logo

The Salesloft–Drift Breach: An Attack Path Case Study

ID: b3cc5193-afa7-5f76-860d-49050602afc1

STIX ID: report--b3cc5193-afa7-5f76-860d-49050602afc1

Feed Name: SpecterOps Blog

Threat Score
80/100

Date Published: 2025-09-24

Date Updated: 2026-04-30

Author: Jared Atkinson

...
...

This post analyzes the Salesloft–Drift breach and shows how a GitHub compromise allowed attackers to pivot into Salesloft's AWS, exfiltrate Drift–Salesforce OAuth tokens, and use those tokens to access hundreds of Salesforce tenants and harvest customer data and embedded secrets; the author frames the incident as an attack-path problem (clean source principle, identities in transit, hybrid cross-organization links) and advocates using attack-graph tooling to reveal and mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.