Rescana
Salesloft Drift OAuth Token Breach Exposes Salesforce Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms. The attackers harvested sensitive data, including plaintext AWS keys and VPN credentials, using automated Salesforce Object Query Language (SOQL) queries and bulk exports. The breach was detected on August 19, prompting immediate revocation of OAuth tokens and removal of the Drift integration from the AppExchange. While the immediate threat was contained, the stolen credentials pose a long-term risk. The incident highlights the vulnerabilities associated with over-permissive SaaS integrations and the need for stricter OAuth access controls. Organizations are advised to monitor for anomalous API behavior and review their integration security practices.
Key Points: • Over 700 organizations were affected by the breach involving Salesloft's Drift integration with Salesforce. • The attackers exploited stolen OAuth tokens to perform unauthorized data exports from Salesforce. • Immediate actions included revoking OAuth tokens and removing the Drift integration from the AppExchange.