© Mapbox, © OpenStreetMap

Speaker

Damien Miller-McAndrews

Damien Miller-McAndrews

SaaS Threat Researcher @ Obsidian Security

Edmonton, Canada

Actions

Damien is as a Threat Researcher at Obsidian Security where he specializes in SaaS security & ITDR. He publishes original research on his blog, cybercorner.tech, and contributes to open source DFIR and CTI projects. In his free time you can find him spending time with his flock of birds, making art, or getting into trouble on the internet.

Area of Expertise

  • Information & Communications Technology

Topics

  • cybersecurity
  • cyber threat intellience
  • Cyber Threat Intelligence
  • Digital Forensic
  • Incident Response
  • digital forensics
  • SaaS security
  • Cybersecurity and Cybercrime
  • Microsoft 365
  • okta

Advanced SaaS Threats: Case Studies from the Field

An increasing reliance on SaaS does not always come with the knowledge or motivation needed to secure these services. As businesses move away from on-premise systems, SaaS platforms are increasingly used for business-critical purposes, storing vital, sensitive company information. Organizations continue to underestimate SaaS breach risk, prioritizing ransomware defense while leaving critical SaaS exposures unaddressed.

But attackers have noticed, and they’re exploiting this blind spot.

Through a number of real-world case studies, including incidents involving Scattered Spider helpdesk takeovers, Salesforce-connected app compromises, malicious OAuth abuse, and a million-dollar BEC, we’ll dissect each campaign from initial access to root cause.

Attendees will see how these intrusions unfolded across platforms, threat actor groups, and techniques mapped to MITRE ATT&CK. Each case illustrates that SaaS is no longer a peripheral threat vector. It’s an attacker’s playground. You’ll leave with a better understanding of how these breaches occur, what defenders can learn from them, and practical steps to defend against the next wave of SaaS-native attacks.

Clicker and Mic appreciated. The longer the session the more studies I can put in/the deeper into the studies I can go.

ATT&CKcon 6.0

Leveraging ATT&CK to Fortify Detections for Scattered Spider and Other Advanced Threats

October 2025 McLean, Virginia, United States

BSides Toronto 2025

Caught in a Web: Exploring a Scattered Spider Attack from a SaaS Perspective

October 2025 Toronto, Canada

Antisyphon Training IR Summit

Shorter version of my talk from Edmonton and Calgary BSides
https://www.youtube.com/watch?v=jMqtkFckpqQ

August 2025

BSides Calgary 2023

The Million Dollar CEO Fraud: Anatomy of a Business Email Compromise
https://youtu.be/NlCoACTso_g

November 2023 Calgary, Canada

BSides Edmonton 2023

The Million Dollar CEO Fraud: Anatomy of a Business Email Compromise

September 2023 Edmonton, Canada

Damien Miller-McAndrews

SaaS Threat Researcher @ Obsidian Security

Edmonton, Canada

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top