A story made the rounds recently that sounds like a workplace comedy sketch but is actually a security case study: a terminated employee kept remote control of the office speakers because the Bluetooth system was still linked to their personal Spotify account. Nobody thought to check it during offboarding. It's funny until you realize the same blind spot applies to Dropbox folders, RMM agents, and every OAuth-connected app your team has quietly authorized over the years.
Most small businesses handle offboarding with a mental checklist: disable email, collect the laptop, change the door code. That covers the obvious stuff. It almost never covers the sprawling web of third-party integrations, shared logins, and personal-device links that accumulate over months or years of employment. And attackers know it.
Why This Matters Right Now
According to The Hacker News, a recent roundup documented over 5,000 compromised Dropbox accounts and active OAuth traps being exploited in the wild — attackers specifically targeting old, forgotten account links that were never cleaned up. That's the exact mechanism behind the Spotify speaker story, just with higher stakes: instead of an ex-employee blasting music, it's an attacker pivoting through a stale OAuth grant into your file storage.
The risk isn't limited to consumer apps. According to The Hacker News, the U.S. has become the top target in an RMM phishing campaign spanning 46 countries. Remote monitoring and management tools are routinely provisioned for employees, contractors, and even former IT staff — and a forgotten RMM agent or leftover credential is precisely the kind of residual access this campaign is built to exploit. If your offboarding process doesn't include a full audit of remote access tools, you're leaving a door wide open, a problem we've also broken down in our guide to detecting unauthorized RMM agents.
Third-party services amplify the exposure further. According to Krebs on Security, the FBI is investigating a service tied to over 153 million exposed driver's licenses, traced back to an identity verification vendor with broad data access. It's a reminder that offboarding isn't just about internal systems — it's about every vendor, SaaS platform, and identity-adjacent service an employee touched during their tenure.
The Offboarding Checklist Most Companies Skip
Before an employee walks out the door, someone should be able to check off every item below — not just email and the badge:
- Identity and SSO: Disable the account in your identity provider first, which should cascade to connected apps. This is the backbone of proper identity threat detection — if you're not managing identity centrally, you're chasing individual apps one by one.
- OAuth and connected apps: Review the app authorization list in Google Workspace, Microsoft 365, and any SSO admin console. Revoke tokens for anything personal (Spotify, Canva, personal Google Drive) that got linked to a shared or company device.
- Cloud storage: Dropbox, Google Drive, OneDrive — remove the account and transfer file ownership, not just disable login.
- RMM and remote access tools: Deprovision the user in ScreenConnect, NinjaOne, TeamViewer, or whatever tool you run, and rotate any shared credentials they had access to.
- Shared and service accounts: If the employee ever had a shared login for a printer, scanner, or line-of-business app, rotate it. Shared credentials are a recurring blind spot, as we covered in our piece on shared credentials on printers and MFPs.
- VPN and firewall access: Remove VPN profiles and firewall rules tied to the individual.
- Password manager vaults: Revoke vault access and rotate any passwords they could view, especially admin-level entries.
- Physical and IoT access: Badge access, building Bluetooth/Wi-Fi devices, and yes — office speaker systems linked to personal streaming accounts.
- Privilege review: Confirm no lingering admin rights or elevated permissions remain on any system, a gap we detail in preventing employee privilege escalation.
Make It Repeatable, Not Ad Hoc
The root problem isn't laziness — it's that offboarding checklists rarely get updated as new tools get adopted. Every time you onboard a new SaaS app, add it to the offboarding checklist too. Assign one owner for the process, require a signoff, and run a quarterly audit of connected apps across your identity provider to catch anything that slipped through.
Take Action
A thorough offboarding checklist stops the obvious leaks, but the only way to know what's still exposed across your network, cloud apps, and remote access tools is to actually scan for it. Oscar Six Security's Radar finds unauthorized access, stale accounts, and exposed credentials before an attacker does — for just $99 a scan. Check out our solutions and see what's still lingering in your environment. Focus Forward. We've Got Your Six.