Salesloft: Hacker broke into systems in March through GitHub account
ID: c604206b-229f-5ca7-92ca-7b713fe40b8f
STIX ID: report--c604206b-229f-5ca7-92ca-7b713fe40b8f
Feed Name: The Record from Recorded Future News
Salesloft disclosed that a threat actor compromised a Salesloft GitHub account from March through June, enabling downloads from repositories, addition of a guest user and malicious workflows; the attacker accessed Drift’s AWS environment and stole authentication/OAuth tokens tied to customer integrations, leading to data theft across dozens of major organizations (Google TIG reported ~700 related victims) including exposure of support-ticket contents and, in some cases, sensitive PII. Salesloft and impacted vendors isolated systems, rotated credentials, and are conducting forensic reviews.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
