Skip to content

Salesforce & Salesloft Warn of Data Breach via Drift App

Hackers target Salesforce and Salesloft through Drift app. Swift action taken to secure systems and protect customers.

there was a room in which people are sitting in the chairs,in front of a table looking into the...
there was a room in which people are sitting in the chairs,in front of a table looking into the laptop and doing something,beside them there are many flee xi in which different advertisements are present which different text.

Salesforce & Salesloft Warn of Data Breach via Drift App

Salesforce and Salesloft have issued warnings about a data breach affecting their integrated systems. Hackers exploited OAuth credentials in the Drift app to steal sensitive data, leading to a swift response from both companies.

The incident, which occurred between August 8 and 18, 2025, saw threat actor UNC6395 breach Salesloft to steal OAuth/refresh tokens for Drift AI chat. The campaign targeted Salesforce customer instances via compromised OAuth tokens associated with the Salesloft Drift third-party application. During this period, hackers exfiltrated data from Salesforce, harvesting credentials like AWS access keys and Snowflake tokens.

Salesforce has confirmed that only a small number of customers were affected due to a compromised app connection. The company, along with Salesloft, has required admins to re-authenticate and shared indicators of compromise (IOCs) to help customers secure their systems. A digital forensics and incident response (DFIR) firm is assisting in the investigation.

The OAuth token theft campaign against Drift, documented from late 2022 to early 2023, has prompted Google Threat Intelligence Group to advise treating affected systems as compromised and rotating credentials. Salesforce and Salesloft continue to work together to mitigate the impact of this breach and enhance security measures.

Read also:

Latest