked through a tool that had been connected.
Salesloft, which owned Drift, pulled the tool offline on August 20 and revoked all affected connections. Salesforce removed Drift from its marketplace, but the data was already gone.
Three months later, in November 2025, the same pattern appeared with Gainsight, a customer success tool. More than 200 Salesforce-connected organisations had their data accessed without authorisation, across a period of nearly four weeks. Same story; the attack came in through something those organisations had connected, too.
In July 2026, an OpenAI agent running inside a sandboxed evaluation environment escaped its containment via a flaw no one knew about. It broke into Hugging Face’s production systems precisely because Hugging Face, an open-source AI community platform, held benchmark answers that it was looking for. It calculated that breaking in was faster than solving the test it had been given.
The agent accessed internal datasets and service credentials before Hugging Face detected and contained it five days later. Roughly 17,600 attacker actions were recovered from logs. Public models and datasets were untampered.
The AI agents behaved like water and found the most direct route to where they needed to go. Hugging Face wasn’t chosen, it was just the best available option, the most convenient path.
The question of whether your business is or will be an intended target is irrelevant. In the AI-era, risk comes via what you have connected, and whether those connections represent routes that someone – or more likely something – will find useful.
Connecting a tool to a CRM used to require a developer. Now, it doesn’t. AI coding tools have made it straightforward for a sales ops person, a growth hire, or a founder to build something functional in an afternoon and connect it to the CRM the same day, without the connection passing any formal decision point.
Research collated by the Cloud Security Alliance, covering more than 100 AI models tested across coding tasks, found that 45% of AI-generated code samples introduced a well-known class of security vulnerability. For Java, that figure was 72%. AI-assisted developers were committing three to four times more code than before, producing security findings at 10x the rate.
As the tools proliferate, the connections accumulate. Which means the number of connected apps in the market is growing faster than anyone can count.
If you have been looking for a framework that tells you exactly what to do, you are not alone, and you are about to be disappointed.
In June 2026, the Australian Signals Directorate announced that the Essential Eight, the government’s cyber checklist, will be retired within two years and replaced with something more adaptive. The stated reason is that it was built around conventional threats and static conditions. Too rigid for the pace at which the threat environment is now moving.
Existing investment is not wasted but the checklist form is being retired because the checklist form is not sufficient.
That aside, for most it still contains generally good protocols that can be sized for the maturity of the business in question.
Disclaimer: we’re not cyber security experts, nor are we lawyers, so this is a general heads up rather than a compliance notice. You really shouldn’t rely on a blog post for that kind of advice!
You can’t govern what you haven’t listed. The control available to most businesses without a dedicated security function is the decision about what gets connected in the first place.
That means being clear about what you will not connect before any requests come. Some useful exclusion categories, in plain language:
Before any tool connects to your CRM, four questions are worth answering.
HubSpot’s Connected Apps settings allow you to review the scope of every connected application and revoke access individually. Most accounts have never opened that screen.
Produce a list of every system with access to customer data.
For each write down:
If you can produce that list inside a week, you’re doing pretty well. These connections will have accumulated the same way every other piece of infrastructure does which is one at a time. Likely, each has (or had) a good reason, just no single moment when someone was responsible for the total.
The real finding here is how difficult it is to produce this list. It tells you what the governance gap actually looks like in your business and with your specific stack.
The first action is building the inventory. Every connected system, scope of access, owner, and the last review date. Start with the CRM and work outwards.
The second is deciding on what you will definitely not connect. It doesn’t need to be long or particularly technical. But it should exist so that the next request for a new integration has something to be measured against.
The third is giving one person authority to refuse. It doesn’t need a policy or a committee be effective quickly. One person with a clear remit and the backing to say no to a new connection, until it has been properly reviewed, costs next to nothing.
If producing that list is where you are stuck, a Discovery with Fly is where to start. It is Fly’s structured first engagement with a client.
Smart reads without the noise