Find notable cyber news and cases, enriched with sources, timelines, and signals.

Salesloft Drift Salesforce data exfiltration via OAuth token abuse

Data Leak
First reported
Last updated
Happening score
H score 95
4 unique sources, 10 articles

Summary

Hide ▲

Between August 8 and August 18, 2025, attackers used compromised OAuth tokens tied to Salesloft Drift to exfiltrate data from connected Salesforce customer instances, including records, credentials, AWS access keys, passwords, and Snowflake-related access tokens. Google Threat Intelligence Group attributed the activity to UNC6395 and said it affected hundreds of organizations, while Salesloft and Salesforce revoked tokens, removed Drift from AppExchange, and told customers to rotate credentials. On October 3, 2025, Scattered Lapsus$ Hunters opened a leak site to extort 39 companies, and later Salesforce said it would not negotiate or pay the ransom. Separate victim reporting from Stellantis, Cloudflare, Palo Alto Networks, and Zscaler confirmed related customer-data exposure.

Cases

Related Happenings

Moltbook wide-open database exposure

Data Leak
H score52 First: 22.04.2026 13:41 Last: 22.04.2026 13:41 Sources 1

About this happening: The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credentia...

Scattered Spider SMS phishing and SIM-swap crypto theft campaign

Campaign
H score53 First: 20.04.2026 16:33 Last: 20.04.2026 16:33 Sources 1

About this happening: The Scattered Spider campaign used SMS phishing and SIM swap attacks to steal employee credentials, hijack phone numbers, and take over email and virtual currency wa...

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
H score39 First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The W3LL phishing operation turned into a high-volume Microsoft 365 credential-theft campaign, exposing more than 17,000 victims worldwide to BEC risk. The kit use...

UNC6783 BPO compromise campaign targeting downstream companies

Campaign
H score65 First: 09.04.2026 00:46 Last: 09.04.2026 00:46 Sources 1

About this happening: UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...

Over a dozen companies data exposed after SaaS integration provider Snowflake breach

Data Leak
H score69 First: 07.04.2026 22:39 Last: 07.04.2026 22:39 Sources 1

About this happening: A stolen-token attack from a SaaS integration provider breach has led to data theft claims affecting over a dozen companies, creating immediate exposure and extortion risk...

Timeline

  1. 03.10.2025 17:16 3 articles · 9mo ago

    Scattered Lapsus$ Hunters launch Salesforce data leak site for 39 victims

    Campaign Scope Update

    Scattered Lapsus$ Hunters launched a new data leak site to extort 39 companies affected by Salesforce breaches, posting samples of data allegedly stolen from victims' Salesforce instances and warning them to contact the group before an October 10 deadline. Scattered Lapsus$ Hunters also added a separate demand that Salesforce pay a ransom to stop disclosure of roughly 1 billion records containing personal information.

    Show sources
  2. 22.09.2025 21:01 2 articles · 9mo ago

    Stellantis confirms customer data theft in ShinyHunters-linked breach

    Victim Impact Update

    Stellantis confirmed that attackers accessed a third-party service provider platform supporting its North American customer service operations and stole customer contact information, and ShinyHunters claimed responsibility for the breach and said it took over 18 million Salesforce records from Stellantis.

    Show sources
  3. 08.09.2025 23:17 1 articles · 10mo ago

    Mandiant traces Salesloft GitHub compromise and Drift token theft

    Technical Analysis Update

    Mandiant determined that Salesloft’s GitHub account was compromised as early as March, that UNC6395 downloaded data from multiple Salesloft repositories and conducted reconnaissance across the Salesloft and Drift environments between March and June, and that the actor later reached Drift’s AWS environment to steal OAuth tokens for customer integrations beyond Salesforce.

    Show sources
  4. 27.08.2025 22:05 3 articles · 10mo ago

    Google reports UNC6395 Salesforce data theft via Salesloft Drift

    Initial Disclosure

    Google said UNC6395 abused OAuth tokens tied to Salesloft Drift to carry out a widespread data theft campaign against numerous corporate Salesforce instances, exporting large volumes of data to harvest sensitive credentials such as AWS access keys (AKIA), passwords, and Snowflake-related access tokens. Google also said the actor searched stolen data for secrets that could be used to compromise victim environments and deleted query jobs to cover tracks, while advising affected organizations to treat Salesforce data as compromised, rotate credentials, review Salesforce Event Monitoring logs, and search for exposed secrets; Salesloft and Salesforce revoked active access and refresh tokens for the Drift application, removed the app from Salesforce AppExchange, and notified impacted organizations.

    Show sources
  5. 20.08.2025 03:00 1 articles · 11mo ago

    Salesloft issues Drift security advisory

    Initial Disclosure

    Salesloft said on August 20, 2025 that it identified a security issue in the Drift application, proactively revoked connections between Drift and Salesforce, and told administrators that the issue does not affect customers who do not integrate with Salesforce.

    Show sources