logo

Anatomy of the Salesloft Breach - Detection, Response, and Lessons Learned

ID: a9e2141d-7221-5ee5-b5ea-c239a031740f

STIX ID: report--a9e2141d-7221-5ee5-b5ea-c239a031740f

Feed Name: Cloud Chronicles

Threat Score
88/100

Date Published: 2025-09-15

Date Updated: 2026-07-29

Author: Ian Ahl

...
...

**Executive Summary:** The SalesLoft Drift supply‑chain breach involved a GitHub compromise that led attackers to harvest secrets from AWS, steal hundreds of per‑user OAuth tokens, and use those tokens to mass‑export Salesforce and other integrated service data—then mine those exports for additional cloud credentials; the report provides timelines, two observed attacker IPs, detection signals (bulk API usage, OAuth refresh patterns, premature export deletions), and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.