Salesloft Drift OAuth abuse exposes Salesforce customer data
Case score 56
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 56
- Main story score
- 55
- Related evidence lift
- +1 / 20
- Contributing updates
- 1
- Context updates
- 0
- Data Leak Primary Salesloft Drift OAuth-token abuse event; bulk Salesforce exfiltration and credential harvesting define the core activity. main
- Incident Related Salesforce exposure through the same Salesloft Drift path; confirms downstream victim impact and support-case data loss. contributes
Overview
Latest development Open development history Scattered Lapsus$ Hunters launch Salesforce data leak site for 39 victims Scattered Lapsus$ Hunters launched a new data leak site to extort 39 companies affected by Salesforce breaches, posting samples of data allegedly stolen from victims' Salesforce instances and warning them to contact the group before an October 10 deadline. Scattered Lapsus$ Hunters also added a separate demand that Salesforce pay a ransom to stop disclosure of roughly 1 billion records containing personal information.
-
Google reports UNC6395 Salesforce data theft via Salesloft Drift
Google said UNC6395 abused OAuth tokens tied to Salesloft Drift to carry out a widespread data theft campaign against numerous corporate Salesforce instances, exporting large volumes of data to harvest sensitive credentials such as AWS access keys (AKIA), passwords, and Snowflake-related access tokens. Google also said the actor searched stolen data for secrets that could be used to compromise victim environments and deleted query jobs to cover tracks, while advising affected organizations to treat Salesforce data as compromised, rotate credentials, review Salesforce Event Monitoring logs, and search for exposed secrets; Salesloft and Salesforce revoked active access and refresh tokens for the Drift application, removed the app from Salesforce AppExchange, and notified impacted organizations.
-
Mandiant traces Salesloft GitHub compromise and Drift token theft
Mandiant determined that Salesloft’s GitHub account was compromised as early as March, that UNC6395 downloaded data from multiple Salesloft repositories and conducted reconnaissance across the Salesloft and Drift environments between March and June, and that the actor later reached Drift’s AWS environment to steal OAuth tokens for customer integrations beyond Salesforce.
-
Salesloft issues Drift security advisory
Salesloft said on August 20, 2025 that it identified a security issue in the Drift application, proactively revoked connections between Drift and Salesforce, and told administrators that the issue does not affect customers who do not integrate with Salesforce.