Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Dissecting the Salesloft Drift Breach
Published: Loading… | Updated: Loading…
At a Glance
- The August 2025 Salesloft Drift breach demonstrates the cascading risks of compromised OAuth tokens in integrated SaaS platforms.
- Attackers accessed hundreds of enterprise systems, exfiltrating sensitive CRM data and cloud credentials.
- The incident underscores the need for robust token management, least-privilege access, and proactive monitoring to defend against supply-chain attacks.
Summary
Overview
In August 2025, a major cyberattack targeted Salesloft Drift, the chatbot and sales engagement service acquired by Salesloft in 2024 and integrated with Salesforce, Slack, Google Workspace, and other enterprise systems. Attackers exploited compromised OAuth tokens to gain unauthorised access to customer environments, exfiltrating sensitive data such as AWS access keys, Snowflake tokens, CRM records, and support case content.
Later investigations revealed that attackers had compromised Salesloft’s GitHub account between March and June 2025, enabling reconnaissance and preparation for the Drift token exfiltration.
More than 700 organisations were affected, including Cloudflare, Zscaler, Palo Alto Networks, PagerDuty, SpyCloud, Google, and Tanium. This incident highlights the risks of trusted SaaS integrations becoming entry points for widespread supply-chain compromise.
Salesforce and Other Integrated Systems: Central Targets
Salesforce served as the primary focus of the attack, acting as a central Customer Relationship Management (CRM) hub containing:
- Customer names, email addresses, and phone numbers
- Sales pipelines, opportunities, and forecast data
- Support tickets, case notes, and attachments
- Potentially embedded credentials within support cases
Compromise of Salesforce data provided attackers with sensitive information and in some cases exposed secrets enabling further system access. Beyond Salesforce, stolen tokens also granted access to Google Workspace (“Drift Email”), Slack, AWS, and cloud storage platforms.
How Integrations Amplify Risk
Integrations enhance productivity by automating workflows such as:
- Pushing leads directly into Salesforce
- Syncing email, calendar, and communications
- Delivering notifications to collaboration platforms
These functions rely on OAuth tokens, which authorise third-party apps to act on behalf of users or organisations. Drift’s integration required broad read/write access to multiple Salesforce objects and other connected services.
While enabling seamless automation, these broad scopes created a single point of failure—once tokens were compromised, attackers inherited trusted access without further authentication.
Breach Mechanics: OAuth Token Compromise
Mandiant confirmed that UNC6395 (aka GRUB1) first accessed Salesloft’s GitHub repositories months earlier, where they added a guest user, established workflows, and performed reconnaissance. Although no evidence of deeper exploitation of Salesloft itself was found, this activity set the stage for the August OAuth token theft from Drift’s AWS environment.
The threat group UNC6395 infiltrated Drift’s environment between 8 and 18 August 2025, exfiltrating stored OAuth tokens. They used these tokens to:
- Systematically query Salesforce environments
- Perform reconnaissance by counting records and mapping structures
- Execute bulk data exports, including CRM data and embedded credentials
- Access a small number of Gmail accounts via the Drift Email integration
- Harvest AWS, Snowflake, and other cloud service keys stored in support case content
The attackers used Python automation with asynchronous libraries (aiohttp) and Salesforce’s Bulk API for rapid exfiltration. They attempted to conceal activity by deleting query jobs, though Salesforce event logs later revealed their actions.
Operational and Industry Impact
On 20 August 2025, Salesloft revoked all active Drift tokens in coordination with Salesforce and removed Drift from the Salesforce marketplace. The chatbot was taken offline, and all integrations were suspended.
On 28 August 2025, Google’s Threat Intelligence Group confirmed that the compromise extended beyond Salesforce, affecting Gmail, Slack, and cloud storage integrations.
On 7 September 2025, Salesforce restored the Salesloft integration following containment and validation by Mandiant that Drift and Salesloft environments were properly segmented.
