logo

Drift massive attack traced back to loose Salesloft GitHub account

ID: 4a1aaab8-686f-5f0b-ae54-cb6d9dc41d8c

STIX ID: report--4a1aaab8-686f-5f0b-ae54-cb6d9dc41d8c

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-09-08

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Salesloft/Drift breach: attackers obtained access to Salesloft's GitHub and Drift AWS, created workflows and guest access, and stole OAuth tokens that were used to access and exfiltrate data from hundreds of customer Salesforce instances; Mandiant validated containment steps and segmentation, while attribution points to UNC6395/GRUB1 with potential involvement by ShinyHunters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.