Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak Incident

Salesloft Drift OAuth abuse exposes Salesforce customer data

Updated 08.10.2025 03:17
Case score 56
Members 2 First seen 27.08.2025 12:39 Latest activity 08.10.2025 03:17

Overview

**Salesloft Drift** token abuse led to bulk exfiltration from connected **Salesforce** customer environments, with attackers pulling corporate records and credential material that could support follow-on compromise. **Zscaler** later disclosed a related Salesforce exposure through the same integration path, showing that the activity had already produced at least one separate victim environment and CRM data loss. Salesloft and Salesforce revoked active tokens, and affected organizations were told to review logs, rotate credentials, and treat exposed data as compromised.
Latest development Open development history 3 earlier developments Scattered Lapsus$ Hunters launch Salesforce data leak site for 39 victims Scattered Lapsus$ Hunters launched a new data leak site to extort 39 companies affected by Salesforce breaches, posting samples of data allegedly stolen from victims' Salesforce instances and warning them to contact the group before an October 10 deadline. Scattered Lapsus$ Hunters also added a separate demand that Salesforce pay a ransom to stop disclosure of roughly 1 billion records containing personal information.
  1. Earlier development

    Google reports UNC6395 Salesforce data theft via Salesloft Drift

    Google said UNC6395 abused OAuth tokens tied to Salesloft Drift to carry out a widespread data theft campaign against numerous corporate Salesforce instances, exporting large volumes of data to harvest sensitive credentials such as AWS access keys (AKIA), passwords, and Snowflake-related access tokens. Google also said the actor searched stolen data for secrets that could be used to compromise victim environments and deleted query jobs to cover tracks, while advising affected organizations to treat Salesforce data as compromised, rotate credentials, review Salesforce Event Monitoring logs, and search for exposed secrets; Salesloft and Salesforce revoked active access and refresh tokens for the Drift application, removed the app from Salesforce AppExchange, and notified impacted organizations.

  2. Earlier development

    Mandiant traces Salesloft GitHub compromise and Drift token theft

    Mandiant determined that Salesloft’s GitHub account was compromised as early as March, that UNC6395 downloaded data from multiple Salesloft repositories and conducted reconnaissance across the Salesloft and Drift environments between March and June, and that the actor later reached Drift’s AWS environment to steal OAuth tokens for customer integrations beyond Salesforce.

  3. Earlier development

    Salesloft issues Drift security advisory

    Salesloft said on August 20, 2025 that it identified a security issue in the Drift application, proactively revoked connections between Drift and Salesforce, and told administrators that the issue does not affect customers who do not integrate with Salesforce.

Signals

Impact signals
Affected impact
CVEs/products
Remediation
Status
Threat context
Data exposure

Threat actor context

22 listed

Malware & tooling context

2 families · 6 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Data Leak Salesloft Drift Salesforce data exfiltration via OAuth token abuse
Updated 27.08.2025 12:39 Lead Contribution 55
Data Type Passwords Data Status Partially Leaked

Between **August 8** and **August 18, 2025**, attackers used compromised **OAuth tokens** tied to **Salesloft Drift** to exfiltrate data from connected **Salesforce** customer instances, including records, credentials, **AWS access keys**, passwords, and **Snowflake-related access tokens**. **Google Threat Intelligence Group** attributed the activity to **UNC6395** and said it affected **hundreds of organizations**, while **Salesloft** and **Salesforce** revoked tokens, removed **Drift** from **AppExchange**, and told customers to rotate credentials. On **October 3, 2025**, **Scattered Lapsus$ Hunters** opened a leak site to extort **39 companies**, and later Salesforce said it would not negotiate or pay the ransom. Separate victim reporting from **Stellantis**, **Cloudflare**, **Palo Alto Networks**, and **Zscaler** confirmed related customer-data exposure.

Incident Zscaler hit by cyberattack
Updated 01.09.2025 20:00 Scoring Support Contribution 1
Extortion None Incident Disclosed Patch No Patch

**Zscaler** confirmed a **data breach** in its **Salesforce instance**, where unauthorized actors obtained customer information and some **support case content**. The exposed records included contact details, regional information, and product licensing data, creating **phishing** and **social-engineering** risk. Zscaler said the impact was limited to its Salesforce environment and that **no products, services, or infrastructure** were affected.