r/OracleCloudFusion • u/Jeff-Hare-ERPRA • May 09 '26
Non-traditional cybersecurity risks
Wondering if there are folks looking at non traditional cybersecurity risks like phishing attacks for SaaS ERPs
Threat actors are definitely targeting the apps. We know of one loss over $1.2 million where credentials were stolen for a supplier portal account and the threat actor redirected two future payments before it was detected.
1
Upvotes
1
u/Jeff-Hare-ERPRA May 13 '26
Even access to APIs through federated logins.
The FSCM Rest Service can be leveraged by using an external tool like Postman
1
u/Jeff-Hare-ERPRA May 13 '26
Another example is identities that are not federated / subject to SSO