SpyCloud is an organization tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
SpyCloud is a organization tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 14, 2026; most recent activity June 21, 2026.
Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…
On January 14, 2026, SpyCloud announced the launch of its Supply Chain Threat Protection solution, designed to enhance identity threat protection across vendor ecosystems. This solution provides organizations with…
SpyCloud is an organization tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning SpyCloud on ThreatCluster is dated June 21, 2026. Activity was first observed January 14, 2026, giving a tracked span from then to June 21, 2026.
Across ThreatCluster reporting, SpyCloud most frequently co-occurs with Data Breach, Supply Chain Attack, Drift, Cloudflare, Google, among 12 tracked related entities.
The most significant recent cluster is “Salesloft Drift OAuth Token Breach Exposes Salesforce Data” (3 articles · Updated June 21, 2026). SpyCloud appears across 2 threat clusters in total, listed above with sources.
SpyCloud appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.