Salesloft Drift OAuth Token Breach Exposes Salesforce Data

Salesloft Drift OAuth Token Breach Exposes Salesforce Data

First seen 21 Jun 2026, 08:48 UTC Rescanacloud.google.comwww.anomali.comarcticwolf.com 81% similarity 69.0

Article Content

Browse articles
ThreatCluster

Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms. The attackers harvested sensitive data, including plaintext AWS keys and VPN credentials, using automated Salesforce Object Query Language (SOQL) queries and bulk exports. The breach was detected on August 19, prompting immediate revocation of OAuth tokens and removal of the Drift integration from the AppExchange. While the immediate threat was contained, the stolen credentials pose a long-term risk. The incident highlights the vulnerabilities associated with over-permissive SaaS integrations and the need for stricter OAuth access controls. Organizations are advised to monitor for anomalous API behavior and review their integration security practices.

Key Points: • Over 700 organizations were affected by the breach involving Salesloft's Drift integration with Salesforce. • The attackers exploited stolen OAuth tokens to perform unauthorized data exports from Salesforce. • Immediate actions included revoking OAuth tokens and removing the Drift integration from the AppExchange.

ThreatCluster AI How this analysis works

Timeline

2025-08-09
Initial access gained via stolen OAuth tokens
UNC6395 exploited compromised OAuth tokens to access Salesforce APIs, enabling data theft.
Anomali
2025-08-17
Data theft campaign concluded
Attackers systematically exported sensitive data from Salesforce, focusing on credentials and support case information.
Anomali
2025-08-19
Breach detected and containment initiated
Salesloft detected the unauthorized access and revoked all Drift OAuth tokens to halt further exploitation.
Anomali
2026-06-19
Widespread data theft campaign reported
New reports confirmed ongoing data theft targeting organizations using Salesloft Drift, emphasizing the need for credential hygiene.
Rescana
2026-06-21
Google issues advisory on OAuth token compromise
Google alerted users about potential compromises of OAuth tokens connected to the Drift platform, advising immediate action.
Cloud Google

Community

Browse all →