Salesloft engaged Mandiant and Coalition for incident response. Observers warn that stolen credentials are likely to be used for targeted phishing, credential stuffing, and further supply-chain attacks.
Key Factors in Breach Escalation
Several technical and operational weaknesses combined to magnify the impact of the Drift compromise.
- Broad OAuth scopes: Overly permissive integrations enabled wide access across customer systems.
- Centralised token storage: Drift stored large volumes of tokens in one place, creating a single point of failure.
- Customer convenience: Organisations granted minimal restrictions to enable seamless automation.
- Cross-platform exposure: Salesforce, Google Workspace, Slack, and cloud storage services were all impacted.
- Delayed detection: The breach persisted for ten days before discovery, reflecting weak real-time monitoring.
Confirmed Victim Disclosures
Multiple high-profile organisations have publicly acknowledged exposure of data through the Drift integration.
- Zscaler: Large volumes of customer records, including support case details, were exposed.
- Cloudflare: 104 internal API tokens were identified and rotated after discovery in support case notes.
- Palo Alto Networks: Exposure of Salesforce CRM records and sensitive case content.
- PagerDuty: Customer names, emails, and phone numbers accessed.
- SpyCloud: Salesforce data compromised despite Drift no longer being active.
- Google: A small number of Gmail accounts accessed via Drift Email on 9 August.
- Tanium: Limited Salesforce data exposed; no impact to core platform.
- Proofpoint: Confirmed Salesforce data exposure through the Drift integration.
- Tenable: Customer information compromised within Salesforce instances.
- BeyondTrust: Salesforce support-related records accessed.
- Bugcrowd: Exposure of customer data linked to case management.
- CyberArk: Confirmed limited Salesforce data impact.
- Cato Networks: CRM records accessed via the integration.
- JFrog: Salesforce data exposure through support case content.
- Rubrik: Confirmed Salesforce CRM compromise.
- Elastic: A single email account compromised via the Drift Email integration.
- Esker, Heap, Megaport, Nutanix, Sigma Computing, Workiva: Customer support ticket data exposed, including names, email addresses, and phone numbers.
Recommendations for Affected Organisations
Organisations using the Drift integration should act swiftly to contain exposure and mitigate further risk.
- Revoke and rotate tokens: Invalidate all Drift-related credentials across Salesforce, Google Workspace, Slack, AWS, and other platforms.
- Audit logs: Review Salesforce Event Monitoring, login history, and API logs for suspicious access between 8–18 August 2025.
- Check for exposed secrets: Search exported case data for embedded API keys or cloud credentials.
- Enforce least privilege: Restrict OAuth scopes and apply IP restrictions where supported.
- Strengthen monitoring: Enable real-time anomaly detection for third-party integrations.
- Prepare for follow-on attacks: Expect phishing and credential abuse targeting exposed organisations.
- Review GitHub and other code repository access logs: Attackers may target source control systems for long-term reconnaissance.
Lessons Learned
The Salesloft Drift breach underscores the cascading risks of SaaS supply-chain compromise:
- Excessive OAuth permissions: Dramatically increase exposure; integrations must request the least possible scope.
- Centralised token storage: Requires encryption, logging, and continuous monitoring to prevent silent abuse.
- System dependency mapping: Organisations must maintain a clear map of integrations to enable rapid containment.
- Proactive anomaly detection: Monitoring SOQL queries, API patterns, and unusual IP activity is essential to catch abuse early.
- Source control compromise: GitHub (or similar) can act as an early staging ground, highlighting the need for strict repository access control, audit logging, and monitoring of unusual user additions or workflow changes.
Conclusion
This incident illustrates the growing fragility of interconnected SaaS ecosystems. The breach proves that SaaS supply-chain attacks are not theoretical. Even widely trusted integrations can become high-value targets if token governance, access scoping, and cross-platform visibility are inadequate. Organisations must reassess how they manage third-party OAuth access and ensure monitoring is robust enough to detect abuse before it escalates.
Weekly Coverage